Skip to content

LockBit

Ransomware Group2 claimsLast activity:

Overview

LockBit is a financially motivated ransomware-as-a-service operation that began operating in 2019 and was first observed in attacks around January 2020. A joint CISA and international-partner advisory describes a global affiliate program that became one of the most deployed ransomware operations. International law enforcement severely disrupted LockBit in February 2024, but Check Point Research documented the launch of LockBit 5.0 and renewed activity in September 2025. The LockBit name can also appear on malware built from leaked code, so a matching payload or ransom note does not by itself establish participation by the core service.

Activity and targeting

LockBit affiliates have attacked public- and private-sector organizations across many industries and countries. The U.S. Department of Justice said the operation had targeted more than 2,000 victims worldwide before the February 2024 disruption, including critical infrastructure, government, education, healthcare, manufacturing, logistics, insurance and semiconductor organizations. These figures describe law-enforcement findings about the service as a whole; individual leak-site listings and affiliate claims still require incident-specific corroboration.

Operation Cronos seized public-facing sites and servers, obtained decryption material and exposed victim and affiliate intelligence. The action degraded the operation but did not permanently eliminate the brand. Check Point later observed LockBit 5.0 attacks in the United States, Mexico, Indonesia and Europe, while noting that the return might re-centralize affiliates around the established name.

Methods and operational characteristics

LockBit’s core operators develop ransomware, maintain control panels and negotiation or leak infrastructure, and recruit affiliates. Affiliates select and access victims, sometimes by exploiting vulnerabilities or using stolen credentials purchased from other criminals. The service supports encryption, data theft and demands for payment in exchange for decryption and non-publication; the Justice Department also identified StealBit infrastructure used to organize and transfer victim data.

The operation has iterated through multiple malware generations and supports Windows, Linux and VMware ESXi environments. Check Point reported that LockBit 5.0 added evasion and anti-analysis features, faster encryption, randomized file extensions and private negotiation portals. Because affiliates bring their own access methods and tools, no single intrusion chain should be generalized to every LockBit case.

What type of group is it?

LockBit is best characterized as a financially motivated ransomware group operating an affiliate service. Core developers and administrators provide the brand, malware and infrastructure, while affiliates conduct many of the intrusions and share ransom proceeds. Government actions identify and allege roles for specific administrators and affiliates, but criminal charges remain allegations unless resolved in court. The reviewed sources do not establish state direction or political motivation. Attribution should also distinguish the service from unaffiliated actors using leaked LockBit builders.

Incident claims

Delano Public Schools ransomware cancels classes

View public claim
Incident date: Source: ransomware.livePublished: Discovered:

Claim details

On Jun. 9, 2026, the LockBit 5.0 ransomware/extortion site listed delano.k12.mn.us, the domain used by Delano Public Schools, on its leak site with a stated deadline of Jun. 24, 2026. The post appeared about three weeks after the publicly reported start of the incident, which was reported as either Monday evening, May 18, or Tuesday morning, May 19. The timing is consistent with a delayed extortion or leak-site escalation following an earlier intrusion, but the claim remains unverified. The posting included a short description of the district and links labeled as stolen data, but DysruptionHub has not independently verified the authenticity, scope or sensitivity of the claimed data. The listing increases confidence that the incident involved an extortion component and likely data theft, but it does not, by itself, confirm that ransomware encryption occurred or that LockBit was the original intruder.

Town of Orange outage and LockBit claim

View public claim
Incident date: Source: otherPublished:

Claim details

DysruptionHub documented a LockBit5 leak-site listing for townoforangeva.gov with a March 5, 2026 upload date. The Town of Orange has not confirmed the claim or linked it to the February outage.

Impacted organizations

Impacted locations

Sources