FBI: Breaking Affiliate Trust Sped Along LockBit’s Takedown

The takedown of LockBit, one of the most successful ransomware-as-a-service (RaaS) groups in history, was a major milestone for law enforcement. The group’s operations were disrupted by Operation Cronos, a multinational effort that targeted its infrastructure and severed ties with its network of affiliates. This article will explore how the FBI and its international partners succeeded in dismantling LockBit, and what this means for cybersecurity.

LockBit operated between 2020 and 2024, victimizing over 2,500 organizations across at least 120 countries, including more than 1,800 attacks in the US. The group collected over $500 million in ransom payments, making it one of the most lucrative cybercrime operations ever seen. Its RaaS model allowed a network of nearly 200 affiliates to do its dirty work, with the group’s leader, Dmitry Yuryevich Khoroshev, collecting 20 cents on every dollar earned.

The key to LockBit’s success was its ability to establish trust with its affiliates, who were promised anonymity and long-term success. However, Operation Cronos successfully broke this trust relationship by using LockBit’s own leak site to “out” the affiliates. The effort created a rift with those partnerships, damaging the group’s credibility in a way that it could never recover.

The FBI’s Brett Leatherman explains that trust is what RaaS actually sells: “An affiliate hands the platform his access, his malware builds, his negotiations, and his money, and what he buys in return is anonymity and a payday.” By targeting LockBit’s technical infrastructure and damaging its credibility, law enforcement was able to cripple the group’s operations.

However, simply taking down LockBit’s servers would not have been enough. Officials needed to damage its credibility in a way that it could never recover. As Leatherman notes, “A criminal enterprise can rebuild a server in a day, but rebuilding trust is a much harder problem.” The FBI and its partners focused on forging strong trust and partnerships with other law enforcement agencies, which was a rare occurrence at the time.

The collaboration of all agencies was indeed key to the success of Operation Cronos. As Paul Foster, deputy director of the National Cyber Crime Unit of the NCA, notes, “Each agency using its own unique skills and accesses to deliver a greater substantial impact required close cooperation and alignment.” The operation’s success is a testament to the power of international collaboration in disrupting major cybercrime operations.

The takedown of LockBit sends a strong message to other RaaS groups: that law enforcement is capable of disrupting even the most successful operations. It also highlights the importance of breaking trust relationships between these groups and their affiliates, which can be done by using the group’s own infrastructure against them. As Leatherman notes, “Law enforcement published affiliate names with a simple message: We know who they are and we will be watching.” This approach has been shown to be effective in damaging the credibility of these groups.

In practical terms, this means that organizations should prioritize building strong relationships with their partners and law enforcement agencies. By doing so, they can improve their chances of success in disrupting major cybercrime operations. Additionally, businesses should focus on establishing robust cybersecurity measures to prevent ransomware attacks from occurring in the first place.


Source: Dark Reading — 2026-07-27