Undermining affiliates' trust and strong international partnerships were the keys to dismantling LockBit, one the most successful ransomware-as-a-service (RaaS) groups of its time, which at its peak was responsible for a quarter of all ransomware attacks.
LockBit operated primarily between 2020 and 2024, and Brett Leatherman, assistant director of the FBI's Cyber Division, tells Dark Reading that during its time it victimized more than 2,500 organizations across at least 120 countries, with more than 1,800 of these attacks occurring in the US. Overall, the group collected more than $500 million in ransom payments, and the group and its leader, a Russian national named Dmitry Yuryevich Khoroshev, seemed invincible.
LockBit's RaaS enterprise "for a time … was the most successful criminal business in the world," Leatherman says. Indeed, by the time the group was disrupted, it included a network of nearly 200 affiliates doing its dirty work, with Khoroshev collecting 20 cents on every dollar of ransom earned by that network, he ways.
Related:CISOs vs. Boards: Myth or Misunderstanding?
That's until a law-enforcement effort called Operation Cronos targeted the group in February 2024 (part of the wider Operation Endgame effort), seizing LockBit's infrastructure and doing permanent damage to its reputation and day-to-day operations. The law-enforcement operation took control of LockBit's own platform, from the leak site to the control panel to the source code and the data inside it, seizing LockBit's servers and putting decryption keys in victims' hands, Leatherman says.
Leatherman and Paul Foster, deputy director of the National Cyber Crime Unit of the National Crime Agency (NCA), will unpack Operation Cronos in a session called "Anatomy of a Takedown: Inside the Operation That Broke LockBit" at Black Hat USA 2026 next week in Las Vegas.
Operation Cronos: Breaking & Building Trust
One of the core reasons for the success of the operation — which the FBI ran in collaboration with the UK's National Crime Agency, Europol, and 10 other international partners — was breaking the trust relationship the group had established with its network of affiliates, who had been promised anonymity and long-term success with the group, Leatherman tells Dark Reading. Specifically, the effort created a rift with those partnerships by using the group's own leak site to "out" them.
"Trust is what ransomware-as-a-service actually sells," Leatherman explains. "An affiliate hands the platform his access, his malware builds, his negotiations, and his money and what he buys in return is anonymity and a payday."
Related:Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation
... continue reading