LockBit Down!
LockBit Ransomware’s infrastructure has been seized through a global joint law enforcement action. It is not just their main site, it appears most negotiation and portal sites are now under the control of law enforcement.
This is unequivocally good news. The LockBit ransomware group has been around since 2019 and is responsible for thousands of ransomware victims. Operating as an largely open Ransomware-as-a-Service, they had more affiliates than any other group (at least as far as I know) and their level of destruction was unprecedented among RaaS groups.
According to law enforcement, there is a second shoe that is going to drop tomorrow, so tune in for more details.
It is very unlikely that the core of the LockBit group, which is based in Russia, will be arrested but this disruption will have a significant impact on the ransomware ecosystem and we should enjoy that disruption before we get quickly back to building our defenses.