# How the FBI Turned LockBit's Business Model Into a Weapon Against It


When law enforcement seized LockBit's infrastructure in February 2024, the headline was simple: biggest ransomware group taken down. But two and a half years later, the FBI is finally explaining the part that actually ended LockBit — and it wasn't the servers they grabbed. It was the trust they poisoned.


Brett Leatherman, assistant director of the FBI's Cyber Division, is set to present the full anatomy of Operation Cronos at Black Hat USA 2026 next week alongside Paul Foster from the UK's National Crime Agency. The details emerging ahead of that session reframe what looked like a straightforward infrastructure seizure as something closer to a deliberate psychological campaign against a criminal franchise.


## The Empire Before the Fall


LockBit's scale, at peak, was genuinely staggering. Between 2020 and 2024, the group hit more than 2,500 organizations across at least 120 countries — with more than 1,800 of those attacks hitting US targets. Total ransom collected: over $500 million. At its height, LockBit accounted for roughly a quarter of all ransomware attacks globally.


Its leader, a Russian national named Dmitry Yuryevich Khoroshev — known online as LockBitSupp — ran what Leatherman describes as "the most successful criminal business in the world" at its peak. The structure was textbook ransomware-as-a-service: Khoroshev developed and maintained the platform, recruited affiliates to carry out attacks, and collected 20 percent of every ransom dollar they earned. Nearly 200 active affiliates at the time of disruption. Two hundred contractors, all motivated, all experienced, all trusting that the platform worked and that Khoroshev would pay them.


That trust was the load-bearing wall of the entire operation. Operation Cronos hit it with a sledgehammer.


## The Weapon Law Enforcement Used: Doubt


Operation Cronos — a multinational effort coordinating the FBI, UK's National Crime Agency, Europol, and ten additional international partners — didn't just seize servers. It seized LockBit's *own platform*, from the leak site through the control panel down to the source code and the data sitting inside it.


Decryption keys went directly to victims. But something more damaging happened to the affiliates: they watched law enforcement stand inside LockBit's infrastructure and announce it. The group's reputation for operational security — the core promise to affiliates that the platform was safe to use — had just been publicly demolished.


RaaS models run on trust. An affiliate risks legal exposure every time they deploy ransomware. The return on that risk requires confidence that the payment infrastructure works, that the operator won't get compromised, that law enforcement can't trace the money back. The moment affiliates couldn't trust any of those things, the workforce evaporated. You don't need to arrest 200 people if 200 people decide the job is no longer worth the risk.


This is the strategic insight that Leatherman and Foster are bringing to Black Hat, and it's the part that deserves more attention than the technical seizure mechanics.


## What the Takedown Actually Required


What's striking about Operation Cronos in retrospect is the coordination it demanded. Twelve countries moving in sync, executing simultaneously to prevent infrastructure from being shifted or affiliates from scattering. The FBI has run high-profile cybercrime operations before — Hive in 2023, REvil in 2021 — but LockBit's geographic distribution and operational sophistication required a different scale of partnership.


Khoroshev himself has been indicted and sanctioned, though he remains at large in Russia. The technical disruption was real: infrastructure seized, decryption keys recovered, affiliates burned. But the group's leader walking free, protected by Russian non-extradition, is the asterisk on every success story in this space. Law enforcement can dismantle the platform. The person who built it keeps breathing.


## What Comes After a Takedown


RaaS disruptions have a documented pattern: the group dissolves, affiliates migrate. After REvil's 2021 disruption, experienced operators dispersed into BlackCat/ALPHV, LockBit, and other groups. After LockBit's February 2024 takedown, LockBit 3.0 attempted a restart, LockBit's branding was co-opted by separate actors, and the broader RaaS ecosystem — RansomHub chief among them — absorbed talent and infrastructure within months.


This isn't failure. It's the realistic outcome. You don't permanently stop ransomware by taking down one group; you increase the operational cost, shorten the group's runway, and force rebuilding cycles that consume time and resources. The goal is to make it expensive and risky enough that the criminal calculus shifts — which is a harder thing to measure than a press release about seized servers.


---


## HackWire Analysis


The real lesson from Operation Cronos isn't "law enforcement can beat ransomware groups." It's more specific: the RaaS franchise model's greatest commercial innovation is also its greatest vulnerability.


LockBit's affiliate network let Khoroshev scale to 25% market share without doing the dirty work himself. But the flip side of a contractor model is that contractors are mercenaries — they defect when conditions deteriorate. Law enforcement understood this and deliberately exploited it. By seizing LockBit's platform and *publicly demonstrating* that control, they weren't just sending a technical message. They were sending a market signal to every affiliate still active: *this operator cannot protect you.*


Compare this to the 2021 REvil disruption, where the takedown was more surgical and less visible. REvil's affiliates regrouped faster because the damage to confidence wasn't as theatrical. Operation Cronos appears to have internalized that lesson: the seizure *needed* to be visible, public, and humiliating to suppress regrouping.


The timing matters here too. Black Hat 2026 is the right venue to walk through this playbook precisely because the security community needs to understand it as a repeatable template, not a one-time event. RansomHub, which emerged as LockBit's primary successor, runs a similar affiliate model. The attack surface is the same: affiliate trust, operational security promises, payment reliability. The question is whether law enforcement can execute the same playbook against a group that now knows what the playbook looks like.


For defenders, the practical implication hasn't changed: LockBit's affiliates are still active, just flying different flags. Incident response teams who saw LockBit attacks should expect similar TTPs from RansomHub and its offshoots. Attribution matters less than pattern recognition at the technical level.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Ransomware](https://www.hackwire.news/category/ransomware) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)