◇ SIGN IN
← all actors
ransomware

LockBit / LockBit 3.0

activemedium confidence
Ransomware
LockBitLockBit BlackLockBit 3.0ABCD (early variant)Bitwise Spider
Attribution
RaaS (Russian-speaking, unattributed to a state)
Origin
Unknown (Russian-speaking operators assessed)
First seen
2019
Last active
2026
Motivation
Financially motivated (ransomware)
Confidence
medium
MENA targeting
UAE, Saudi Arabia, Kuwait, Qatar, Oman, Bahrain, Egypt
Sectors
Telecom, government, energy, construction

Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.

Why it mattersRansomware actor, medium confidence, documented targeting UAE, Saudi Arabia, Kuwait (Telecom, government, energy sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.

LockBit is one of the most prolific ransomware-as-a-service operations of the past several years, running a double-extortion affiliate model that was significantly disrupted by law enforcement in 2024 but has continued in a diminished, fragmented form.

History

LockBit emerged in 2019 (initially known as 'ABCD') and grew into the highest-volume RaaS brand of 2021-2023, iterating through LockBit 2.0 and LockBit 3.0 (LockBit Black) with an affiliate program, a bug bounty, and a data-leak site used for double extortion. Affiliates gain access via exploited public-facing services, phishing, and purchased access, then exfiltrate data before encryption and threaten publication on the leak site.

In February 2024, the multinational Operation Cronos (NCA, FBI, Europol and partners) seized LockBit infrastructure, took down servers, obtained the source of decryptors, and undermined affiliate trust. The operation degraded but did not eliminate the brand; reporting through 2025-2026 describes reduced scale, a reconstituted leak site, an emerging 'LockBit 5.0' variant, and reported alliances with other brands such as Qilin and DragonForce.

Across the Gulf and wider MENA region, LockBit's leak site has listed victims in the UAE, Saudi Arabia, Kuwait, Qatar, Oman, Bahrain, and Egypt over its lifetime. All such leak-site listings are the group's own extortion claims and should be treated as unverified allegations rather than confirmed breaches unless independently corroborated by the named organization or a reputable authority.

Notable campaigns

2024
Operation Cronos takedown
International law enforcement seized LockBit infrastructure in February 2024, disrupting the affiliate program and leak site.
2025
LockBit 5.0 / cross-brand alliances
Reporting described an emerging LockBit 5.0 build and claimed cooperation with Qilin and DragonForce as the brand attempted to rebuild.
2025
MENA Gulf leak-site listings
Organizations across the UAE, Saudi Arabia and other GCC states appeared on LockBit's leak site (claimed, not independently confirmed).

Claimed victims · 2016 tracked

Leak-site postings via ransomware.live — claimed by the group, not confirmed breaches. Metadata only. MENA Ransomware Watch →

Claim volume · last 12 months
SONDJFMAMJJA
DateVictimCountrySector
new blog domain lockbit 5.0Other
pdcm.comUSFinancial Services
kll-law.comUSProfessional Services
ehlers-inc.comUSTechnology
aqhch.com.cnCNManufacturing
asiapacificex.comSGTransportation
visionproducts.llcUSRetail & E-Commerce
tuttoperlufficio.euITProfessional Services
ende.boBOEnergy & Utilities
intelliloan.comUSFinancial Services
aeamg.org.brBRGovernment & Defense
physiciansmedicalbilling.netUSHealthcare