Delano Public Schools ransomware cancels classes
View public claimClaim details
LockBit claimed responsibility and threatened to release allegedly stolen data if the district did not negotiate.
LockBit is a financially motivated ransomware-as-a-service operation that began operating in 2019 and was first observed in attacks around January 2020. A joint CISA and international-partner advisory describes a global affiliate program that became one of the most deployed ransomware operations. International law enforcement severely disrupted LockBit in February 2024, but Check Point Research documented the launch of LockBit 5.0 and renewed activity in September 2025. The LockBit name can also appear on malware built from leaked code, so a matching payload or ransom note does not by itself establish participation by the core service.
LockBit affiliates have attacked public- and private-sector organizations across many industries and countries. The U.S. Department of Justice said the operation had targeted more than 2,000 victims worldwide before the February 2024 disruption, including critical infrastructure, government, education, healthcare, manufacturing, logistics, insurance and semiconductor organizations. These figures describe law-enforcement findings about the service as a whole; individual leak-site listings and affiliate claims still require incident-specific corroboration.
Operation Cronos seized public-facing sites and servers, obtained decryption material and exposed victim and affiliate intelligence. The action degraded the operation but did not permanently eliminate the brand. Check Point later observed LockBit 5.0 attacks in the United States, Mexico, Indonesia and Europe, while noting that the return might re-centralize affiliates around the established name.
LockBit’s core operators develop ransomware, maintain control panels and negotiation or leak infrastructure, and recruit affiliates. Affiliates select and access victims, sometimes by exploiting vulnerabilities or using stolen credentials purchased from other criminals. The service supports encryption, data theft and demands for payment in exchange for decryption and non-publication; the Justice Department also identified StealBit infrastructure used to organize and transfer victim data.
The operation has iterated through multiple malware generations and supports Windows, Linux and VMware ESXi environments. Check Point reported that LockBit 5.0 added evasion and anti-analysis features, faster encryption, randomized file extensions and private negotiation portals. Because affiliates bring their own access methods and tools, no single intrusion chain should be generalized to every LockBit case.
LockBit is best characterized as a financially motivated ransomware group operating an affiliate service. Core developers and administrators provide the brand, malware and infrastructure, while affiliates conduct many of the intrusions and share ransom proceeds. Government actions identify and allege roles for specific administrators and affiliates, but criminal charges remain allegations unless resolved in court. The reviewed sources do not establish state direction or political motivation. Attribution should also distinguish the service from unaffiliated actors using leaked LockBit builders.
LockBit claimed responsibility and threatened to release allegedly stolen data if the district did not negotiate.