U.S., U.K. and other international law enforcement agencies disrupted the operations of one of the world's most active and destructive ransomware groups — LockBit — by seizing its public-facing websites and control of its servers.

LockBit has targeted over 2,000 victims globally, accumulated more than $120 million in ransom payments and made ransom demands totaling hundreds of millions of dollars, according to the U.S. Department of Justice.

In a joint operation, law enforcement agencies seized numerous of LockBit's public-facing websites for its infrastructure connections and control of servers used by its administrators, which disrupts the ability to attack and encrypt networks and extort victims by threatening to publish stolen data.

Agencies also arrested two individuals and the U.S. Justice Department unsealed indictments against two others associated with the ransomware group.

The operation also obtained keys from the seized LockBit infrastructure, which may enable hundreds of victims around the world to decrypt their captured systems and regain access to their data.

Victims targeted by the LockBit ransomware variant are encouraged to contact the federal bureau of investigation (fFBI) at https://LockBitvictims.ic3.gov/.

“LockBit is not the first ransomware variant the Justice Department and its international partners have dismantled. It will not be the last,” U.S. Attorney General Merrick B. Garland said in a statement.

Law enforcement has taken several actions against notorious ransomware groups in recent years, which led to the decline of groups like Hive and Ragnar Locker, and the near-collapse of ALPHV (BlackCat), according to Palo Alto Networks’ Unit 42.

For example, the Hive ransomware group, one of the most prolific groups in 2022, was shut down as part of a law enforcement-led operation reported in January 2023. The operation captured the group’s decryption keys and saved potential victims over $130 million in ransom payments.

Who is LockBit?

LockBit, identified as a ransomware-as-a-service (RaaS) operation, leveraged a model that allowed it to scale its malicious activities by providing access to the ransomware variant and tools to affiliates who executed the attacks that include perpetration, spearfishing, data theft, ransomware and extortion.

The LockBit ransomware variant first appeared around January 2020. It was the first RaaS operation to offer a bug bounty program.

Security vendors such as Palo Alto Networks, Dragos and Arctic Wolf all identified LockBit as the most active ransomware group in 2023 in their recent research. The Unit 42 team has seen LockBit post about more than 2000 victims on its leaked site.

Likely to rebrand after disruptions

The Check Point Research team noted LockBit has suffered two major disruptions in the past two months. “We assume that the combination of those two factors, will have a big effect on LockBit operations, especially on the reputational aspect and will cause them significant difficulties to recruit and maintain affiliates who will operate this ransomware.”

However, “mostly such successful groups don’t disappear so we can expect some type of rebranding,” the team said.

Matt Hull, global head of threat intelligence at NCC Group, said “The law enforcement intervention against the LockBit RaaS Group is perhaps the most significant over the last three years.”

“No doubt people will be wondering whether LockBit can bounce back. The Group has claimed that they have back-ups of their systems and data. We have seen in the past various ransomware operators re-brand, join forces with other groups, or come back a few months later,” Hull said.

“Past examples have shown how groups can quickly regroup following these disruptions,” echoed Arctic Wolf Chief Information Security Officer (CISO) Adam Marrè. “For example, last year Arctic Wolf identified how the new ransomware group Akira had risen from the fallout of the Conti ransomware in 2022. Given the dispersed nature of LockBit, it is also likely threat actors that aren’t involved in any follow-up arrests will still make use of the existing infrastructure not affected by this activity.”