LockBit did not collapse just because police seized servers. Operation Cronos worked because investigators hit the trust and payment relationships that let ransomware-as-a-service scale, then made the platform look unreliable to the affiliates who actually delivered the attacks.
The FBI said the multinational effort with the UK National Crime Agency, Europol, and other partners seized LockBit’s leak site, control panel, source code, and data, and put decryption keys in victims’ hands. LockBit had operated from 2020 to 2024, hit more than 2,500 organizations in at least 120 countries, and collected more than $500 million in ransom payments.
For defenders, the point is that a RaaS franchise can be dismantled by breaking its ecosystem, not just by taking infrastructure offline.