Feeds.Feedburner Operation Cronos Successfully Dismantles LockBit Ransomware Group
Article Content
- •Operation Cronos dismantled LockBit, a major ransomware-as-a-service group.
- •LockBit was responsible for over 2,500 attacks and $500 million in ransom payments.
- •The operation exposed affiliate identities, eroding trust and crippling the group's operations.
Operation Cronos, an international law enforcement initiative, effectively dismantled the LockBit ransomware group, which operated from 2020 to 2024 and was responsible for over 2,500 attacks worldwide, extorting more than $500 million in ransom. The operation, executed by the FBI in collaboration with the UK's National Crime Agency and Europol, targeted LockBit's infrastructure, including its leak site and control panels. A key strategy involved undermining trust between LockBit and its nearly 200 affiliates by exposing their identities on the group's leak site. This tactic aimed to cripple the ransomware-as-a-service model that relied heavily on affiliate confidence. As a result of the operation, LockBit's credibility and operational capacity have significantly declined, leading to a reduction in ransomware attacks attributed to the group. The FBI's efforts have altered the ransomware landscape by removing a dominant force in the field.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Lockbit in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…