International law enforcement agencies said Operation Cronos disrupted LockBit, the ransomware-as-a-service group long described as the world’s most prolific ransomware operation. Authorities seized infrastructure, took control of LockBit’s leak site and platform, exposed affiliates, delivered decryption keys to victims, and publicly revealed that the group sometimes retained stolen victim data and failed to provide working decryptors. According to the FBI, LockBit operated from 2020 to 2024, hit more than 2,500 organizations in at least 120 countries, and collected more than $500 million in ransom payments; several members have since been arrested or charged, while alleged leader Dmitry Yuryevich Khoroshev remains indicted, sanctioned, and at large.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
The early 2026 intrusion culminated in ransomware deployment that encrypted thousands of files across multiple systems, with SMB-based propagation noted in Darktrace's reporting.
During the same early 2026 intrusion, Darktrace observed outbound transfers to Wasabi cloud storage, including more than 200 MB of data, consistent with double-extortion tactics before encryption.
In early 2026, Darktrace observed a multi-stage ransomware intrusion in a customer environment that began with compromised VPN credentials and progressed over several days through reconnaissance, privilege escalation, lateral movement, command-and-control, and data exfiltration.
Following the February 2024 takedown, law enforcement delivered decryption keys to LockBit victims as part of the disruption effort.
According to the FBI, LockBit operated from 2020 to 2024, targeting more than 2,500 organizations in at least 120 countries and collecting over $500 million in ransom payments.
The US Department of Justice sanctioned and indicted alleged LockBit leader Dmitry Yuryevich Khoroshev, who remained at large at the time of reporting.
After the takedown, several key LockBit members were arrested or charged, while alleged leader Dmitry Yuryevich Khoroshev remained at large.
In February 2024, the FBI, the UK National Crime Agency, Europol, and partners seized LockBit infrastructure, took control of its leak site and platform, and used that access to expose affiliates and undermine trust in the operation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcedarkreading.com
Open sourcedarktrace.com
Open sourcedarktrace.com
Open sourcedarktrace.com
Open sourceeuropol.europa.eu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.