LIVE NEWS
  • ‘A disaster for America First’: Trump allies fear Netanyahu meeting will pull US deeper into war with Iran – Politico
  • AI Hosts And Sandboxes Save Intel’s Datacenter CPU Cookies
  • How one man’s near-death experience led to the discovery of the first Jurassic sea dragon in Wales | Fossils
  • Badenoch urges Burnham to cancel prisoners’ early release scheme – UK politics live | Politics
  • Eating within 8 hours may help keep the aging brain sharp
  • Today’s NYT Mini Crossword Answers for Tuesday, July 28
  • Heat wave threatens to worsen France, Spain wildfires
  • Why SEO Agencies Focus On Technical, On-page, And Off-page SEO Together
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»Breaking Affiliate Trust Sped Along LockBit’s Takedown
Cybersecurity

Breaking Affiliate Trust Sped Along LockBit’s Takedown

primereportsBy primereportsJuly 27, 2026No Comments6 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Breaking Affiliate Trust Sped Along LockBit’s Takedown
Share
Facebook Twitter LinkedIn Pinterest Email


Undermining affiliates’ trust and strong international partnerships were the keys to dismantling LockBit, one the most successful ransomware-as-a-service (RaaS) groups of its time, which at its peak was responsible for a quarter of all ransomware attacks.

LockBit operated primarily between 2020 and 2024, and Brett Leatherman, assistant director of the FBI’s Cyber Division, tells Dark Reading that during its time it victimized more than 2,500 organizations across at least 120 countries, with more than 1,800 of these attacks occurring in the US. Overall, the group collected more than $500 million in ransom payments, and the group and its leader, a Russian national named Dmitry Yuryevich Khoroshev, seemed invincible.

LockBit’s RaaS enterprise “for a time … was the most successful criminal business in the world,” Leatherman says. Indeed, by the time the group was disrupted, it included a network of nearly 200 affiliates doing its dirty work, with Khoroshev collecting 20 cents on every dollar of ransom earned by that network, he ways.

Related:CISOs vs. Boards: Myth or Misunderstanding?

That’s until a law-enforcement effort called Operation Cronos targeted the group in February 2024 (part of the wider Operation Endgame effort), seizing LockBit’s infrastructure and doing permanent damage to its reputation and day-to-day operations. The law-enforcement operation took control of LockBit’s own platform, from the leak site to the control panel to the source code and the data inside it, seizing LockBit’s servers and putting decryption keys in victims’ hands, Leatherman says.

Leatherman and Paul Foster, deputy director of the National Cyber Crime Unit of the National Crime Agency (NCA), will unpack Operation Cronos in a session called “Anatomy of a Takedown: Inside the Operation That Broke LockBit” at Black Hat USA 2026 next week in Las Vegas.

Operation Cronos: Breaking & Building Trust

One of the core reasons for the success of the operation — which the FBI ran in collaboration with the UK’s National Crime Agency, Europol, and 10 other international partners — was breaking the trust relationship the group had established with its network of affiliates, who had been promised anonymity and long-term success with the group, Leatherman tells Dark Reading. Specifically, the effort created a rift with those partnerships by using the group’s own leak site to “out” them.

“Trust is what ransomware-as-a-service actually sells,” Leatherman explains. “An affiliate hands the platform his access, his malware builds, his negotiations, and his money and what he buys in return is anonymity and a payday.”

Related:Escape Artists: ‘Incorrigible’ AI Models Resist Rehabilitation

After Operation Cronos seized and took down LockBit’s technical infrastructure to cripple the group, it created countdown clocks on the leak site.

“Law enforcement published affiliate names with a simple message: We know who they are and we will be watching,” Leatherman explains. “And we let their own servers tell the truth about them: They kept victim data that they promised to delete, and some paying victims got broken decryptors and no support.”

Indeed, the FBI and its partners knew that targeting the group’s capability was not enough to successfully knock them out of action, according to Leatherman. Officials also needed to damage LockBit’s credibility in a way that it could never recover, which it still to this day has not, Leatherman says. “A criminal enterprise can rebuild a server in a day, but rebuilding trust is a much harder problem,” he says.

Meanwhile, agents focused on forging strong trust and partnerships with other law-enforcement agencies — which “at the time was genuinely rare.”

“The collaboration of all agencies was inevitably key” to the success of the operation,” concurs the NCA’s Foster. “Each agency using its own unique skills and accesses to deliver a greater substantial impact required close cooperation and alignment.”

Related:Europe’s Multilingual Reality Exposes AI Security Gaps

Though some of its LockBit’s pieces remain in operation today, several of its key members have been arrested, and others have been charged with crimes, so the group itself is no longer a major player on the international ransomware stage. Khoroshev remains at large, but has been sanctioned and charged on several criminal counts by the US Department of Justice, which has offered a $10 million reward for information leading to his arrest.

Two and a half years after Operation Cronos, LockBit remains a minor player in ransomware ecosystem, but has been “signicantly degraded in impact and credibility,” Leatherman says. “The ransomware landscape is now significantly different,” Foster says. “We have moved away from LockBit being a single dominant force with other smaller ransomware strains alongside them, to a landscape where there is no real dominant strain.”

Indeed, LockBit’s average attacks in the UK have fallen 73% since disruption, with “a similar decrease in the US,” he says, citing numbers by Chainanalysis, a company that helps track cryptocurrency, which found that LockBit’s ransom payments in the US fell 79% in the second half of 2024.

Lessons Learned From LockBit’s Takedown

Law enforcement learned some important lessons that the FBI and other agencies have carried into their future investigations and activities, Leatherman says, sharing three takeaways with Dark Reading.

One is that when faced with the investigation of a cybercrime ecosystem, authorities needs to see “reputation as an operational asset,” and go after that as much as any tangible infrastructure or other asset a group and its partners may have, he says. “LockBit spent years building that reputation that it could protect its affiliates and pay them and we proved in one coordinated operation that they could do neither,” he says.

Another lesson is that the centralization of infrastructure, such as LockBit had — controlling the affiliates from a central hub — “cuts both ways,” Leatherman says. “On one hand, it’s efficient for LockBit to have a centralized platform in which to conduct their operations, but on the other it was also efficient for us to target that system as well.”

Since then, threat actors have started to decentralize their operations in response to law enforcement’s ability to more easily attack a central hub, which has also forced investigators to change their tactics, Leatherman says.

A third lesson from Operation Cronos was more “reaffirmed” than learned, he says, and that is: “A ransomware group is a marketplace,” and “the malware is just a name for the storefront,” that has “a small core group of people bulid the tools and take the cuts.”

However, around that, “sits a wider economy of affiliates, access brokers and money launderers,” he says, which should be the true target for any law-enforcement operation that wishes for a successful takedown. “We have to go after that ecosystem and by going after that ecosystem it undercuts their ability to operate.”



Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleOil markets are on edge again
Next Article BitMEX Faces Proposed Class Action Seeking Return Of 622 BTC
primereports
  • Website

Related Posts

Cybersecurity

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

July 27, 2026
Cybersecurity

Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack

July 27, 2026
Cybersecurity

Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached

July 26, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Paxton’s win over Cornyn sets up high-stakes Texas clash with Talarico

May 28, 202616 Views

Global Resources Outlook 2024 | UNEP

December 6, 202510 Views

Texas Democrat Talarico claims voting laws are rigged ahead of Paxton race

May 28, 20269 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • ‘A disaster for America First’: Trump allies fear Netanyahu meeting will pull US deeper into war with Iran – Politico
  • AI Hosts And Sandboxes Save Intel’s Datacenter CPU Cookies
  • How one man’s near-death experience led to the discovery of the first Jurassic sea dragon in Wales | Fossils
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.