Go offline with the Player FM app!
19. A Deep Dive Into The LockBit Data Leaks
Manage episode 495564893 series 3550088
On May 7th, 2025 the notorious ransomware group LockBit’s dark web leak site displayed an unusual message: “Don’t do crime, crime is bad xoxo from Prague”. Alongside this text was the link to an archive file, containing data that appeared to have been stolen from the LockBit ransomware group itself.
In this month's episode of The Dark Dive, members of the Searchlight Cyber threat intelligence team share what they learned by downloading and analysing the files. They share insights into the "Lite" version of LockBit's Ransomware-as-a-Service scheme captured in the data, what we learnt about the 76 affiliate hackers caught up in the data leak, and from the 208 victim negotiations.
Juicy details include the range of payments that the hackers demand from their victims, unexpected conversations in the negotiation chats, and the deliberate targeting of Chinese enterprises.
Further reading:
- Previous episode of The Dark Dive on LockBit - "The LockBit TakeDown" (Discussed at 01.20): https://slcyber.io/podcasts/the-lockbit-takedown/
- Listen to previous episode of The Dark Dive - "Ransomware Groups on the Dark Web" - for more information on Ransomware-as-a-Service schemes (Discussed from 01.50 onwards): https://slcyber.io/podcasts/ransomware-gangs-on-the-dark-web/
- The episode of The Dark Dive that covers TOX and other messaging applications - "Encrypted Communication Apps: From Telegram to EncroChat" (Discussed at 10.20) : https://slcyber.io/podcasts/encrypted-communication-apps-from-telegram-to-encrochat/
Want to find out more or have a suggestion for future podcast episodes?
Email: [email protected]
Website: www.slcyber.io
LinkedIn: www.linkedin.com/company/searchlight-cyber
Weekly newsletter: www.slcyber.io/beacon/
20 episodes
Manage episode 495564893 series 3550088
On May 7th, 2025 the notorious ransomware group LockBit’s dark web leak site displayed an unusual message: “Don’t do crime, crime is bad xoxo from Prague”. Alongside this text was the link to an archive file, containing data that appeared to have been stolen from the LockBit ransomware group itself.
In this month's episode of The Dark Dive, members of the Searchlight Cyber threat intelligence team share what they learned by downloading and analysing the files. They share insights into the "Lite" version of LockBit's Ransomware-as-a-Service scheme captured in the data, what we learnt about the 76 affiliate hackers caught up in the data leak, and from the 208 victim negotiations.
Juicy details include the range of payments that the hackers demand from their victims, unexpected conversations in the negotiation chats, and the deliberate targeting of Chinese enterprises.
Further reading:
- Previous episode of The Dark Dive on LockBit - "The LockBit TakeDown" (Discussed at 01.20): https://slcyber.io/podcasts/the-lockbit-takedown/
- Listen to previous episode of The Dark Dive - "Ransomware Groups on the Dark Web" - for more information on Ransomware-as-a-Service schemes (Discussed from 01.50 onwards): https://slcyber.io/podcasts/ransomware-gangs-on-the-dark-web/
- The episode of The Dark Dive that covers TOX and other messaging applications - "Encrypted Communication Apps: From Telegram to EncroChat" (Discussed at 10.20) : https://slcyber.io/podcasts/encrypted-communication-apps-from-telegram-to-encrochat/
Want to find out more or have a suggestion for future podcast episodes?
Email: [email protected]
Website: www.slcyber.io
LinkedIn: www.linkedin.com/company/searchlight-cyber
Weekly newsletter: www.slcyber.io/beacon/
20 episodes
All episodes
×Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.