Finance

Ransomware group Lockbit appears to have been hacked, analysts say

Published by Global Banking & Finance Review

Posted on May 8, 2025

2 min read

· Last updated: January 23, 2026

Add as preferred source on Google
Eagle S tanker involved in undersea cable damage case in Finland - Global Banking & Finance Review
The Eagle S oil tanker, accused of damaging undersea cables in the Gulf of Finland, faces legal charges. This incident highlights growing concerns over maritime safety and infrastructure security in the Baltic Sea region.
Global Banking & Finance Awards 2026 — Call for Entries

By Raphael Satter WASHINGTON (Reuters) -The ransom-seeking cybercriminals behind the extortion group Lockbit appear to have suffered a breach of their own, according to a rogue post to one of the

Lockbit Ransomware Group Suffers Possible Breach, Analysts Suggest

By Raphael Satter

WASHINGTON (Reuters) -The ransom-seeking cybercriminals behind the extortion group Lockbit appear to have suffered a breach of their own, according to a rogue post to one of the group's websites and security analysts who follow the gang.

On Wednesday one of Lockbit's darkweb sites was replaced with a message saying, "Don't do crime CRIME IS BAD xoxo from Prague" and a link to an apparent cache of leaked data.

Reuters could not immediately determine the authenticity of the data, which appeared to capture chats between the hackers and their victims, among other things. But others who sifted through the material said it appeared legitimate.

"The leaked information looks real," said Christiaan Beek, the senior director of threat analytics at cybersecurity firm Rapid7. In a message posted to LinkedIn on Thursday, he said he was struck by how aggressively Lockbit's hackers appeared to hustle even for relatively small payouts.

"In some cases, victims were pressured to pay just a few thousand dollars," he said.

Reuters could not immediately reach Lockbit or establish who had apparently leaked their data. Some darkweb sites associated with Lockbit appeared to be inoperative on Thursday, displaying a note saying they would be "working soon."

Lockbit is one of the most prolific ransomware gangs operating online - one analyst called it "the Walmart of ransomware groups" - and it has survived past disruptions. Last year British and U.S. officials worked with a coalition of international law enforcement agencies to seize some of the gang's infrastructure. A few days later, the group defiantly announced it was back online, saying, "I cannot be stopped."

(Reporting by Raphael Satter; editing by Edward Tobin)

Key Takeaways

  • Lockbit ransomware group reportedly hacked.
  • Leaked data includes chats between hackers and victims.
  • Analysts confirm the authenticity of the breach.
  • Lockbit's darkweb sites were temporarily inoperative.
  • Lockbit is a prolific ransomware group with past disruptions.

Frequently Asked Questions

What happened to the Lockbit ransomware group?
The Lockbit ransomware group appears to have suffered a breach, as indicated by a rogue post on one of their darkweb sites.
What did the message on Lockbit's darkweb site say?
The message stated, 'Don't do crime CRIME IS BAD xoxo from Prague' and included a link to what seemed to be leaked data.
How credible is the leaked information?
Experts, including Christiaan Beek from Rapid7, believe the leaked information looks real, capturing chats between hackers and their victims.
What is Lockbit known for?
Lockbit is recognized as one of the most prolific ransomware gangs, often compared to 'the Walmart of ransomware groups.'
What was the response from victims regarding payments?
Some victims were reportedly pressured to pay just a few thousand dollars, as indicated by the leaked communications.

Tags

Related Articles

More from Finance

Explore more articles in the Finance category