FBI holds 7,000 LockBit decryption keys
FBI's Cyber Division urges LockBit ransomware victims to contact IC3, revealing it now holds over 7,000 decryption keys.
FBI Cyber Division Assistant Director Bryan Vorndran used a keynote at the 2024 Boston Conference on Cyber Security to update the public on the Bureau's ongoing disruption efforts against the LockBit ransomware group. He disclosed that the FBI now possesses more than 7,000 LockBit decryption keys, obtained through law enforcement operations against the group's infrastructure, and is actively reaching out to identified victims while encouraging unreported victims to file through the IC3 LockBit Victim Reporting Form.
Vorndran characterized LockBit as one of the most prolific ransomware variants, citing over 2,400 attacks globally, more than 1,800 of which hit U.S.-based victims, with damages reaching into the billions of dollars across multiple sectors. He also noted that the international operation to seize LockBit infrastructure and sanction the group and its affiliates uncovered evidence that victim data was retained even after ransom payments were made, undermining assurances typically given by the group during extortion negotiations.
This article is a law-enforcement update rather than a new technical disclosure, reinforcing prior DOJ and international actions against LockBit, including the criminal charges against a Russian national tied to LockBit development and operation, and the broader U.S.-U.K. disruption of the ransomware variant's infrastructure.
Mentioned in this report
Source reporting: https://www.fbi.gov/news/stories/fbi-cyber-lead-urges-potential-lockbit-victims-to-contact-internet-crime-complaint-center
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free