Law enforcement disrupted LockBit infrastructure in February 2024 through Operation Cronos, but disruption of one brand or platform does not remove ransomware risk. Affiliates, tools, access paths, and tactics can shift. Defenders should turn the event into durable controls rather than a prediction that one operation ended the threat.
Current as of 2026-08-15
The UK National Crime Agency’s Operation Cronos announcement documents the 2024 disruption. The FBI 2025 Internet Crime Report still lists LockBit among ransomware variants reported to the IC3 in 2025, showing why disruption and eradication are different claims.
Decision summary
- Defend against access paths and behaviors, not only a group name.
- Harden remote access, privilege, identity, and exposed services.
- Use segmentation and monitored controls to limit impact.
- Protect backups and rehearse business-led response and recovery.
Lesson one: disruption is not eradication
Infrastructure seizure, arrests, sanctions, leaks, and reputational damage can reduce an operation’s capacity, but actors and affiliates may regroup or change brands. Track current intelligence while basing controls on techniques that persist across groups.
Lesson two: initial access deserves executive attention
The CISA LockBit advisory describes varied affiliate behavior and mitigations. Inventory exposed services, remove unsupported systems, require strong authentication, patch known risk, limit vendor access, and investigate unusual login or remote-management activity.
Lesson three: identity and privilege shape blast radius
Separate administrative accounts, use phishing-resistant MFA where supported, limit standing privilege, protect service accounts, monitor directory changes, and maintain emergency access. Recovery credentials should not depend entirely on the identity system they may need to restore.
Lesson four: segmentation must match real flows
Document required communication between user, server, management, backup, cloud, and operational zones. Deny unnecessary paths, control administrative protocols, monitor exceptions, and test isolation procedures. A diagram without enforced and verified policy does not contain an incident.
Lesson five: recovery is a business capability
CISA’s ransomware guide recommends protected backups and regular testing. Define RPO, RTO, restoration sequence, legal and communications roles, evidence preservation, provider escalation, and decision authority. Exercise loss of identity, endpoints, cloud access, and normal communications—not only file restoration.
Next step for your environment
Run a ransomware tabletop that begins with compromised identity and inaccessible backups, then fund the control and decision gaps it exposes.
Record the accountable owner, baseline, source date, decision, exceptions, acceptance evidence, and review trigger. Test consequential changes in a bounded environment, maintain a rollback path, and verify the real result before closing the work. Product names, availability, pricing, legal requirements, and security guidance can change; recheck the primary sources whenever the decision is renewed or the environment changes.
If you need an independent baseline before changing production systems, start with an ITECS technology and security assessment and keep the resulting evidence with the decision record.
Sources and update trigger
- UK NCA — Operation Cronos disruption of LockBit
- FBI — 2025 Internet Crime Report
- CISA — LockBit advisory AA23-165A
- CISA — StopRansomware Guide
Review trigger: Review after material LockBit, ransomware, advisory, known-exploitation, control, incident, or recovery changes.
continue reading
More ITECS blog articles
About Brian Desmot
The ITECS team consists of experienced IT professionals dedicated to delivering enterprise-grade technology solutions and insights to businesses in Dallas and beyond.
View full profile and articles