U.S. Charges Mastermind Behind LockBit Ransomware, Seeks 185‑Year Sentence
How did LockBit operate?
LockBit worked on a "ransomware as a service" model, allowing cybercriminals to lease the software to launch attacks. This ransomware was responsible for several notable attacks, including incidents involving the UK mail service, a children's hospital, and St. Marys, a small Canadian town in Ontario. In February of this year, efforts by U.S. and UK authorities led to the seizure of websites and servers linked to LockBit, securing keys to assist organizations in data recovery. Alongside Khoroshev, Arthur Sungatov and Ivan Kondratyev were charged for deploying LockBit in attacks within the USA.
What consequences does Khoroshev face?
Was LockBit dismantled?
Despite significant actions by law enforcement, LockBit continues to operate. Recent efforts by the FBI and Europol to take down the group's infrastructure and impede its activities involved seizing servers, capturing essential infrastructure components, and converting the group's data leak site into a law enforcement press portal, significantly hindering LockBit's activities. These actions resulted in the deletion of the group's online infrastructure, including servers in the United States. They provided victims with decryption keys, enabling them to recover their data without ransom. However, despite these actions, some dark websites associated with the group remain active, and the damage from past attacks cannot be undone.