A recent study presented at Black Hat Europe analyzed data seized from the LockBit ransomware group, revealing that organizations who pay ransoms to avoid publicity often experience greater media exposure than those who refuse to pay. Max Smeets, co-director of Virtual Routes, examined the largest 100 payouts to LockBit and compared them to 100 random cases where victims did not pay, using data provided by the UK's National Crime Agency following Operation Cronos, which disrupted LockBit's infrastructure. The findings indicate that succumbing to extortion does not reduce, and may even increase, unwanted attention for victim organizations.
The research challenges the common belief that paying ransomware demands can help organizations avoid reputational damage. Instead, the analysis suggests that payment may attract more media coverage, potentially due to increased interest in high-profile payouts or leaks by threat actors. The study underscores the importance of considering the broader consequences of ransom payments and highlights the ongoing risks posed by ransomware groups like LockBit, even after law enforcement interventions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
At Black Hat Europe 2025, Max Smeets presented research based on UK National Crime Agency data showing that LockBit victims who paid were more likely to receive media coverage than those who refused. The study argued that paying for secrecy often fails and can worsen reputational exposure.
Analysis of data seized during Operation Cronos showed that after the 2024 law enforcement action, fewer LockBit affiliates received payments and successful extortions dropped sharply. Researchers and officials concluded the group was no longer a major threat at its previous scale.
Following the 2024 disruption, law enforcement publicly identified Dmitry Yuryevich Khoroshev as the person behind the LockBitSupp alias. The attribution was part of broader efforts to weaken the group's credibility and operations.
In 2024, coordinated law enforcement action under Operation Cronos infiltrated LockBit's infrastructure and disrupted the group's operations. Authorities also recovered stolen data and used LockBit's own leak site to undermine affiliate trust.
Research presented at Black Hat Europe 2025 found that LockBit had 194 affiliates active between 2022 and 2024, with 80 of them successfully receiving ransom payments. The data illustrated the scale of LockBit's ransomware-as-a-service model before its disruption.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
computerweekly.com
Open sourcewelivesecurity.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.