LockBit’s Hidden Empire Laid Bare in Shocking Cyber Heist
In a dramatic turn of events, the infamous LockBit ransomware syndicate has suffered a devastating breach—this time as the victim. On May 7, 2025, the group’s secretive dark web infrastructure was infiltrated and defaced, displaying a taunting message: “Don’t do crime. CRIME IS BAD xoxo from Prague.” A link to a leaked MySQL database accompanied the message, offering up an extensive trove of internal data.
This leak cracked open LockBit’s black box, exposing the full extent of its cybercrime machinery. Among the disclosures: nearly 60,000 Bitcoin wallet addresses, confidential encryption keys, and a detailed archive of over 4,400 private ransom negotiation logs spanning December 2024 to April 2025. Personal and operational data tied to affiliate partners were also compromised.
Cybersecurity analysts reviewing the dump have confirmed its authenticity. Even LockBit’s elusive figurehead, known online as “LockBitSupp,” acknowledged the compromise, though attempted to downplay the impact, claiming encryption keys remained untouched.
This compromise lands just over a year after Operation Cronos, a coordinated global crackdown in February 2024 that saw 34 of LockBit’s servers dismantled by authorities. Despite that blow, the group had rebounded—until now.
Attack Anatomy: Exploits Behind the Curtain
Threat researchers at Qualys uncovered a disturbing pattern in the leaked data: LockBit’s systematic abuse of at least 20 high-impact software vulnerabilities, spanning a wide array of platforms:
- Citrix: CVE-2023-4966, CVE-2019-19781
- PaperCut: CVE-2023-27351, CVE-2023-27350
- Microsoft: CVE-2022-21999, CVE-2021-36942, CVE-2021-34523/34473/31207, CVE-2020-1472, CVE-2019-0708
- VMware: CVE-2022-22965
- Apache (Log4j): CVE-2021-44228
- F5: CVE-2021-22986
- SonicWall: CVE-2021-20028, CVE-2019-7481
- Fortinet: CVE-2018-13379
- Ivanti: CVE-2019-11510
- Fortra: CVE-2023-0669
- Potix: CVE-2022-36537
These flaws span critical infrastructure—from VPN gateways to print servers—revealing how LockBit infiltrated targets across industries.
Discounts for Discretion: Monero and Multi-Vector Targeting
The breach also unearthed LockBit’s ransom playbook: demands ranging from $4,000 to $150,000, with victims offered significant discounts—up to 20%—if they paid using Monero (XMR), a cryptocurrency favored for its transaction anonymity.
Notably, LockBit’s campaign extended far beyond conventional endpoints. The group specifically targeted Veeam backup servers, VMware vCenter and ESXi platforms, NAS appliances, and file transfer clients like FileZilla and WinSCP—showcasing a strategic emphasis on environments that many security teams underestimate.
As of early 2023, LockBit was linked to an estimated 44% of global ransomware activity, cementing its status as a dominant threat actor.
Industry Alarm and a $10 Million Manhunt
“This breach is a rare window into how one of the world’s most dangerous cybercrime groups operates,” said analysts. “It’s a wake-up call for defenders to shore up exposed systems, especially overlooked infrastructure like backup tools and file transfer software.”
The fallout comes on the heels of the U.S. government’s unmasking of Dmitry Khoroshev, a 31-year-old Russian citizen named as the alleged leader of LockBit. He remains at large, with a $10 million bounty issued for information leading to his capture.




