Months after the UK’s National Crime Agency (NCA) launched a major offensive against the notorious ransomware group LockBit, the cybercriminal gang appears to have resurfaced, continuing to carry out attacks. Despite law enforcement efforts, ransomware groups like LockBit remain resilient, demonstrating the evolving challenge in the fight against cybercrime.
In February 2024, the NCA, in coordination with nine other countries, launched Operation Cronos, a decisive strike on LockBit, a group that emerged around 2019. This cybercrime group had gained infamy for its use of ransomware – a type of malicious software that locks victims’ data and demands a ransom for its release. It operates on a Ransomware-as-a-Service (RaaS) model, where it provides ransomware tools and infrastructure to affiliates who then carry out the attacks. LockBit was also known for a tactic called “double extortion,” threatening not only to keep data locked but also leak sensitive information if the ransom wasn’t paid. Operating through the dark web, the group was built on anonymity and encryption, making it difficult for authorities to track.