13 Jan 2025

LockBit Hack: Everything You Need to Know

LockBit Hack: Everything You Need to Know

LockBit is one of the most deployed ransomware globally. This hacking group has compromised thousands of entities, spanning financial institutions, logistics companies, and healthcare organizations. These victims are now backed by an international law enforcement task force called Operation Cronos.

On this page

On February 20, the National Crime Agency (NCA) of the UK, alongside the Federal Bureau of Investigation (FBI), declared the neutralization of the LockBit cybercriminal syndicate. This breakthrough is a critical stride in curtailing online fraud.

The operation enabled authorities to:

  • Seize control over the gang's primary website;
  • Shut down 34 servers across the Netherlands, Germany, Finland, France, Switzerland, Australia, the US, and the UK;
  • Freeze 200 cryptocurrency wallets linked to LockBit;
  • File charges against five of its members.

Additionally, arrests were made in Poland and Ukraine, capturing two suspects. The future of other LockBit affiliates remains uncertain, with some under U.S. sanctions and others residing in russia, the true identity of the group's mastermind still unverified.

What is LockBit?

LockBit operates as a cybercrime gang, offering either a development kit or ready-to-use software designed to hijack or restrict data access, demanding a ransom in return. The scale of its user base is unclear, but likely involves hundreds of global affiliates.

The modus operandi of ransomware programs. Source: akamai.com

The modus operandi of ransomware programs. Source: akamai.com

Established in 2019 and originally dubbed “ABCD” for the “.abcd” extension used in encrypting the victims' files, LockBit quickly escalated to become the most prevalent ransomware in existence, targeting entities in the US, China, India, Ukraine, and the EU.

Russian citizen Ivan Kondratiev, aka “Bassterlord,” is suspected to be the orchestrator behind LockBit. His connections extend to other hacking factions like REvil, RansomEXX, and Avaddon, and it's speculated he may also collaborate with russia's Federal Security Service.

Prominent victims of LockBit include the British Royal Mail, Boeing, the Industrial and Commercial Bank of China (ICBC), and the law firm Allen & Overy.

Major LockBit Incidents

Boeing. In October 2023, hackers acquired “a vast amount” of confidential data from aerospace giant Boeing and demanded a ransom. Boeing chose to ignore the demand, leading LockBit to release some of the internal information.

On November 10, two weeks after the initial leak claim, LockBit disclosed all 43 GB of data it had on Boeing, including software configuration backups and logs from monitoring and audit tools. Although Boeing confirmed the cyberattack, it did not provide further details about the incident.

Taiwan Semiconductor Manufacturing Company (TSMC). In June 2023, the world's largest semiconductor manufacturer confirmed a data breach after LockBit listed the company among its victims. The hackers demanded $70 million for the return of the data.

The breach didn't occur directly at TSMC but through a hack of one of its IT service providers, Kinmax Technology. This cyberattack potentially affected Nvidia as well; however, unlike TSMC, the tech giant did not confirm any data leak.

Royal Mail. In January 2023, British postal service Royal Mail fell victim to a data leak by LockBit, causing severe disruptions to international mail services.

About three weeks after the incident, LockBit disclosed negotiation details with Royal Mail, revealing a ransom demand of $80 million for the safe return of the stolen data. The postal service refused to pay.

Royal Mail's semi-annual financial reports, published in the fall of 2023, showed a 5% decrease in international parcel volumes due to the LockBit incident. Additionally, infrastructure costs rose by 5.6% over the same period, with the estimated damage cost around $12.4 million.

Operation Cronos

On February 20, participants of Operation Chronos, which includes the NCA, FBI, Europol, and other law enforcement bodies, announced the takedown of LockBit. The operation's name likely references the Greek myth of Cronos, the ruler of the Golden Age, though, unlike the myth where Cronos ends up imprisoned, many LockBit members remain at large.

The initiative to dismantle LockBit began in April 2022, prompted by the French authorities. At the time, France was the fifth most targeted country by ransomware attacks, following the USA, UK, Canada, and Germany.

Ransomware Attack Statistics by Country for 2023. Source: malwarebytes.com

Ransomware Attack Statistics by Country for 2023. Source: malwarebytes.com

LockBit's French victims included:

  • La Poste Mobile: Even though the ransom was negotiated down from $1.4 million to $300,000, the mobile operator refused to cooperate with the hackers, leading LockBit to leak data on over 1.5 million users.
  • Centre Hospitalier Sud Francilien: Following an attack on this Parisian medical facility, LockBit demanded a $10 million ransom. Upon refusal, the hackers leaked patient data, including health conditions and examination reports.
  • Thales Group: LockBit leaked sensitive data affecting Thales' contracts and partnerships in Malaysia and Italy.

The seizure of LockBit's infrastructure revealed extensive details about the gang's operations. Besides information on the fate of the stolen data, law enforcement clarified that over 2,000 organizations fell victim to LockBit, with total ransoms amounting to $120 million.

A distinctive feature of Operation Chronos was its psychological impact on LockBit members. For example, the website was hacked in stages: on February 19, an announcement and countdown timer appeared, and by February 20, authorities exposed the “inner workings” of the hackers. Additionally, law enforcement efforts undermined the reputation of the group's leader, LockBitSupp, hinting at plans to reveal their real identity.

What's the Current Situation with LockBit?

Despite their website being compromised, LockBit quickly rebounded, establishing a new platform to continue their operations within just five days. LockBitSupp, the group's leader, made a public statement dismissing the impact of Operation Chronos on their non-PHP servers.

Furthermore, this hacker issued a warning about taking retaliatory measures and indicated that government sectors would be their next target. The NCA countered by promising to disclose details about LockBitSupp and announced a $10 million reward for information that could help identify the hacker. 

From LockBitSupp's communication, it appears they are unfazed by law enforcement efforts:

No FBI with their assistants can scare me and stop me, the stability of the service is guaranteed by years of continuous work. They want to scare me because they cannot find and eliminate me, I cannot be stopped.

Examining the potential future for LockBit, we can look at previous instances where ransomware groups like Hive and Conti encountered law enforcement actions and simply altered their branding:

  • Conti's operations have spread to new factions such as Black Basta, BlackByte, and Karakurt;
  • Hive underwent rebranding to become Hunters International.

While taking a hacker at their word is risky, LockBitSupp's statement suggests that law enforcement only acquired a handful of decoders, apprehended the wrong individuals, and failed to shut down all the websites under the group's control. If this assertion holds, LockBit might similarly rebrand itself, suggesting that authorities might spend additional years attempting to completely dismantle the LockBit network.

Final Thoughts

The allure of hacker movies, with their depiction of cybercriminal romance, boldness, and clashes with the law, sometimes mirrors real-life events. The LockBit breach is a prime example of such a narrative unfolding in the real world.

The LockBit saga is likely far from over. To stay informed about the latest developments in Operation Chronos and other cutting-edge news in the realms of cryptocurrency and technology, keep an eye on our X account.

The content on The Coinomist is for informational purposes only and should not be interpreted as financial advice. While we strive to provide accurate and up-to-date information, we do not guarantee the accuracy, completeness, or reliability of any content. Neither we accept liability for any errors or omissions in the information provided or for any financial losses incurred as a result of relying on this information. Actions based on this content are at your own risk. Always do your own research and consult a professional. See our Terms, Privacy Policy, and Disclaimers for more details.

Articles by this author

Latest News

MORE
The Future of Crypto in 2025: Fidelity’s Predictions

The Future of Crypto in 2025: Fidelity’s Predictions

What’s next for the biggest cryptocurrencies in 2025? Fidelity Digital Assets analyst Chris Kuiper shares insights on how Bitcoin will navigate volatility, Ethereum will address scaling challenges, and stablecoins will adapt to evolving regulations.

13 Jan 2025
The Crypto Rollercoaster of 2024 — Wins and Woes

The Crypto Rollercoaster of 2024 — Wins and Woes

The crypto sector evolved at breakneck speed in 2024. With major wins and notable setbacks, it’s time to reflect on the year’s key developments and their implications for the future.

31 Dec 2024
OpenSea Token: Release Date and How to Qualify for the Airdrop

OpenSea Token: Release Date and How to Qualify for the Airdrop

The NFT marketplace OpenSea, a pioneer in the space for the past seven years, is expected to launch its native token in 2025. A significant portion of the tokens will likely be distributed through a retroactive airdrop—a common way to reward the community for their past activity and support.

30 Dec 2024
5 Most Exciting Token Launches to Watch in 2025

5 Most Exciting Token Launches to Watch in 2025

In 2024, we saw a number of hot airdrops and token launches, from AI-powered projects to the rise of memecoins. Now, as we head into 2025, the crypto space is set to expand even further with an increasing number of cryptocurrencies.

27 Dec 2024

Latest News Alt

MORE
Weekly Analysis of BTC, ETH, and the Stock Market (Jan 6, 2025)

Weekly Analysis of BTC, ETH, and the Stock Market (Jan 6, 2025)

An overview of BTC, ETH, XAUT, and S&P500 charts, along with the current cryptocurrency market dynamics.

06 Jan 2025
Weekly Analysis of BTC, ETH, and the Stock Market (Dec 30, 2024)

Weekly Analysis of BTC, ETH, and the Stock Market (Dec 30, 2024)

An overview of BTC, ETH, XAUT, and S&P500 charts, and the current cryptocurrency market dynamics.

30 Dec 2024
Weekly Analysis of BTC, ETH, and the Stock Market (Dec 23, 2024)

Weekly Analysis of BTC, ETH, and the Stock Market (Dec 23, 2024)

An overview of BTC, ETH, XAUT, and S&P500 charts, and the current cryptocurrency market dynamics.

23 Dec 2024

Might Be Interesting

MORE
Mining Farms Uncovered — How Crypto Is Mined at Scale

Mining Farms Uncovered — How Crypto Is Mined at Scale

As a cornerstone of the crypto industry, mining farms drive blockchain networks. But how do they work? Uncover the mechanics behind these cutting-edge hubs and their role in the crypto landscape.

07 Jan 2025
William Quigley, WAX/Tether: Stablecoins’ Role in Global Payments

William Quigley, WAX/Tether: Stablecoins’ Role in Global Payments

William Quigley, co-founder of WAX and Tether, firmly believes that stablecoins are more than a tool for traders—they’re the key to transforming the global economy. Already central to crypto trading and cross-border payments, their future potential is even more exciting.

04 Jan 2025
Why Blockchain Is Different from Traditional Databases

Why Blockchain Is Different from Traditional Databases

In the world of business and finance, information is everything. Traditional databases have been reliable tools for decades, but blockchain presents a groundbreaking alternative. What sets it apart, and could it lead to a paradigm shift?

03 Jan 2025
How Does Multisig Works and Protect Your Assets?

How Does Multisig Works and Protect Your Assets?

As threats to digital assets evolve, multisig technology provides a highly effective security layer. By requiring multiple signatures for transactions, it significantly reduces risks such as hacking and access loss.

02 Jan 2025
Crypto Price Gaps: Why Platforms Show Different Prices

Crypto Price Gaps: Why Platforms Show Different Prices

The crypto market has nuances you may not have noticed at first glance. For example, when you want to check the Bitcoin price, you probably Google it without thinking to compare the results. But when you monitor the market regularly and engage in trading, you notice the prices aren’t the same on all platforms.

24 Dec 2024
The Czech Republic and Its Crypto-Friendly Policies

The Czech Republic and Its Crypto-Friendly Policies

The Czech Republic is emerging as a crypto-friendly nation, recognizing cryptocurrencies as legitimate payment methods and encouraging their use in business. But its regulatory framework is still taking shape. Here’s how crypto is managed today.

23 Dec 2024

Opinions

8 Commandments for Crypto Exchange Users

8 Commandments for Crypto Exchange Users

While cryptocurrency exchanges offer many security features, they are still vulnerable to hacks, fraud, and other criminal activity. Remember, no online platform can guarantee 100% protection for your funds. Follow these eight key rules to reduce your risks. Rule #1: Don’t Believe in the Myth of Absolute Exchange Security Even the largest and most seemingly […]

12 Jan 2025
10 Key Investment Trends to Watch in 2025: Green Crypto, Regulations, and More

10 Key Investment Trends to Watch in 2025: Green Crypto, Regulations, and More

Donald Trump is back, Germany’s economy is in trouble, while U.S. economic indicators seem to have a robust momentum, and interest rates are sliding downhill. Sounds dramatic? It is. But 2025 isn’t all doom and gloom—it’s full of opportunities for investors who know where to look. Whether you’re a seasoned pro or someone still figuring […]

12 Jan 2025
MORE

Interviews

Dmytro Gordon and Volodymyr Nosov: A Sensational Interview

Dmytro Gordon and Volodymyr Nosov: A Sensational Interview

Volodymyr Nosov, CEO of Europe’s largest crypto exchange WhiteBIT, sat down with Dmytro Gordon, one of Ukraine’s most prominent journalists. The interview touched on Bitcoin, crypto, WhiteBIT, cars, keys to success, and business vision.

18 Dec 2024
WhiteBIT CEO: Standing Strong Against Russian Aggression

WhiteBIT CEO: Standing Strong Against Russian Aggression

In an interview with BTC-ECHO, Volodymyr Nosov, the founder and CEO of WhiteBIT, discussed the impact of Russian aggression on the crypto exchange’s business, how WhiteBIT stays a top competitor in the industry, and when he believes our financial system will be completely transformed.

04 Oct 2024
MORE