FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown
The FBI, in collaboration with international law enforcement agencies, successfully dismantled LockBit, one of the most prolific ransomware-as-a-service (RaaS) groups, through Operation Cronos. The operation focused on breaking the trust LockBit had established with its affiliate network by publicly exposing them and fostering strong partnerships with other law enforcement agencies. This resulted in a significant decline in LockBit's operations and ransom payments, with a 73% drop in attacks in the UK and a 79% drop in US payments since the takedown. The effort highlighted the importance of targeting a ransomware group's reputation and broader ecosystem rather than solely focusing on infrastructure.
The FBI, in collaboration with the UK’s National Cyber Crime Unit (NCA) and other international partners, successfully disrupted LockBit, a leading ransomware-as-a-service (RaaS) group, with Operation Cronos. LockBit operated between 2020 and 2024, victimizing over 2,500 organizations across 120 countries and collecting more than $500 million in ransom payments. The group relied heavily on a network of affiliates, with its leader, Dmitry Yuryevich Khoroshev, remaining at large and subject to US Department of Justice sanctions.
Operation Cronos targeted LockBit’s infrastructure and, crucially, its reputation. The operation involved publishing affiliate names and a message stating that law enforcement knew who they were and would be watching, coupled with exposing the affiliates’ continued practice of holding victim data despite promises to delete it and providing broken decryptors. This strategy directly undermined LockBit’s ability to maintain trust with its affiliates.
Beyond targeting the technical infrastructure – including the leak site, control panel, and source code – law enforcement actively forged strong partnerships with other agencies, emphasizing close cooperation and alignment of skills and access to deliver a greater impact. Since the takedown, LockBit’s influence has diminished significantly, with ransom payments in the UK falling 73% and in the US by 79% according to Chainanalysis data from the second half of 2024.
Law enforcement agencies have learned key lessons from Operation Cronos. Firstly, targeting a ransomware group requires focusing on its reputation as an operational asset, rather than solely targeting infrastructure. Secondly, the centralization of LockBit’s operations – controlling its affiliates from a central hub – was a double-edged sword, allowing law enforcement to effectively target that system. Finally, the FBI and its partners recognized that ransomware groups operate within a broader ecosystem of affiliates, access brokers, and money launderers, and that these elements should be the primary target for successful takdowns.
The operation is being discussed at Black Hat USA 2026, where agents Leatherman and Foster will unpack the details.
Black Hat USA Aug 1, 2026 TO Aug 6, 2026 |Mandalay Bay Convention Center, Las Vegas, USA The premier cybersecurity event of the year returns to Mandalay Bay with a re‑engineered, six‑day program built to ignite innovation, push boundaries, and bring the global security community together like never before. This year’s event features four days of immersive, expert‑led Trainings (August 1–4), followed by Summit Day on Tuesday, August 4, and a two‑day main conference packed with groundbreaking Briefings, open‑source tool demos in Arsenal, a dynamic Business Hall, and unlimited learning & networking opportunities. Use code: DARKREADING to save $200 on a Briefings pass or $100 on a Business pass.
