LockBit
The most prolific ransomware-as-a-service operation of the decade. Russian-speaking, affiliate-driven, with a long-running leak site. Disrupted by Operation Cronos in 2024 — infrastructure seized and operator “LockBitSupp” (Dmitry Khoroshev) named and sanctioned — yet it continues to claim victims.
Claimed victims
3,315
Top region
US
Top sector
Manufacturing
Suspected origin
Russia
Latest claimed victims
Victims as claimed by the group on its leak site and tracked in our graph — claims are not independently verified, and listing here is not confirmation a breach occurred.
| Date | Organisation (claimed) | Sector | Country |
|---|---|---|---|
| 2026-09-29 | spg.co.kr | Other | KR |
| 2026-09-29 | camorim.com.br | Retail & E-Commerce | BR |
| 2026-09-25 | taspenlife.com | Healthcare | KZ |
| 2026-09-25 | anery.com.br | Agriculture and Food Production | BR |
| 2026-09-25 | corisricambi.it | Other | IT |
| 2026-09-21 | siinqeebank.com | Financial Services | SO |
| 2026-09-18 | hygear.com | Healthcare | DE |
| 2026-09-18 | forus.cl | Professional Services | CL |
| 2026-09-14 | tpi.tw | Technology | TW |
| 2026-09-14 | comune.robeccosulnaviglio.mi.it | Government & Defense | IT |
Regions targeted
Sectors targeted
Suspected origin
Russia — Russian-speaking RaaS; operator indicted as a Russian national. Attribution reflects open-source consensus, not certainty.
Track it daily
Ransomware moves every day. So does our paper.
The Probably Fine Daily is our morning threat-intelligence briefing — new victims, new groups, what actually matters, in plain English. Free.
Read today's Daily →Browse the archiveDefender-oriented threat intelligence. Nothing here assists an attack. Attribution and lineage reflect open-source reporting.