Threat actor
LockBit
CISA and international partners describe LockBit as a ransomware-as-a-service operation that recruits affiliates to carry out ransomware attacks using its tools and infrastructure.Source [1]
What authorities and investigators report
- The advisory says that since January 2020, affiliates using LockBit attacked organizations across critical infrastructure sectors including financial services, education, energy, healthcare, manufacturing and transportation.Source [1]
- It says LockBit affiliates used phishing and spearphishing, and obtained and abused credentials of existing accounts, to gain initial access.Source [1]
- It says that since 2021, LockBit affiliates have used double extortion, encrypting victim data and exfiltrating it while threatening to post it on leak sites.Source [1]
- The U.S. Treasury said LockBit licenses its ransomware to affiliated cybercriminals in exchange for payment, including a percentage of paid ransoms.Source [2]
- Treasury, citing the Justice Department, said LockBit has targeted over 2,500 victims worldwide and is alleged to have received more than $500 million in ransom payments.Source [2]
Individuals named in government actions
Status is as stated in the cited government document on its date.
- Dmitry Yuryevich Khoroshev — sanctionedSource [2]
Techniques
Attack vectors
Sources
- Understanding Ransomware Threat Actors: LockBit (AA23-165A) — CISA, 2023-06-14
- United States Sanctions Senior Leader of the LockBit Ransomware Group (jy2326) — U.S. Department of the Treasury, 2024-05-07
Last reviewed Oct 2, 2026