LockBit Ransomware Group Breached: Internal Chat Logs Leaked

LockBit Ransomware Group Breached: Internal Chat Logs Leaked

LockBit Crumbles: Infamous Ransomware Syndicate Exposed in Stunning Cyberattack

In a dramatic turn of events, the cybercrime group known as LockBit has been hit by a breach of its own. On May 7, unknown actors dismantled its dark web infrastructure and published a trove of internal data—marking a rare and symbolic reversal in the world of ransomware.

The takedown includes a full MySQL database dump, ominously titled “paneldb_dump.zip,” now freely accessible online. Visitors to the formerly secure LockBit portal are instead met with a taunting banner: “Don’t do crime. CRIME IS BAD. xoxo from Prague.”

This breach strikes at the core of one of the most dominant ransomware operations globally, dealing a reputational and operational blow few thought possible.

LockBit Leak Verified: A Glimpse Into the Machinery of Digital Extortion

Cybersecurity analysts have authenticated the recently exposed dataset tied to LockBit, offering an unprecedented look behind the curtain of the ransomware syndicate’s operations.

The compromised files reveal nearly 60,000 Bitcoin wallet addresses—allegedly used in ransom transactions—alongside over 4,400 private negotiation exchanges between LockBit affiliates and their victims, spanning from December through late April. The archive also uncovers records of tailored ransomware variants, purpose-built for targeted strikes.

This rare insight provides investigators, researchers, and the public with a forensic roadmap of one of the cyber underworld’s most elusive players.

Admin Secrets Laid Bare: LockBit’s Internal Credentials Uncovered

Among the most damaging revelations in the leaked database is a user table listing unencrypted passwords tied to 75 admin and affiliate accounts—an unforced error from a group known for its operational discipline.

“This is a treasure trove for investigators,” said Alon Gal, CTO and Co-Founder of Hudson Rock. He emphasized that the exposed credentials, paired with blockchain data, could open new paths for tracking ransom payments and unmasking those behind the attacks.

For a syndicate that once thrived in the shadows, this breach puts its inner circle squarely in the crosshairs.

LockBit Scrambles for Control After Latest Blow; Blames “Light Panel” Hack

In a bid to control the narrative, LockBit has publicly dismissed the severity of the breach. A Cyrillic-language post on one of their remaining leak sites framed the incident as a compromise of an auxiliary “light panel”—an automated registration system—insisting no decryption tools or stolen corporate data were impacted. The group has even offered a bounty for intel on the Prague-based hacker behind the breach.

This cyberattack follows closely on the heels of Operation Cronos, the international law enforcement sting that momentarily knocked LockBit offline in February 2024. Although the group was quick to reboot, researchers observed cracks in their façade. Numerous extortion claims published post-Cronos were reportedly recycled—either pulled from previous cases or borrowed from rival gangs—casting doubt on the group’s operational integrity.

Interestingly, the defacement message used in this breach mirrors a recent disruption of the Everest ransomware operation, suggesting a possible connection. Experts suspect the root of both compromises may be linked to CVE-2024-4577, a critical flaw in PHP 8.1.2 that enables remote code execution.

For an outfit once responsible for nearly half of global ransomware activity in early 2023, this latest breach could shake the confidence of affiliates and accelerate their decline.

More Articles & Posts