Ransomware group LockBit is disrupted by a global police operation that includes 2 arrests

Advertisement

Advertise with us

LONDON (AP) — Law enforcement agencies have infiltrated and disrupted LockBit, arresting two people involved with the prolific ransomware syndicate that has extracted $120 million from thousands of victims around the world, British, American and European officials said Tuesday.

Read this article for free:


or

Already have an account? Log in here »

To continue reading, please subscribe:

Subscribe and receive a limited-edition Free Press branded hat or tote.

Digital Subscription

One year of digital access for only $205*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles

*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.

To continue reading, please subscribe:

Add Free Press access to your Brandon Sun subscription for only an additional

$1 for the first 4 weeks*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles
Start now

*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.

Hey there, time traveller!
This article was published 20/02/2024 (960 days ago), so information in it may no longer be current.

LONDON (AP) — Law enforcement agencies have infiltrated and disrupted LockBit, arresting two people involved with the prolific ransomware syndicate that has extracted $120 million from thousands of victims around the world, British, American and European officials said Tuesday.

Britain’s National Crime Agency, or NCA, said it led an international operation targeting LockBit, which provides ransomware as a service to so-called affiliates who infect victim networks with the computer-crippling malware and negotiate ransoms.

The operation resulted in the arrests of two people in Poland and Ukraine and the seizure of 200 cryptocurrency accounts, officials said at a joint news conference. The Justice Department, meanwhile, unsealed indictments against two more people, both Russian nationals. Authorities said they gained “comprehensive access” to LockBit’s systems, taking control of infrastructure and obtaining keys to help victims decrypt their data.

A TV screen shows the front page of LockBit's dark-web leak site that was replaced with the words
A TV screen shows the front page of LockBit's dark-web leak site that was replaced with the words "this site is now under control of law enforcement," alongside the flags of the U.K., the U.S. and several other nations during the law enforcement press conference to outline the details of a law enforcement operation against the ransomware syndicate LockBit in London, Tuesday, Feb. 20, 2024. Law-enforcement agencies said they infiltrated and disrupted LockBit, arresting two people involved with the prolific ransomware syndicate that has extracted $120 million from thousands of victims around the world. (AP Photo/Kelvin Chan)

“We have hacked the hackers,” Graeme Biggar, the NCA’s director general, said at the news conference in London. “LockBit has been locked out.”

Hours before the announcement, the front page of LockBit’s dark-web leak site was replaced with the words “this site is now under control of law enforcement,” alongside the flags of the U.K., the U.S. and several other nations.

The message said the U.K.’s NCA was “working in close cooperation with the FBI and the international law enforcement task force, Operation Cronos.” The continuing operation also involves agencies from Germany, France, Japan, Australia, New Zealand and Canada, among others, including Europol, it said.

The announcement brings to five the number of people the U.S. has indicted since the operation began. Three Russians have previously been indicted, with two of those taken into custody, one in Canada and one in the U.S. The rest are still wanted.

“Today we have turned the tables on these cybercriminals,” Philip Sellinger, the top federal prosecutor in New Jersey, said at the news conference.

Authorities said they also seized servers that the gang used to organize and transfer victim data, and gained access to nearly 1,000 potential decryption tools. They also obtained the Lockbit platform’s source code and a trove of intelligence on people the gang worked with.

LockBit, which has been operating since 2019, has been the most prolific ransomware syndicate two years running. The group accounted for 23% of the nearly 4,000 attacks globally last year in which ransomware gangs posted data stolen from victims to extort payment, according to the cybersecurity firm Palo Alto Networks.

The operation is “probably the most significant ransomware disruption to date,” Analyst Brett Callow of the cybersecurity firm Emsisoft said. And while it will likely spell the end of the brand, such groups routinely rebrand and re-emerge under new names. Over the long term, Callow said, this operation alone will not diminish the volume of ransomware attacks.

A rare offensive cyber-operation for the U.K. crime agency, the operation aimed to steal all of LockBit’s data and then destroy its infrastructure, causing a “significant major degradation” of the cybercrime threat.

LockBit is dominated by Russian speakers and does not attack former Soviet nations. The syndicate provides clients with the platform and the malware to conduct attacks and collect ransoms.

Officials suggested that LockBit could have hundreds of members but there’s no evidence that a nation state such as Russia is behind the syndicate, Biggar said.

“These are criminals,” he said, although the lack of a Russian crackdown indicates that Moscow tolerates the gang’s activity.

LockBit has been linked to attacks on the U.K.’s Royal Mail, Britain’s National Health Service, airplane manufacturer Boeing, international law firm Allen and Overy and China’s biggest bank, ICBC.

U.S. Attorney Philip Sellinger, second left, and Graeme Biggar, director general of Britain's National Crime Agency, center, are among law enforcement officials appearing at a press conference to outline the details of a law enforcement operation against the ransomware syndicate LockBit in London, Tuesday, Feb. 20, 2024. Law-enforcement agencies said they infiltrated and disrupted LockBit, arresting two people involved with the prolific ransomware syndicate that has extracted $120 million from thousands of victims around the world. (AP Photo/Kelvin Chan)
U.S. Attorney Philip Sellinger, second left, and Graeme Biggar, director general of Britain's National Crime Agency, center, are among law enforcement officials appearing at a press conference to outline the details of a law enforcement operation against the ransomware syndicate LockBit in London, Tuesday, Feb. 20, 2024. Law-enforcement agencies said they infiltrated and disrupted LockBit, arresting two people involved with the prolific ransomware syndicate that has extracted $120 million from thousands of victims around the world. (AP Photo/Kelvin Chan)

“We have disrupted at every level the criminal operation of the LockBit ransomware group,” Europol’s Deputy Executive Director of Operations Jean-Philippe Lecouffe said at the news conference. “Today we have dealt a decisive blow not only to their operation, but also importantly, to their reputation.”

Cybersecurity experts wondered Tuesday how much detail law enforcement obtained in infiltrating LockBit’s infrastructure on affiliate negotiations with victims, including who quietly paid ransoms and how much. Influenced by specialty firms they hire to respond to attacks, victims generally resist admitting publicly that ransomware is to blame.

Officials told reporters the gang targeted 2,000 victims worldwide, including 200 in the U.K. Biggar said the numbers will be “significant underestimates.”

Last June, U.S. federal agencies released an advisory that attributed about 1,700 ransomware attacks in the United States since 2020 to LockBit and said victims included “municipal governments, county governments, public higher education and K-12 schools, and emergency services.”

Artur Sungatov and Ivan Kondratyev, the two indicted Russians, are accused of deploying LockBit against manufacturing companies in the U.S. and semiconductor businesses worldwide. Kondratyev allegedly used the ransomware against municipal and private targets in Oregon, Puerto Rico and New York and others victims in Singapore, Taiwan, and Lebanon while Sungatov allegedly deployed it against manufacturing, logistics and insurance companies in Minnesota, Indiana, Puerto Rico, Wisconsin, Florida, and New Mexico.

Ransomware is the costliest and most disruptive form of cybercrime, crippling local governments, court systems, hospitals and schools as well as businesses. It is difficult to combat as most gangs are based in former Soviet states and out of reach of Western justice. Law enforcement agencies have scored some recent successes against ransomware gangs, most notably the FBI’s operation against the Hive syndicate. But the criminals regroup and rebrand.

Britain’s National Cyber Security Centre has previously warned that ransomware remains one of the biggest cyber threats facing the U.K. and urges people and organizations not to pay ransoms if they are targeted.

____

Frank Bajak in Boston contributed to this report.

Report Error Submit a Tip

More Stories

Essential workers ruling raises questions

Editorial 4 minute read Preview

Essential workers ruling raises questions

Editorial 4 minute read Updated: Yesterday at 3:56 PM CDT

Ever been to a Dynacare clinic? Most of us have been. It’s an amazing demographic and ethnic slice of the city we’ve become.

Read
Updated: Yesterday at 3:56 PM CDT

Three Manitoba nurses censured for inappropriate behaviour

Morgan Modjeski 3 minute read Monday, Oct. 5, 2026

A Manitoba nurse has been disciplined for inappropriate behaviour towards students including what is being described as unwanted touching.

Alzheimer’s has sent my mother back in time

Pam Frampton 5 minute read Preview

Alzheimer’s has sent my mother back in time

Pam Frampton 5 minute read 2:01 AM CDT

My mother does a lot of time-travelling — time-shifting, the Alzheimer’s Society calls it.

I wonder how it feels to be in the present at one moment and then suddenly catapulted deep into the past. Is it a jolting experience or a smooth transition to go back and forth in time?

Mom will never be able to tell me. There is so much she can never tell me now.

She can still recite her children’s names when prompted, but she doesn’t ask us about our lives. Instead, she talks about her younger siblings, their grandfather who was hard of hearing, the isolated place where they used to live whose inhabitants were resettled nearly 60 years ago.

Read
2:01 AM CDT

Sidney Crosby sings praises of Jets' Bjorck, summer training partner Barron

Ken Wiebe 6 minute read Preview

Sidney Crosby sings praises of Jets' Bjorck, summer training partner Barron

Ken Wiebe 6 minute read Monday, Oct. 5, 2026

PITTSBURGH — It wasn’t that long ago when the shoe was on the other foot for Sidney Crosby.

Read
Monday, Oct. 5, 2026

Waiver wire pickup leads Jets to victory in Pittsburgh

Ken Wiebe 6 minute read Preview

Waiver wire pickup leads Jets to victory in Pittsburgh

Ken Wiebe 6 minute read Monday, Oct. 5, 2026

PITTSBURGH – Now that’s a positive first impression.

The Winnipeg Jets swept a two-game road trip, thanks in part to Clay (Mud) Stevenson making 30 saves in his debut with the team that claimed him off waivers one week earlier.

Stevenson was excellent in a 3-2 victory for the Jets over the Pittsburgh Penguins on Monday night at PPG Paints Arena.

“He obviously made some big big stops, right up to the end of the game there,” said Jets head coach Scott Arniel. “He was real solid and confident and looked comfortable. It was great to see a kid come in here like that, a new organization late in training camp. He came as advertised.”

Read
Monday, Oct. 5, 2026

This week’s silly geopolitical spat

Gwynne Dyer 4 minute read 2:01 AM CDT

“I would not like to call this an incident. Let’s say it’s a diplomatic misunderstanding,” said Ukrainian Foreign Affairs Minister Andrii Sybiha. But the South Korean president definitely sees it as a serious incident, and he has already gone public with it.

“If (Ukraine’s) refusal to acknowledge the facts and issue a public apology continues, we will take additional measures,” President Lee Jae-myung wrote on X. He probably means cutting the non-military aid South Korea gives to Ukraine. (There is no military aid, since the constitution bans Seoul from providing arms to a country actively involved in a war).

What monstrous misdeed did the Ukrainian government commit to deserve such harsh words from a country that is generally sympathetic to Ukraine’s struggle against its giant neighbour? Have the South Koreans discovered Ukrainian spies in the Blue House?

No, it’s what we professionals call a “spat.”