Lockbit cybercrime gang disrupted in global takedown

An international law enforcement operation led by the United Kingdom's National Crime Agency and the FBI has arrested and indicted members of the Lockbit ransomware gang, in an unprecedented police operation that has struck one of the world's most notorious cybercrime gangs.

The United States has charged two Russian citizens with deploying Lockbit ransomware against companies and groups around the world.

Police in Poland and Ukraine made two arrests.

The NCA, US Department of Justice, FBI and Europol gathered in London to announce the disruption of the gang, which has targeted more than 2000 victims worldwide and received more than $US120 million ($A183 million) in ransom payments, the DOJ said.

The UK's National Crime Agency Cyber Division, with the US Department of Justice, the FBI and other law enforcement agencies seized control of websites used by Lockbit, US and UK authorities said. 

The agencies used Lockbit's own website to release internal data about the group itself.

“We have hacked the hackers," Graeme Biggar, director general of the National Crime Agency, told reporters.

"We have taken control of their infrastructure, seized their source code and obtained keys that will help victims decrypt their systems".

The takedown, dubbed "Operation Cronos" was an international coalition of countries including Australia, he said. 

"Together, we have arrested, indicted or sanctioned some of the perpetrators and we have gained unprecedented and comprehensive access to Lockbit’s systems".

"As of today, Lockbit is effectively redundant," he added.

"Lockbit has been locked out".

A representative for Lockbit did not respond to messages from Reuters seeking comment.

Obtained in New Jersey, the unsealed indictment charges Artur Sungatov and Ivan Kondratyev, also known as Bassterlord, with using Lockbit ransomware to target victims in manufacturing, logistics, insurance and other companies in five US states and Puerto Rico as well as in semiconductor and other industries around the world.

Additional criminal charges against Kondratyev were unsealed on Tuesday related to his use of ransomware in 2020 against a victim in California, the Justice department said.

Both men were also sanctioned by the US Treasury.

Graeme Biggar and other officials
"We have hacked the hackers," Graeme Biggar of the UK National Crime Agency has told reporters.

In November last year, Lockbit published internal data from Boeing, one of the world's largest defence and space contractors, and said the US arm of China's ICBC had paid a ransom following an attack that disrupted trades in the US Treasury market.

In early 2023, Britain’s Royal Mail faced severe disruption after an attack by the group.

Ransomware is malicious software that encrypts data; Lockbit and its affiliates makes money by coercing its targets into paying ransom to decrypt or unlock that data with a digital key. 

The gang's digital extortion tools have been used against some of the world’s largest organisations in recent months.

Its affiliates are like-minded criminal groups that Lockbit recruits to wage attacks using those tools. 

Those affiliates carry out the attacks, and provide Lockbit a cut of the ransom, which is usually demanded in the form of cryptocurrency, making it harder to trace.

Operation Cronos seized 34 of Lockbit's servers, arrested two members of the gang, froze 200 cryptocurrency accounts and closed 14,000 "rogue accounts" used online to launch Lockbit's operations, the police agencies said.

Lockbit has caused monetary losses totalling billions, the NCA's Biggar said, to businesses who not only had to pay ransom payments but also had to shoulder the cost of getting their systems back online.

Before it was taken down, Lockbit's website displayed an ever-growing gallery of victim organisations that was updated nearly daily. 

Next to their names were digital clocks that showed the number of days left to the deadline given to each organisation to provide ransom payment.

On Tuesday, the Lockbit leak website had been transformed by the NCA, FBI and Europol into a leak site about the criminal gang itself, onto which international police agencies published internal data from inside the group, and countdown clocks threatening to reveal upcoming sanctions and the identity of Lockbit's ringleader "LockbitSupp".

License this article

What is AAPNews?

For the first time, Australian Associated Press is delivering news straight to the consumer.

No ads. No spin. News straight-up.

Not only do you get to enjoy high-quality news delivered straight to your desktop or device, you do so in the knowledge you are supporting media diversity in Australia.

AAP Is Australia’s only independent newswire service, free from political and commercial influence, producing fact-based public interest journalism across a range of topics including politics, courts, sport, finance and entertainment.

What is AAPNews?
The Morning Wire

Wake up to AAPNews’ morning news bulletin delivered straight to your inbox or mobile device, bringing you up to speed with all that has happened overnight at home and abroad, as well as setting you up what the day has in store.

AAPNews Morning Wire
AAPNews Breaking News
Breaking News

Be the first to know when major breaking news happens.


Notifications will be sent to your device whenever a big story breaks, ensuring you are never in the dark when the talking points happen.

Focused Content

Enjoy the best of AAP’s specialised Topics in Focus. AAP has reporters dedicated to bringing you hard news and feature content across a range of specialised topics including Environment, Agriculture, Future Economies, Arts and Refugee Issues.

AAPNews Focussed Content
Subscription Plans

Choose the plan that best fits your needs. AAPNews offers two basic subscriptions, all billed monthly.

Once you sign up, you will have seven days to test out the service before being billed.

AAPNews Full Access Plan
Full Access
AU$10
  • Enjoy all that AAPNews has to offer
  • Access to breaking news notifications and bulletins
  • Includes access to all AAPNews’ specialised topics
Join Now
AAPNews Student Access Plan
Student Access
AU$5
  • Gain access via a verified student email account
  • Enjoy all the benefits of the ‘Full Access’ plan at a reduced rate
  • Subscription renews each month
Join Now
AAPNews Annual Access Plan
Annual Access
AU$99
  • All the benefits of the 'Full Access' subscription at a discounted rate
  • Subscription automatically renews after 12 months
Join Now

AAPNews also offers enterprise deals for businesses so you can provide an AAPNews account for your team, organisation or customers. Click here to contact AAP to sign-up your business today.

SEVEN DAYS FREE
Download the app
Download AAPNews on the App StoreDownload AAPNews on the Google Play Store