For several years, LockBit reigned as the largest and most formidable cybercriminal organization in the world. Unlike traditional hacking groups, LockBit operated like a well-oiled business, automating and outsourcing its ransomware attacks to maximize efficiency and profits. At its peak, the group dominated the cybercrime landscape, leaving rival gangs in the dust.
But then, something went wrong—not because LockBit failed, but because it became too successful. Internal conflicts, technical failures, and fierce competition began to erode its dominance. This is the story of LockBit, a criminal enterprise unlike any other—its rise, its innovations, and the cracks that eventually threatened its empire.
Chapter 1: The Birth of LockBit – A Criminal Enterprise Like No Other
LockBit emerged in 2019, distinguishing itself from other ransomware gangs by adopting a business-like approach. While most cybercriminal groups operated as loose collectives of hackers, LockBit structured itself like a legitimate tech company, focusing on scalability, customer service, and innovation.
The Ransomware-as-a-Service (RaaS) Model
LockBit’s biggest innovation was perfecting the Ransomware-as-a-Service (RaaS) model. Instead of carrying out attacks themselves, LockBit leased its malware to independent hackers (called affiliates), who executed the attacks and split the profits.
- Traditional RaaS Model:
- The core gang controlled finances.
- Affiliates often got scammed, with many not receiving their share.
- Source: Cybersecurity & Infrastructure Security Agency (CISA)
- LockBit’s Revolutionary Approach:
- Affiliates took the ransom payments first, then paid LockBit a 20% commission.
- This trust-based system attracted more hackers, making LockBit the most popular RaaS provider.
- Source: BleepingComputer – LockBit 2.0
Corporate-Style Operations
LockBit didn’t just stop at ransomware—it copied Silicon Valley tactics:
- Bug Bounty Program: Offered rewards for finding vulnerabilities in their malware (just like Google or Microsoft).
- Source: Krebs on Security
- Customer Support: Provided 24/7 assistance to affiliates.
- Continuous Updates: Released improved versions (LockBit 2.0, 3.0) with new features.
By 2022, LockBit had become the #1 ransomware group, responsible for thousands of attacks worldwide.
Chapter 2: LockBit’s Reign – How It Dominated the Cybercrime World
The Power of LockBit 3.0
The release of LockBit 3.0 in 2022 marked the gang’s peak. The malware was faster, deadlier, and more automated than ever before. Key features included:
- Self-destruct mechanisms (to evade detection).
- Automatic data theft & encryption.
- Dark web leak sites (to pressure victims by publishing stolen data).
- Customizable options (like changing the victim’s wallpaper).
John Deaggio, an undercover researcher who infiltrated LockBit, described it:
“It was something I could literally teach my kids to do.”
Source: Interview with John Deaggio
Affiliate-Driven Growth
LockBit’s success relied on its vast network of affiliates:
- Low-Skill Hackers: Could easily deploy ransomware without deep technical knowledge.
- High-Volume Attacks: More affiliates = more victims = more profits.
- Global Reach: Attacks spanned hospitals, governments, and Fortune 500 companies.
At its height, LockBit was responsible for 40% of all ransomware attacks, dwarfing competitors like REvil and Conti.
Source: Sophos 2023 Threat Report
Chapter 3: The Downfall – Where It All Went Wrong
1. The $50,000 Bug Bounty Disaster
LockBit 3.0 had a critical flaw—a vulnerability carried over from an older ransomware called BlackMatter. When a hacker exposed the bug, LockBit had to pay a $50,000 bounty.
- The Developer Conflict:
- LockBit’s lead developer (previously behind DarkSide, the group behind the Colonial Pipeline hack) refused to cover the cost.
- Result: He quit and leaked LockBit’s source code publicly.
- Source: The Record by Recorded Future
2. The Source Code Leak – A Free-for-All
Once the ransomware builder was leaked:
- Copycat gangs emerged, using LockBit’s code without paying the 20% fee.
- Affiliates abandoned LockBit for competitors.
- Security firms reverse-engineered the malware, making it easier to defend against.
Source: ZDNet – LockBit Source Code Leak
3. Storage Overload – Too Much Success
LockBit’s automated data theft became a liability:
- Massive data dumps overwhelmed their servers.
- Slow dark web speeds made leaks unreliable.
- Affiliates grew frustrated when stolen data wasn’t published properly.
Source: Dark Reading – LockBit Infrastructure Issues
4. The Rise of CL0P – A Rival’s Triumph
While LockBit struggled, CL0P (aka KOP) launched MOVEit attacks (2023), breaching hundreds of organizations in one go.
- CL0P’s Victories:
- Double the victims of LockBit.
- Millions in profits.
- Proved LockBit wasn’t invincible.
Source: BBC – CL0P MOVEit Attacks
Chapter 4: Can LockBit Make a Comeback?
Despite its setbacks, LockBit isn’t dead yet.
- Engineering Problems Can Be Fixed: Server upgrades, new developers.
- Brand Recognition: Many affiliates still prefer LockBit’s reputation.
- Adaptability: If it innovates again, it could regain dominance.
John Deaggio’s warning:
“If he fixes it, they could get right back on top.”
Source: Interview with John Deaggio
Conclusion: The Future of LockBit
LockBit’s story is a cautionary tale—even the most powerful criminal empires can crumble due to greed, betrayal, and overexpansion. Whether LockBit recovers or fades into obscurity will depend on its ability to reinvent itself in an increasingly competitive cybercrime landscape.
For now, one thing is clear: No hacking group stays on top forever.
Want More Cybercrime Stories?
The Evolution of Ransomware: From petty scams to billion-dollar empires.
CL0P (KOP): The gang that dethroned LockBit.
REvil & DarkSide: Other notorious ransomware groups.