LockBit
Attribution profile
- Type
- Crime Syndicate
- Location
- Russia
- Known incidents
- 2 incidents
- Sources
- 122 sources
- First seen
- 2025-03-17
- Last seen
- 2026-08-19
- Updated
- 2026-09-11 00:21
- Aliases
- 3 aliases
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
LockBit, also tracked under the alias ABCD, is a prolific cybercriminal ransomware operation that has been active since at least September 2019. According to several accounts, the group began operations under the name ABCD before rebranding to LockBit, and later iterated through versions including LockBit 2.0 and LockBit 3.0. The gang operates using a Ransomware-as-a-Service (RaaS) model, in which core developers maintain the malware and infrastructure while affiliates conduct intrusions and deploy the encryptor, with ransom proceeds split between the developers and the attacking affiliate who can receive up to three-quarters of the funds. The malware itself is considered by some researchers to share behavioral traits with the LockerGoga and MegaCortex ransomware families, possessing self-propagation capabilities once executed inside a network. LockBit has been publicly characterized as Russia-linked, and the group's leader, known online as LockBitSupp, is believed to reside in Russia and has claimed to use SpaceX's Starlink internet service to complicate tracking efforts.
The group's targeting spans a wide range of sectors and geographies, with victims identified across banking, healthcare, manufacturing, government, law enforcement, education, and private industry on multiple continents. Notable publicly reported operations include attacks on Bank Syariah Indonesia (BSI), where LockBit ultimately leaked approximately 1.5 terabytes of data after ransom negotiations failed; TSMC, via a breach at IT supplier Kinmax Technology, where LockBit demanded an unusually high $70 million ransom; the Washington County Sheriff's Office in Florida, where stolen data was subsequently leaked; Managed Care of North America (MCNA), affecting nearly 8.9 million individuals; and the Dutch football association KNVB. In Italy specifically, numerous private organizations have appeared on LockBit's data leak site, including STIM Group, Gruppo Mercurio, Metronotte Vigilanza, Comacchio, Errebielle, Tecnosys Italia, Lubrimetal, and Bontà Viva, illustrating a heavy focus on Italian industrial and commercial targets. LockBit has also listed high-profile manufacturers such as YKK, Audio-Technica, and SpaceX contractor Maximum Industries, as well as religious organizations like Relentless Church. Law enforcement actions against the group include the U.S. arrest and charging of a Russian national for his alleged role in multiple LockBit attacks, announced by the Department of Justice.
LockBit's tradecraft relies on a double-extortion model in which victims are first pressured to pay for decryption and then threatened with the publication of exfiltrated data on the group's dark web leak site if the ransom is not paid. The group has introduced paid options for victims on its leak site, including extending countdown timers to delay publication, paying for destruction of all stolen data, or obtaining exclusive download access to the exfiltrated information. Initial access vectors reported in specific cases include exploitation of vulnerable or outdated systems, such as a rogue Windows 7 PC running manufacturing software at British fencing manufacturer Zaun, and use of stolen credentials or third-party supplier compromises, as seen in the TSMC incident. While LockBit has at times publicly apologized and issued decryptors when affiliates attacked sensitive targets such as hospitals, the group has nonetheless continued to list healthcare organizations, including Brazilian hospital system Grupo Hospitalar Vida. Multiple sources describe LockBit as the most active ransomware operation during much of 2022 and into 2023, frequently accounting for the majority of tracked ransomware incidents in monthly tallies, and it has been associated in reporting with other Russia-affiliated groups such as Conti, Black Basta, and the BlackCat/ALPHV lineage, though direct operational overlap beyond shared ecosystem references is not explicitly detailed.
Incidents
Attributed incidents are available to members.
2 incidentsSources
Sources available to members: 122 sources.