How the FBI Dismantled the World's Largest Ransomware Group
A detailed account from an FBI agent involved in Operation Cronos reveals how a multinational law enforcement coalition took down LockBit, once the most prolific ransomware-as-a-service (RaaS) operation in the world. The key weapon: destroying the trust that held LockBit's affiliate network together.
Speaking with Dark Reading, the FBI agent explained that while technical infiltration of LockBit's infrastructure was critical, the psychological and operational blow of fracturing affiliate trust proved equally decisive in the group's eventual collapse.
LockBit at Its Peak
Before Operation Cronos, LockBit dominated the ransomware landscape:
| Metric | Detail |
|---|---|
| Active period | 2019–2024 |
| RaaS model | Affiliates paid ~80% of ransom proceeds |
| Estimated victims | 2,000+ organizations worldwide |
| Estimated proceeds | $120 million+ in ransom payments |
| Notable victims | Boeing, Royal Mail, Ion Group, ICBC |
| Geographic reach | Global — no sector spared |
LockBit's success was built on a franchise model. The core developers maintained the ransomware toolkit while affiliates — independent criminal operators — handled intrusions, negotiations, and victim selection. This separation gave the operation resilience: taking down one affiliate barely dented the whole.
Operation Cronos: The International Takedown
In February 2024, agencies from 11 countries executed Operation Cronos simultaneously, seizing LockBit's infrastructure, arresting key members, and publicly exposing the group's internal workings.
Participating Agencies
- FBI (United States)
- National Crime Agency — NCA (United Kingdom)
- Europol and Eurojust (EU)
- Law enforcement from France, Germany, Netherlands, Sweden, Australia, Canada, Japan, and Switzerland
What Was Seized
| Asset | Details |
|---|---|
| Servers | 34 LockBit servers seized across multiple countries |
| Websites | LockBit leak site and admin panels taken down |
| Wallets | 200+ cryptocurrency wallets frozen |
| Decryptors | 1,000+ decryption keys recovered and distributed to victims |
| Individuals | Multiple arrests, including key administrators |
The Trust Fracture Strategy
The FBI agent's account highlights that the operation went beyond infrastructure seizure — it weaponized information against LockBit's affiliate network.
Exposing the Affiliate List
Investigators accessed LockBit's admin panel and backend systems, obtaining the identities and communications of LockBit affiliates. Law enforcement then published portions of this data on the seized LockBit leak site — turning the group's own public shaming tool against itself.
"When affiliates saw that their operator had been compromised and their identities potentially exposed, the trust that held this criminal ecosystem together evaporated," the FBI agent explained.
Publishing LockBit's Internal Data
Rather than quietly using gathered intelligence, Operation Cronos opted for maximum public exposure:
- Took over the LockBit leak site and replaced it with law enforcement seizure notices
- Published LockBit's affiliate panel structure and statistics, embarrassing the group's leadership
- Named LockBit's lead developer — Dmitry Yuryevich Khoroshev ("LockBitSupp") — publicly, alongside a $10 million reward
- Released decryptors for victims, undermining the value of LockBit's encryption
Why Affiliate Trust Mattered
The RaaS model depends entirely on affiliate confidence that:
- The platform is technically secure
- The operator won't get compromised
- Payment will be honored
- Identities will be protected
Operation Cronos shattered all four pillars simultaneously.
LockBit's Attempted Comeback — and Continued Decline
After the February 2024 operation, LockBit's leader attempted to relaunch the service, downplaying the takedown's impact. However, the operational and reputational damage proved severe:
- Affiliate recruitment dried up as criminal operators moved to competing RaaS platforms
- Attack volume dropped significantly in the months following Operation Cronos
- Several competing ransomware groups actively recruited former LockBit affiliates, fragmenting the threat landscape
Lessons for Defenders
The LockBit takedown offers clear takeaways for organizations and security teams:
What Worked for Law Enforcement
| Tactic | Why It Worked |
|---|---|
| Multi-jurisdiction coordination | Prevented jurisdiction shopping and simultaneous infrastructure recovery |
| Intelligence exploitation | Captured admin access enabled mapping of the full criminal network |
| Public exposure | Naming affiliates and publishing internal data destroyed operational security |
| Victim support | Releasing 1,000+ decryptors built goodwill and reduced ransom incentive |
Defensive Implications
Ransomware groups are not monolithic. The affiliate trust model is a vulnerability — and law enforcement is learning to exploit it. Future operations will increasingly target the human elements of RaaS ecosystems.
For defenders:
- Segment networks aggressively — limit lateral movement that affiliates rely on during intrusions
- Maintain immutable, offsite backups — decryptors are not always available
- Patch aggressively — LockBit affiliates frequently exploited known vulnerabilities (PrintNightmare, ProxyShell, Citrix Bleed) to gain initial access
- Participate in threat intelligence sharing — many LockBit victims had IoCs available before their breach that went unacted upon
Current Ransomware Landscape
The LockBit takedown reshaped, but did not end, the ransomware threat:
- RansomHub emerged as a dominant platform, attracting displaced LockBit affiliates
- BlackCat/ALPHV also suffered a law enforcement operation in late 2023, further fragmenting the ecosystem
- New entrants like Lynx, Fog, and Qilin have filled gaps in the market
- The total ransomware incident volume remained high through 2025, though the concentration in a single group (LockBit's previous dominance) has given way to a more distributed threat landscape
References
- Dark Reading — FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown
- Europol — Operation Cronos: Law Enforcement Disrupts World's Biggest Ransomware Operation
- U.S. Department of Justice — LockBit Ransomware Disruption