
What happened
On 20 February 2024, the UK's National Crime Agency announced that it had led an international operation, called Operation Cronos, against the LockBit ransomware-as-a-service group. The agency said it had taken control of LockBit's primary administration environment, the dark web leak site used to pressure victims, the Stealbit exfiltration tool infrastructure, and 28 servers run by affiliates. It reported recovering more than 1,000 decryption keys and the group's platform source code, and said two LockBit actors were arrested in Poland and Ukraine while two US-based defendants faced charges.
Months later, on 7 May 2024, the US Treasury's Office of Foreign Assets Control announced sanctions against Dmitry Yuryevich Khoroshev, describing him as the developer and administrator operating under the alias LockBitSupp. The action was coordinated with the Department of Justice, the FBI, the NCA and Australian Federal Police, and accompanied an unsealed indictment and a State Department reward offer.
Confidence and limits
Both the seizure and the sanctions designation come from the agencies that carried them out, which gives strong confidence in the described actions themselves. The identification of Khoroshev as LockBitSupp is presented by Treasury as a sanctions designation and by the Justice Department as an indictment, not as a conviction; at the time these documents were issued, no court had adjudicated the underlying criminal charges, and Khoroshev remained unapprehended. Figures describing total losses attributed to LockBit come from the agencies' own investigative summaries rather than from an audited accounting, and should be read as law-enforcement estimates.
Why it mattered
LockBit had operated for roughly four years as one of the most prolific ransomware-as-a-service brands, supplying tooling and infrastructure to a wide affiliate network in exchange for a cut of ransom proceeds. Seizing the administrative back end rather than only a single server disrupted the affiliate relationships that let the brand scale, and naming an alleged administrator publicly removed the anonymity that ransomware-as-a-service operators depend on to recruit affiliates. The operation showed that law enforcement can meaningfully degrade a ransomware brand's infrastructure even without an arrest of its leadership.
Defensive takeaway
Check the NCA's published decryption resources and No More Ransom before paying any ransom demand associated with the LockBit name, since some victims' files may already be recoverable from the more than 1,000 keys law enforcement obtained.
- Would we know whom to contact at law enforcement if we were hit by a ransomware brand that has since been partially disrupted?
- Do our incident response plans include checking free decryption resources before authorizing any ransom payment?
- Have we reviewed whether our backup and segmentation practices would limit an affiliate's ability to reach both production and backup systems, regardless of which ransomware brand is involved?
Operation Cronos degraded LockBit's infrastructure and reputation without ending ransomware-as-a-service as a business model; the same affiliates and tooling can resurface under a different name, which is why the underlying defensive questions matter more than the fate of any single brand.
If your organization has ever paid or considered paying a ransom to a group using the LockBit brand, check the NCA's recovered decryption keys and consult law enforcement before assuming your data is unrecoverable.
The UK National Crime Agency's own announcement and the US Treasury's sanctions designation independently describe the operation and the identification of a senior LockBit administrator; the sanctions designation and accompanying indictment state an accusation and assessment of Khoroshev's role rather than a criminal conviction.
Sources & reading trail
Describes Operation Cronos seizing LockBit's admin environment, leak site and Stealbit infrastructure and recovering over 1,000 decryption keys on 20 February 2024.
government-primary · Source published: 20 February 2024 · Retrieved: 16 September 2026
Records OFAC's 7 May 2024 designation of Dmitry Yuryevich Khoroshev, operating as LockBitSupp, coordinated with DOJ, FBI, NCA and Australian Federal Police.
court-or-regulator-primary · Source published: 7 May 2024 · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.