Ransomware dossier

LockBit

The most prolific ransomware-as-a-service operation of the decade. Russian-speaking, affiliate-driven, with a long-running leak site. Disrupted by Operation Cronos in 2024 — infrastructure seized and operator “LockBitSupp” (Dmitry Khoroshev) named and sanctioned — yet it continues to claim victims.

⚠ Sanctioned. OFAC / UK NCA / FBI 2024 (Operation Cronos) — LockBitSupp (Dmitry Khoroshev) designated. Paying this group may breach sanctions law — check with legal counsel and law enforcement before any payment is discussed.

Claimed victims

3,315

Top region

US

Top sector

Manufacturing

Suspected origin

Russia

Latest claimed victims

Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.

DateOrganisation (claimed)SectorCountry
2026-09-29spg.co.krOtherKR
2026-09-29camorim.com.brRetail & E-CommerceBR
2026-09-25taspenlife.comHealthcareKZ
2026-09-25anery.com.brAgriculture and Food ProductionBR
2026-09-25corisricambi.itOtherIT
2026-09-21siinqeebank.comFinancial ServicesSO
2026-09-18hygear.comHealthcareDE
2026-09-18forus.clProfessional ServicesCL
2026-09-14tpi.twTechnologyTW
2026-09-14comune.robeccosulnaviglio.mi.itGovernment & DefenseIT

Regions targeted

US 19DE 17IT 12BR 11NL 11FR 6MX 5TH 5

Sectors targeted

Manufacturing 24Professional Services 23Healthcare 16Technology 12Agriculture and Food Production 11Business Services 9

Suspected origin

Russia — Russian-speaking RaaS; operator indicted as a Russian national. Attribution reflects open-source consensus, not certainty.

Track it daily

Ransomware moves every day. So does our paper.

The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.

Read today's Daily →Browse the archive

Defender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.

← All ransomware groups