The UK’s National Crime Agency announced that it had taken control of the infrastructure of LockBit, then described as the world’s most harmful ransomware group, in an international operation known as Operation Cronos involving the FBI, Europol, and partners in about ten countries.
What happened
- Investigators took over LockBit’s administration environment and leak site, replacing it with law enforcement notices, and obtained its source code and more than 1,000 decryption keys.
- Two people were arrested in Poland and Ukraine, and the US unsealed indictments against two Russian nationals accused of LockBit attacks.
- The NCA said LockBit had targeted thousands of victims worldwide, causing losses of billions of pounds, dollars, and euros.
- On 7 May 2024 the UK, US, and Australia named and sanctioned a Russian national, Dmitry Khoroshev, as the alleged LockBit administrator.
Why it mattered
The operation disrupted the leading ransomware-as-a-service brand and publicly undermined criminals’ trust in it, showing a new approach of combining technical takedown with psychological operations.
Lessons for organisations
Takedowns do not remove the threat, so organisations should keep tested offline backups, patch internet-facing systems quickly, and enforce MFA on remote access. Reporting incidents to the NCSC and police helps operations like this succeed.
Sources: National Crime Agency, National Crime Agency (sanctions)
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.