LockBit
Attribution profile
- Type
- Undetermined
- Location
- -
- Known incidents
- 0 incidents
- Sources
- 122 sources
- First seen
- -
- Last seen
- -
- Updated
- 2026-09-05 10:58
- Aliases
- 2 aliases
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known publicly as LockBit also used the alias ABCD when it first emerged in September 2019, later rebranding to LockBit 2.0 and then to LockBit 3.0. It operates as a ransomware‑as‑a‑service (RaaS) cyber gang, with affiliates who deploy the LockBit ransomware payload and share ransom proceeds with the core developers. Public sources describe the group as Russia‑linked and note that, according to a U.S. Justice Department statement, LockBit has been involved in over 1,400 attacks against victims in the United States and elsewhere, issuing more than $100 million in ransom demands and receiving over $75 million in payments. The group’s activity has been tracked by multiple threat‑intelligence feeds, which recorded it as the most prominent ransomware gang of 2022 and noted that it had the highest victim count in a single month with 51 organizations listed on its leak site.
LockBit’s victims span a wide range of sectors and regions, including manufacturing firms such as Zaun in the United Kingdom and STIM Group in Italy, technology suppliers like Kinmax Technology that service TSMC, automotive parts dealers such as Euromotors in Peru, logistics providers like Gruppo Mercurio in Italy, food producers such as Bontà Viva in Italy, furniture makers like Errebielle, lubricant producers like Lubrimetal, software developers such as Tecnosysitalia, and wholesale distributors like Essendant. The group has also targeted healthcare organizations, notably the Brazilian hospital system Grupo Hospitalar Vida, educational institutions including Pineland Schools in New Jersey and the Uniondale Union Free School District in New York, religious entities such as Relentless Church in South Carolina, law‑enforcement agencies like the Washington County Sheriff’s Office in Florida, sports bodies including the Royal Dutch Football Association, government agencies such as South Korea’s National Tax Service, and financial institutions including Indonesia’s Bank Syariah Indonesia and allegedly Deutsche Bank. Its tactics involve gaining initial access through exploited unpatched vulnerabilities, insider assistance, or compromised third‑party partners, deploying file‑encrypting LockBit ransomware, and then employing double extortion by threatening to leak stolen data on its dark‑web leak site. The leak site features a countdown timer, offers victims the option to extend the timer, delete all data, or download the exfiltrated data for a fee, and accepts ransom payments in Bitcoin or Monero. Publicly reported operations include the 1.5 TB leak from Bank Syariah Indonesia, the 700 GB breach of dental insurer Managed Care of North America affecting nearly nine million individuals, the claimed theft of SpaceX‑related drawings from contractor Maximum Industries, and the disclosure of employee data from the Royal Dutch Football Association. These facts are drawn directly from the supplied sources and constitute the established profile of the threat actor.
Incidents
Attributed incidents are available to members.
0 incidentsSources
Sources available to members: 122 sources.