Dateline: July 28, 2026
Operation Cronos: How Police Turned LockBit’s Own Site Against It
The biggest ransomware gang of its time did not fall because police smashed a server. It fell because police made its own criminal partners stop trusting it. That single move did what raids alone never could. An FBI cyber official just pulled back the curtain on how it happened.
What Happened?
Back in February 2024, a group of police agencies ran an operation called Cronos. The target was LockBit, a ransomware crew that ran like a business. It rented out its malware to other criminals, called affiliates, who did the actual hacking. The affiliates kept most of the ransom. LockBit’s leader took a 20% cut on every dollar.
At its peak, LockBit was behind a quarter of all ransomware attacks worldwide. It hit more than 2,500 organizations across at least 120 countries. Over 1,800 of those attacks landed in the US. The group pulled in more than 500 million dollars in ransom payments. It looked untouchable.
Then Operation Cronos flipped the script. Police did not just seize the servers, the leak site, the control panel, and the source code. They took the whole platform and handed decryption keys back to victims. But the real blow was psychological.
LockBit sold one thing above all else: trust. Affiliates handed over their access, their malware builds, their negotiations, and their money. In return, they were promised anonymity and a steady payday. So police turned LockBit’s own leak site against it. They posted affiliate names. They started countdown clocks with a simple message: we know who you are, and we are watching.
Then came the receipts. The seized servers showed LockBit had kept victim data it swore to delete. Some victims who paid got broken decryptors and no support. The gang’s whole promise was exposed as a lie, in public, on its own website.
What’s the Impact?
A crew can rebuild a server in a day. Rebuilding trust is much harder, and LockBit still has not done it more than two years later.
The numbers tell the story. LockBit attacks in the UK have dropped 73% since the disruption. The US saw a similar fall. Ransom payments to the group in the US dropped 79% in the second half of 2024, according to figures from a crypto tracking firm.
The wider picture shifted too. LockBit used to be the single dominant name in ransomware. Now there is no clear top dog. Several key members have been arrested or charged. The group’s leader, a Russian national, remains at large but faces sanctions and criminal charges, with a 10 million dollar reward on offer.
There is a warning buried in here for defenders. A ransomware group is a marketplace, not just a piece of malware. A small core builds the tools. Around it sits a wider economy of affiliates, access brokers, and money launderers. Take down the storefront and the sellers scatter, but they do not vanish. Many have since spread out and decentralized to make the next takedown harder.
How to Avoid This
LockBit is degraded, but the playbook that made it rich is still in heavy use. Here is how to stay off the victim list.
- Lock down remote access. Affiliates often broke in through exposed remote desktop, phishing, and stolen logins. Turn off internet-facing RDP where you can and put strong controls on the rest.
- Turn on phishing-resistant multifactor authentication. A stolen password should not be enough to get inside.
- Keep offline backups you have actually tested. If you can restore fast, a ransom demand loses its bite.
- Patch your public-facing systems first. LockBit affiliates jumped on known bugs in edge devices and web apps. Fix those before anything else.
- Watch for the warning signs. Odd reboots into Safe Mode, mass file renaming, and tools probing your network for shares are all red flags worth catching early.