Close Menu
TechCentralTechCentral

    Subscribe to the newsletter

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    Facebook X (Twitter) YouTube LinkedIn
    WhatsApp Facebook X (Twitter) LinkedIn YouTube
    TechCentralTechCentral
    • News

      Apeing Brussels is no way to unlock South Africa’s AI potential

      14 May 2025

      Spar Mobile is South Africa’s latest MVNO

      14 May 2025

      Big changes sweeping through IT distribution: Westcon CEO

      14 May 2025

      Cell C CEO vows to defend MVNO leadership

      14 May 2025

      R10-billion in Post Office bailouts – what the money could have been used for instead

      14 May 2025
    • World

      Microsoft to lay off 3% of workforce in organisation-wide cuts

      14 May 2025

      AI-voiced audiobooks are coming to Audible

      13 May 2025

      Apple turns to AI to tackle iPhone battery woes

      13 May 2025

      Vodafone CFO to step down

      7 May 2025

      Lights, camera, tariffs: Trump declares war on foreign flicks

      5 May 2025
    • In-depth

      South Africa unveils big state digital reform programme

      12 May 2025

      Is this the end of Google Search as we know it?

      12 May 2025

      Social media’s Big Tobacco moment is coming

      13 April 2025

      This is Europe’s shot to emerge from Silicon Valley’s shadow

      10 April 2025

      Microsoft turns 50

      4 April 2025
    • TCS

      Meet the CIO | Schalk Visser on Cell C’s big tech pivot

      13 May 2025

      TCS | Kiaan Pillay on fintech start-up Stitch and its R1-billion funding round

      7 May 2025

      TCS+ | Switchcom and Huawei eKit: networking made easy for SMEs

      6 May 2025

      TCS | How Covid sparked a corporate tug-of-war over Adapt IT

      30 April 2025

      TCS+ | Inside MTN’s big brand overhaul

      11 April 2025
    • Opinion

      Solar panic? The truth about SSEG, fines and municipal rules

      14 April 2025

      Data protection must be crypto industry’s top priority

      9 April 2025

      ICT distributors must embrace innovation or risk irrelevance

      9 April 2025

      South Africa unprepared for deepfake chaos

      3 April 2025

      Google: South African media plan threatens investment

      3 April 2025
    • Company Hubs
      • Africa Data Centres
      • AfriGIS
      • Altron Digital Business
      • Altron Document Solutions
      • Arctic Wolf
      • AvertITD
      • Braintree
      • CallMiner
      • CYBER1 Solutions
      • Digicloud Africa
      • Digimune
      • Domains.co.za
      • ESET
      • Euphoria Telecom
      • Incredible Business
      • iONLINE
      • Iris Network Systems
      • LSD Open
      • NEC XON
      • Network Platforms
      • Next DLP
      • Ovations
      • Paracon
      • Paratus
      • Q-KON
      • SkyWire
      • Solid8 Technologies
      • Tenable
      • Vertiv
      • Videri Digital
      • Wipro
      • Workday
    • Sections
      • AI and machine learning
      • Banking
      • Broadcasting and Media
      • Cloud services
      • Contact centres and CX
      • Cryptocurrencies
      • Education and skills
      • Electronics and hardware
      • Energy and sustainability
      • Enterprise software
      • Fintech
      • Information security
      • Internet and connectivity
      • Internet of Things
      • Investment
      • IT services
      • Lifestyle
      • Motoring
      • Public sector
      • Retail and e-commerce
      • Science
      • Social media
      • Talent and leadership
      • Telecoms
    • Events
    • Advertise
    TechCentralTechCentral
    Home » Information security » Smashing a criminal enterprise – inside the Lockbit ransomware takedown

    Smashing a criminal enterprise – inside the Lockbit ransomware takedown

    One of the world's biggest criminal hacking gangs woke up on Tuesday to a startling discovery.
    By Agency Staff21 February 2024
    Twitter LinkedIn Facebook WhatsApp Email Telegram Copy Link
    News Alerts
    WhatsApp

    One of the world’s biggest criminal hacking gangs woke up on Tuesday to a startling discovery: law enforcement, after taking over their main website on Monday, were now threatening to reveal their personal details and data about their cybercrime organisation.

    The group, Lockbit, had become notorious in cybercrime circles for using malicious software called ransomware to digitally extort victims, relying on underground marketing campaigns to boost its profile. At one point, Lockbit had promised US$1 000 to anyone who tattooed their logo on themselves, according to cybersecurity researchers.

    The group’s ringleader, known by the online moniker LockbitSupp, had also become so confident in their own anonymity that, according to Britain’s National Crime Agency (NCA), they had promised $10-million to the first person who could find and unmask them.

    The core online system was re-engineered to target the hackers in the same way they had terrorised victims

    The international law enforcement operation, which had posted on the extortion website on Monday that it had taken control, on Tuesday announced it had re-engineered Lockbit’s core online system — mimicking the countdown clock that Lockbit used in extortion attempts and posing its own $10-million challenge, according to a review of Lockbit’s darkweb site.

    The core online system was re-engineered to target the hackers in the same way they had terrorised victims: with an advent calendar-like series of tiles, each marked with a countdown timer that, upon reaching zero, published stolen data.

    Across the website’s front page, where victim names once stood, law enforcement agencies replaced the text and links with internal data obtained by hacking the hackers themselves.

    Yearslong investigation

    The resulting display was a smorgasbord of law enforcement action against Lockbit which included indictments, sanctions, a tool with which victims can decrypt their data, and a new countdown with two days left on the clock which asked: “Who is LockbitSupp? The $10 million question.”

    Before it was taken down, Lockbit’s website had displayed an ever-growing gallery of victim organisations that was updated nearly daily. Next to the names were digital clocks showing the number of days left to the deadline given to each organisation to provide ransom payment.

    The unique law enforcement operation was the result of a yearslong investigation by international police agencies and was designed to undermine the group’s credibility in the criminal underground, officials said.

    Read: World’s largest ransomware gang nailed

    “Lockbit’s affiliates should be very concerned right now, especially as law enforcement continues to make decryptors available to victims,” said Charles Carmakal, Mandiant Consulting’s chief technology officer.

    The US has charged two Russian nationals with deploying Lockbit ransomware against companies and groups around the world. Police in Poland and Ukraine made two arrests.

    Before it was seized by police, Lockbit was able to extort multiple hacking victims at the same time through its website, which listed breached companies next to the countdown timer.

    Once the counter expired, the cybercriminals would often publish caches of stolen data from the victimised company – historically, these exposures included personal private information of customers, medical records, internal billing data and the communications of internal staff, among other things.

    These leaks were intended to harm the reputation of victims and put them in legal jeopardy, experts said, netting Lockbit over $120-million in ransom payments.

    Read: Ransomware attacks: how South African companies should respond

    On Tuesday, Graeme Biggar, director-general of the NCA, told journalists that the true cost, including money spent by organisations and corporations scrambling to regain access to their networks and the impact on business, could amounted to losses totalling billions.  — Christopher Bing and James Pearson, (c) 2024 Reuters

    Get breaking news alerts from TechCentral on WhatsApp



    LockBit LockbitSupp
    Subscribe to TechCentral Subscribe to TechCentral
    Share. Facebook Twitter LinkedIn WhatsApp Telegram Email Copy Link
    Previous ArticleTeraco to build gigantic Free State solar farm
    Next Article Worries SA could help kill global deal on tax-free e-commerce

    Related Posts

    Notorious ransomware group gets a taste of its own medicine

    9 May 2025

    LockBit ransomware gang’s power diminished but not eradicated

    19 March 2024

    World’s largest ransomware gang nailed

    20 February 2024
    Company News

    The art of letting go – how great IT leaders scale by creating focus

    14 May 2025

    Transform your contact centre into a strategic growth driver

    14 May 2025

    The Lesaka story: Shaping the future of financial services in Southern Africa

    14 May 2025
    Opinion

    Solar panic? The truth about SSEG, fines and municipal rules

    14 April 2025

    Data protection must be crypto industry’s top priority

    9 April 2025

    ICT distributors must embrace innovation or risk irrelevance

    9 April 2025

    Subscribe to Updates

    Get the best South African technology news and analysis delivered to your e-mail inbox every morning.

    © 2009 - 2025 NewsCentral Media

    Type above and press Enter to search. Press Esc to cancel.