How the FBI Took Down LockBit by Destroying the One Thing Criminals Can't Easily Replace: Trust
Operation Cronos didn't just seize servers. It turned LockBit's own website against its partners, shattered the group's reputation, and cut ransom attacks in the US by nearly 80 percent.

Key points
- LockBit collected more than $500 million in ransom payments from over 2,500 organisations across at least 120 countries between 2020 and 2024.
- Operation Cronos, launched in February 2024, saw the FBI, the UK's National Crime Agency, Europol, and ten other partner agencies seize LockBit's servers, control panels, and source code.
- Law enforcement used LockBit's own website to publicly identify its criminal partners, deliberately destroying the anonymity those partners had been promised.
- LockBit's average attacks in the UK have fallen 73 percent since the disruption, with US ransom payments dropping 79 percent in the second half of 2024.
- LockBit's leader, Russian national Dmitry Yuryevich Khoroshev, remains at large; the US Department of Justice has offered a $10 million reward for information leading to his arrest.
For four years, LockBit was the closest thing the criminal world had to a franchise empire. At its peak, the group was responsible for roughly one in four ransomware attacks globally. Ransomware is malicious software that scrambles a victim's files and demands a payment to unlock them. LockBit perfected the business model.
How did LockBit actually work?
LockBit ran what's called a ransomware-as-a-service operation, meaning it didn't always attack victims directly. Instead, it recruited roughly 200 outside contractors, called affiliates, who carried out the actual attacks using LockBit's tools. The group's leader, Khoroshev, took 20 cents from every dollar those affiliates earned. In exchange, affiliates were promised two things: anonymity and a reliable payday.
Between 2020 and 2024, that arrangement produced over $500 million in ransom payments, with more than 1,800 attacks hitting organisations in the United States alone. Brett Leatherman, assistant director of the FBI's Cyber Division, told Dark Reading the group "was the most successful criminal business in the world" during its peak.
How did law enforcement bring them down?
Agencies didn't just unplug the servers. That, by itself, wouldn't have been enough.
In February 2024, a coordinated effort called Operation Cronos gave law enforcement full control of LockBit's platform: its public-facing leak site (a website criminals use to publish stolen data and pressure victims into paying), its control panel, and its underlying source code. Officials handed decryption keys to victims so they could recover their files without paying.
Then came the move that proved most damaging. Authorities used LockBit's own leak site to publish the identities of its affiliates, with a blunt message: we know who you are, and we are watching. They also revealed that LockBit had kept victim data it promised to delete, and had given some paying victims broken recovery tools with no follow-up support.
"A criminal enterprise can rebuild a server in a day," Leatherman said, "but rebuilding trust is a much harder problem."
| Metric | Figure | Period |
|---|---|---|
| Victims worldwide | 2,500+ organisations | 2020 to 2024 |
| Countries affected | 120+ | 2020 to 2024 |
| US attacks | 1,800+ | 2020 to 2024 |
| Total ransom collected | $500 million+ | 2020 to 2024 |
| Drop in UK attacks | 73% | Post-disruption |
| Drop in US ransom payments | 79% | Second half of 2024 |
Should ordinary people still be worried about LockBit?
LockBit is no longer a major player. Some fragments of the group still exist, but Leatherman describes it as "significantly degraded in impact and credibility." Paul Foster, deputy director of the UK's National Crime Agency, said the ransomware world has shifted from one dominant group to a more scattered picture with no clear leader.
That's better news, though not a reason to relax. Other groups have learned from LockBit's downfall and are deliberately spreading their operations across many systems rather than centralising them, which makes future takedowns harder.
Khoroshev himself remains free. Anyone with information about his whereabouts can report it to the FBI; the $10 million reward stands.
For anyone whose organisation has ever been contacted by criminals claiming to hold their data, the FBI's advice is consistent: report it, and check whether law enforcement already holds a decryption key before considering any payment.


