FBI Holds 7,000 LockBit Decryption Keys
FBI says it now has over 7,000 LockBit decryption keys and urges victims of the ransomware to report through IC3.
FBI Cyber Division Assistant Director Bryan Vorndran announced at the 2024 Boston Conference on Cyber Security that the Bureau's ongoing disruption of LockBit has yielded more than 7,000 decryption keys, which can be used to help victims recover encrypted data. The FBI is actively reaching out to known LockBit victims and encouraging any organization that suspects it was compromised to file a report through the Internet Crime Complaint Center's dedicated LockBit Victim Reporting Form.
Vorndran noted that the LockBit ransomware variant has been used in over 2,400 attacks worldwide, with more than 1,800 affecting U.S. victims, resulting in billions of dollars in damages across multiple sectors. He also highlighted findings from the recent international law enforcement operation that seized LockBit infrastructure, which revealed the group retained stolen victim data even after ransoms were paid, undermining any assurance that payment would prevent data exposure.
This update is primarily a law-enforcement and victim-notification advisory rather than a new technical disclosure, reflecting continued follow-through on the earlier LockBit takedown by U.S. and U.K. authorities. It reinforces that affected organizations should not assume prior ransom payments guaranteed data deletion and should engage with IC3 for potential decryption assistance.
Mentioned in this report
Source reporting: https://www.fbi.gov/news/stories/fbi-cyber-lead-urges-potential-lockbit-victims-to-contact-internet-crime-complaint-center
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free