Back to glossaryCyber

LockBit

Cybercriminal group that operated the most prolific ransomware-as-a-service network between 2019 and 2024, before its partial dismantlement by Operation Cronos.

Definition

LockBit is the name of a cybercriminal group and its eponymous ransomware strain that dominated the ransomware-as-a-service market for more than four years. Emerging in late 2019 under the name ABCD then rebranded LockBit, the group successively developed LockBit 2.0 (2021) and LockBit 3.0 aka Black (2022), the latter incorporating code from the BlackMatter source code leak. At its peak, LockBit claimed more than 2,000 identified victims and is reported to have collected over 120 million dollars in ransoms. Its RaaS business model was particularly sophisticated: affiliate management panels, integrated negotiation service, double-extortion data leak site, and even a bug bounty program for researchers identifying vulnerabilities in its own code. Operation Cronos, coordinated by Europol and the British National Crime Agency in February 2024, led to the seizure of 34 servers, the identification of 194 affiliates and the arrest of several members. The disruption caused an immediate contraction in global ransom payments, illustrating the systemic weight of an actor concentrating a significant share of criminal supply. For cyber actuaries, LockBit constituted a reference scenario for correlation and frequency models for large-scale ransomware losses.

Example

At the time of its dismantlement in February 2024, Europol revealed that LockBit had targeted critical sectors in 111 countries, including hospitals, water infrastructure and public administrations. The United Kingdom, United States, France, Germany and Canada were among the most affected countries, each having suffered hundreds of identified victims.

Related terms
Related articles
Also known as

LockBit 2.0, LockBit 3.0, LockBit Black