An FBI agent explains how the mulitnational law-enforcement Operation Cronos was successful in disrupting the largest ransomware group of its time.

July 27, 2026

Undermining affiliates' trust and strong international partnerships were the keys to dismantling LockBit, one the most successful ransomware-as-a-service (RaaS) groups of its time, which at its peak was responsible for a quarter of all ransomware attacks.

LockBit operated primarily between 2020 and 2024, and Brett Leatherman, assistant director of the FBI's Cyber Division, tells Dark Reading that during its time it victimized more than 2,500 organizations across at least 120 countries, with more than 1,800 of these attacks occurring in the US. Overall, the group collected more than $500 million in ransom payments, and the group and its leader, a Russian national named Dmitry Yuryevich Khoroshev, seemed invincible.

LockBit's RaaS enterprise "for a time … was the most successful criminal business in the world," Leatherman says. Indeed, by the time the group was disrupted, it included a network of nearly 200 affiliates doing its dirty work, with Khoroshev collecting 20 cents on every dollar of ransom earned by that network, he ways.