Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
LockBit is one of the most prolific ransomware-as-a-service operations of the past several years, running a double-extortion affiliate model that was significantly disrupted by law enforcement in 2024 but has continued in a diminished, fragmented form.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
LockBit emerged in 2019 (initially known as 'ABCD') and grew into the highest-volume RaaS brand of 2021-2023, iterating through LockBit 2.0 and LockBit 3.0 (LockBit Black) with an affiliate program, a bug bounty, and a data-leak site used for double extortion. Affiliates gain access via exploited public-facing services, phishing, and purchased access, then exfiltrate data before encryption and threaten publication on the leak site.
In February 2024, the multinational Operation Cronos (NCA, FBI, Europol and partners) seized LockBit infrastructure, took down servers, obtained the source of decryptors, and undermined affiliate trust. The operation degraded but did not eliminate the brand; reporting through 2025-2026 describes reduced scale, a reconstituted leak site, an emerging 'LockBit 5.0' variant, and reported alliances with other brands such as Qilin and DragonForce.
Across the Gulf and wider MENA region, LockBit's leak site has listed victims in the UAE, Saudi Arabia, Kuwait, Qatar, Oman, Bahrain, and Egypt over its lifetime. All such leak-site listings are the group's own extortion claims and should be treated as unverified allegations rather than confirmed breaches unless independently corroborated by the named organization or a reputable authority.
+41 more relationships — see the relationships browser.