Undermining affiliates’ trust and strong international partnerships were the keys to dismantling LockBit, one the most successful ransomware-as-a-service (RaaS) groups of its time, which at its peak was responsible for a quarter of all ransomware attacks.
LockBit operated primarily between 2020 and 2024, and Brett Leatherman, assistant director of the FBI’s Cyber Division, tells Dark Reading that during its time it victimized more than 2,500 organizations across at least 120 countries, with more than 1,800 of these attacks occurring in the US. Overall, the group collected more than $500 million in ransom payments, and the group and its leader, a Russian national named Dmitry Yuryevich Khoroshev, seemed invincible.
LockBit’s RaaS enterprise “for a time … was the most successful criminal business in the world,” Leatherman says. Indeed, by the time the group was disrupted, it included a network of nearly 200 affiliates doing its dirty work, with Khoroshev collecting 20 cents on every dollar of ransom earned by that network, he ways.
That’s until a law-enforcement effort called Operation Cronos targeted the group in February 2024 (part of the wider Operation Endgame effort), seizing LockBit’s infrastructure and doing permanent damage to its reputation and day-to-day operations. The law-enforcement operation took control of LockBit’s own platform, from the leak site to the control panel to the source code and the data inside it, seizing LockBit’s servers and putting decryption keys in victims’ hands, Leatherman says.
Leatherman and Paul Foster, deputy director of the National Cyber Crime Unit of the National Crime Agency (NCA), will unpack Operation Cronos in a session called “Anatomy of a Takedown: Inside the Operation That Broke LockBit” at Black Hat USA 2026 next week in Las Vegas.
Operation Cronos: Breaking & Building Trust
One of the core reasons for the success of the operation — which the FBI ran in collaboration with the UK’s National Crime Agency, Europol, and 10 other international partners — was breaking the trust relationship the group had established with its network of affiliates, who had been promised anonymity and long-term success with the group, Leatherman tells Dark Reading. Specifically, the effort created a rift with those partnerships by using the group’s own leak site to “out” them.
“Trust is what ransomware-as-a-service actually sells,” Leatherman explains. “An affiliate hands the platform his access, his malware builds, his negotiations, and his money and what he buys in return is anonymity and a payday.”
After Operation Cronos seized and took down LockBit’s technical infrastructure to cripple the group, it created countdown clocks on the leak site.
“Law enforcement published affiliate names with a simple message: We know who they are and we will be watching,” Leatherman explains. “And we let their own servers tell the truth about them: They kept victim data that they promised to delete, and some paying victims got broken decryptors and no support.”
Indeed, the FBI and its partners knew that targeting the group’s capability was not enough to successfully knock them out of action, according to Leatherman. Officials also needed to damage LockBit’s credibility in a way that it could never recover, which it still to this day has not, Leatherman says. “A criminal enterprise can rebuild a server in a day, but rebuilding trust is a much harder problem,” he says.
Meanwhile, agents focused on forging strong trust and partnerships with other law-enforcement agencies — which “at the time was genuinely rare.”
“The collaboration of all agencies was inevitably key” to the success of the operation,” concurs the NCA’s Foster. “Each agency using its own unique skills and accesses to deliver a greater substantial impact required close cooperation and alignment.”
Though some of its LockBit’s pieces remain in operation today, several of its key members have been arrested, and others have been charged with crimes, so the group itself is no longer a major player on the international ransomware stage. Khoroshev remains at large, but has been sanctioned and charged on several criminal counts by the US Department of Justice, which has offered a $10 million reward for information leading to his arrest.
Two and a half years after Operation Cronos, LockBit remains a minor player in ransomware ecosystem, but has been “signicantly degraded in impact and credibility,” Leatherman says. “The ransomware landscape is now significantly different,” Foster says. “We have moved away from LockBit being a single dominant force with other smaller ransomware strains alongside them, to a landscape where there is no real dominant strain.”
Indeed, LockBit’s average attacks in the UK have fallen 73% since disruption, with “a similar decrease in the US,” he says, citing numbers by Chainanalysis, a company that helps track cryptocurrency, which found that LockBit’s ransom payments in the US fell 79% in the second half of 2024.
Lessons Learned From LockBit’s Takedown
Law enforcement learned some important lessons that the FBI and other agencies have carried into their future investigations and activities, Leatherman says, sharing three takeaways with Dark Reading.
One is that when faced with the investigation of a cybercrime ecosystem, authorities needs to see “reputation as an operational asset,” and go after that as much as any tangible infrastructure or other asset a group and its partners may have, he says. “LockBit spent years building that reputation that it could protect its affiliates and pay them and we proved in one coordinated operation that they could do neither,” he says.
Another lesson is that the centralization of infrastructure, such as LockBit had — controlling the affiliates from a central hub — “cuts both ways,” Leatherman says. “On one hand, it’s efficient for LockBit to have a centralized platform in which to conduct their operations, but on the other it was also efficient for us to target that system as well.”
Since then, threat actors have started to decentralize their operations in response to law enforcement’s ability to more easily attack a central hub, which has also forced investigators to change their tactics, Leatherman says.
A third lesson from Operation Cronos was more “reaffirmed” than learned, he says, and that is: “A ransomware group is a marketplace,” and “the malware is just a name for the storefront,” that has “a small core group of people bulid the tools and take the cuts.”
However, around that, “sits a wider economy of affiliates, access brokers and money launderers,” he says, which should be the true target for any law-enforcement operation that wishes for a successful takedown. “We have to go after that ecosystem and by going after that ecosystem it undercuts their ability to operate.”
