Ransomware group Lockbit appears to have been hacked, analysts say

Short Url
Updated 09 May 2025
Follow

Ransomware group Lockbit appears to have been hacked, analysts say

  • Lockbit is one of the world’s most prolific cyber extortion gangs and it has survived past disruptions

WASHINGTON: The ransom-seeking cybercriminals behind the extortion group Lockbit appear to have suffered a breach of their own, according to a rogue post to one of the group’s websites and security analysts who follow the gang.
On Wednesday one of Lockbit’s darkweb sites was replaced with a message saying, “Don’t do crime CRIME IS BAD xoxo from Prague” and a link to an apparent cache of leaked data.
Reuters could not immediately verify the data, which appeared to capture chats between the hackers and their victims, among other things. But others who sifted through the material told Reuters it appeared authentic.
“It’s legit,” said Jon DiMaggio, the chief security strategist with the cybersecurity company Analyst1.
Christiaan Beek, senior director of threat analytics at cybersecurity firm Rapid7, agreed the leak “looks really authentic.” He said he was struck by how it showed Lockbit’s hackers hustling even for modest payouts from small businesses.
“They attack everyone,” he said.

Reuters could not immediately reach Lockbit or establish who had apparently leaked their data. Some darkweb sites associated with Lockbit appeared to be inoperative on Thursday, displaying a note saying they would be “working soon.”
Lockbit is one of the world’s most prolific cyber extortion gangs — diMaggio once called it “the Walmart of ransomware groups” — and it has survived past disruptions. Last year British and US officials worked with a coalition of international law enforcement agencies to seize some of the gang’s infrastructure. A few days later, the group defiantly announced it was back online, saying, “I cannot be stopped.”
Behind the bravado, diMaggio said this week’s hack was an embarrassment.
“I think it will hurt them and slow them down,” he said.


Kyrgyzstan parliament speaker resigns after spy chief sacking

Updated 13 sec ago
Follow

Kyrgyzstan parliament speaker resigns after spy chief sacking

BISHKEK: Kyrgyzstan’s parliament speaker said Thursday he would step down, two days after President Sadyr Japarov dismissed the Central Asian country’s powerful secret service chief and arrested political figures who called for early elections.
In a surprise move, Japarov had sacked his one-time close ally — spy chief Kamchybek Tashiev — in a decision Bishkek said was meant to “prevent division in society.”
Japarov is seeking re-election next year in a country that was once a regional leader in terms of openness, though marked by political volatility.
Rights groups have accused him of authoritarian tendencies, as he seeks to assert his control and cast himself as a bringer of stability.
Speaker Nurlanbek Turgunbek uulu — close to the sacked security boss — told MPs he would step down, insisting that he was not resigning under pressure.
“Reforms initiated by the president must be carried out. Political stability is indispensable,” he said.
Kyrgyzstan has in recent years been de-facto governed by the Japarov-Tashiev tandem.
Both came to power in the wake of the 2020 revolution — the third since Bishkek gained independence from the Soviet Union in 1991.
Several NGOs have in recent months denounced the deterioration of freedom of expression in Kyrgyzstan.
Japarov had unexpectedly sacked Tashiev and three of his deputies on Tuesday, also weakening the powers of the secret services.
Japarov rarely speaks publicly. His spokesman had said the decision was taken “in the interests of the state, with the aim of preventing divisions within society, including between government structures, and to strengthen unity.”
Tashiev was in Germany for health treatment when the sacking was announced and had said it was a “total surprise” to him.
The decision came the day after the publication of an open letter from 75 political figures and ex-officials calling to bring forward presidential elections — scheduled for January 2027.
Five of those who signed the letter — which criticized the economic situation in the country — were arrested Wednesday on charges of organizing mass riots.