?Formally attributedActive

LockBit

Coverage omission — Eastern

Prolific ransomware-as-a-service operation that became the most deployed ransomware globally from 2022 to 2024. Disrupted by law enforcement Operation Cronos in February 2024 but resumed operations shortly after.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
3.1
Moderate signal strength
Mentions9
Sources2
High conf.4
Last seenJun 2026
First observed
2019
Last active
Active
Origin
Eastern Europe — leader identified as Russian national by law enforcement
Aliases
5
Techniques
0
Campaigns
0
Eastern Europe — leader identified as Russian national by law enforcementhigh confidence
TargetsGovernmentHealthcareFinancialManufacturingLegal
RegionsUsEuGlobal

Attribution signals

9 mentions · 2 sources
#1attributed tohigh
Unspecified
flu-project
Jun 2026

"The attack was attributed to the LockBit ransomware group, which not only stole the information but also encrypted it, demanding a ransom."

#2uncoveredhigh
HUMINT
coveware
Jun 2026

"law enforcement from 10 countries (including Australia) successfully disrupted the criminal operation of the LockBit ransomware group and uncovered that Lockbit did not routinely delete stolen data once a ransom was paid"

#3suspectedlow
Malware
huntress
Jun 2026

"Based on several clues, the threat actors behind the attacks are suspected to be using the previously leaked LockBit 3.0 builder."

#4possibilitylow
Malware
huntress
Jun 2026

"one possibility is that the threat group behind this incident was using the LockBit builder that had previously been leaked in 2022."

#5unspecifiedhigh
Unspecified
wired-security
May 2026

"The LockBit group hit another Foxconn facility in Mexico in May 2022 and disrupted production."

#6unspecifiedunspecified
Unspecified
socradar
Jun 2026

"Brazil = #2 target country in Q1 2026 (8.6% of victims)"

#7unspecifiedhigh
Unspecified
wired-security
May 2026

"Most recently, LockBit attacked a subsidiary called Foxsemicon Integrated Technology in 2024 with defacements and data breach claims."

#8unspecifiedunspecified
Malware
huntress
Jun 2026

"In some incidents, threat actors have used the compromised Bomgar instances to deploy the LockBit ransomware."

#9unspecifiedunspecified
Geopolitical
socradar
Jun 2026

"Brazil bearing the brunt of an extensive and unequal increase in global cyber threat activity"

Hedge terms observed

attributed topossibilitysuspecteduncoveredunspecified