An international law enforcement operation led by the UK's National Crime Agency and the FBI seized LockBit infrastructure on 19 February 2024, disrupting one of the world's most prolific ransomware-as-a-service groups. Follow-on actions publicly identified and sanctioned a senior LockBit leader, while officials said the campaign targeted the gang's administrators, infrastructure, and criminal affiliates. Subsequent reporting said the disruption sharply reduced LockBit's standing in ransomware rankings after years in which the group had claimed thousands of victims across more than 100 countries.
Threat research shows LockBit's reach was driven by a scalable affiliate model rather than malware alone, with intrusions commonly starting through abused VPN, Citrix, and RDP access or stolen credentials, followed by use of tools such as Impacket, Mimikatz, PsExec, Rclone, and StealBit. Affiliates increasingly targeted VMware ESXi environments to maximize operational impact, and some skipped encryption entirely in favor of data-theft extortion using LockBit-branded notes. The group's earlier attacks included a reported $80 million demand against CDW, but researchers and investigators warn that even as LockBit declines, its affiliates and copycats are likely to continue operating under other ransomware brands.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-09, the U.S. Department of State announced Rewards for Justice offers of up to $10 million for information identifying or locating key LockBit leaders and up to $5 million for information leading to the arrest or conviction of participants in LockBit activities. The notice described LockBit as responsible for more than 2,000 attacks since January 2020 and at least $144 million in bitcoin ransom payments.
U.S. prosecutors announced charges against Rostislav Panev, a dual Russian-Israeli national accused of serving as a LockBit developer and helping build and maintain the group's malware and infrastructure from around 2019 through February 2024. The DOJ said Panev had been arrested in Israel in August 2024 on a U.S. provisional arrest request and remained in custody pending extradition.
On 2024-06-22, reporting attributed the major CDK Global outage to a BlackSuit ransomware attack. This is a separate ransomware event included in the references but not part of the LockBit enforcement timeline.
By 2024-05-22, reporting indicated the February disruption had significantly reduced LockBit's prominence among ransomware groups. The takedown was described as taking a measurable toll on the gang's activity and rankings.
On 2024-05-07, the U.S. Department of Justice unsealed a 26-count indictment against Dmitry Yuryevich Khoroshev, alleging he created, developed, and administered LockBit from 2019 through May 2024. The DOJ said the case followed the February infrastructure seizure and described LockBit as responsible for more than 2,500 victims worldwide and at least $500 million in ransom payments.
On 2024-05-07, UK and US authorities publicly unmasked LockBit's alleged administrator, Dmitry Khoroshev, and imposed sanctions on him. The announcement marked a major attribution and enforcement escalation following the February takedown.
On 2024-02-19, a multinational operation led by the UK's National Crime Agency and the FBI seized LockBit infrastructure and disrupted the ransomware group's operations. The action also targeted individuals associated with the group.
Secureworks reported that LockBit had compromised thousands of organizations and accumulated more than 2,350 named victims across 112 countries by the end of 2023. The scale was driven by its ransomware-as-a-service affiliate model and strong criminal branding.
By mid-October 2023, reports said the LockBit ransomware gang had attacked CDW and demanded an $80 million ransom. This reflects LockBit's continued high-profile activity before the 2024 law-enforcement disruption.
Europol said the multinational investigation into LockBit began in April 2022, well before the public takedown. The long-running probe involved coordination among multiple law-enforcement agencies ahead of Operation Cronos.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
state.gov
Open sourcesophos.com
Open sourcejustice.gov
Open sourcebleepingcomputer.com
Open sourcechainalysis.com
Open sourcetechcrunch.com
Open sourcebleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.