LockBit was the most prolific ransomware-as-a-service (RaaS) operation of the early 2020s, responsible for thousands of attacks worldwide before a major law-enforcement disruption in 2024.
Key facts
- Operated a RaaS affiliate model, leasing its ransomware to affiliates who carried out attacks for a share of the ransom.
- Known for fast encryption and aggressive double-extortion, publishing stolen data on its leak site when victims refused to pay.
- Disrupted in February 2024 by Operation Cronos, an international action led by the UK NCA and FBI that seized infrastructure and identified affiliates.
- Attempted to rebuild and rebrand after the takedown, illustrating the resilience of established ransomware brands.
Why it matters
LockBit set the template for modern RaaS: high volume, double extortion and a polished affiliate program. Even after disruption, its leaked data and rebranding efforts mean organisations must keep watching underground channels for their names and credentials.
How DarkThreatX helps
DarkThreatX monitors dark web leak sites, forums and marketplaces for activity and data tied to your organisation, so you can respond before exposure becomes a breach. Run a free dark web scan or explore the platform.