LockBit Ransomware Group Members Indicted
International authorities dismantle the world's largest ransomware operation.

LockBit ran the biggest ransomware operation in the world for five straight years, and the indictments unsealed against its members finally show exactly how. This was a criminal franchise, complete with developers, a management layer, and a rotating cast of affiliates who paid for access like it was a Costco membership, minus the free samples.
The scale of damage LockBit caused before anyone was charged
Start with the number that should stop you cold: more than 2,500 victims across at least 120 countries, including 1,800 in the US alone, according to the DOJ's 2024 accounting. That's a supply chain.
The victim list reads like a cross-section of modern life. Hospitals, schools, government agencies, and critical infrastructure all turned up on it, alongside small businesses that had no idea what a "locker" even was until their files turned into digital hostages. The UK's National Crime Agency put LockBit's share of all global ransomware attacks at 25% heading into the takedown, and in 2023 alone the group claimed 979 victims, roughly 24% of everything tracked that year, per BlackFog. One group accounted for a quarter of the entire ransomware economy.
The DOJ puts confirmed ransom payments above $500 million, with total damage from downtime, recovery, and incident response climbing into the billions. That's the kind of number that explains why ten countries eventually decided to stop working this case separately and start working it together. No single country's police force wanted to be the one left holding this bag alone.
How the group was structured, from developer to affiliate
LockBit worked like a franchise, literally. There were three layers.
Developers built and maintained the actual ransomware code, the locker, the tools that disabled antivirus software, the delivery mechanisms. Administrators ran the business side: recruiting affiliates, managing infrastructure, negotiating publicly, and running the leak site that shamed victims into paying. Affiliates did the dirty work, picking targets, breaking in, deploying the malware, and haggling over the ransom.
Take Rostislav Panev, one of the alleged developers. Prosecutors say he designed locker code, maintained the build system, and wrote the tools that let the malware spread and hide, earning roughly $230,000 between June 2022 and February 2024. That's a solid contractor rate for someone allegedly building weapons for a criminal enterprise, though his attorney argues his role was "strictly limited to software development," a defense we'll come back to, because it's more interesting than it sounds.
Then there's Dmitry Khoroshev, allegedly the admin behind the "LockBitSupp" persona, who according to prosecutors took a 20% cut of every ransom paid, with affiliates keeping the rest. Twenty percent bought a licence to the infrastructure and guaranteed non-interference. It's the ransomware equivalent of a landlord who never fixes the plumbing but still cashes the rent check every month.
Operation Cronos eventually identified around 190 affiliates, ninety of whom were named defendants; the rest were just out there, running their own version of the same playbook under LockBit's roof.
The individuals indicted and what each is alleged to have done
Here's the roster, and it spans continents, ages, and how much anyone actually got caught.
Mikhail Vasiliev, a dual Russian-Canadian national, was arrested back in November 2022, the first real crack in LockBit's armor, and he later pleaded guilty to participating in the group. Mikhail Matveev, who went by "Wazawaka" online (a name that sounds like a theme park mascot but belongs to someone accused of hitting the Washington D.C. Metropolitan Police Department), was indicted in May 2023 across two jurisdictions. He's still out there, and the State Department has a multimillion-dollar reward on his head.
Ruslan Astamirov, just 21 when charged in June 2023, pleaded guilty as one of the younger affiliates on record. Artur Sungatov and Ivan Kondratyev, known online as "Bassterlord," both Russian nationals, were indicted in February 2024 alongside the big Cronos announcement. Kondratyev's alias was already a known quantity in threat intelligence circles well before his name hit an indictment.
Then there's Khoroshev, indicted in May 2024, facing 26 counts and a maximum sentence of 185 years, accused of running the whole operation since it launched in 2019. He's sanctioned by the UK, the US, and Australia, and in a detail that tells you everything about how these people think, he reportedly tried negotiating with law enforcement after the takedown, offering to rat out rival ransomware operators. Extortion, then negotiation, consistent if nothing else. As one investigator might put it: he ran a locksmith business and, when cornered, offered to turn in the other locksmiths.
And finally Panev, arrested in Israel in August 2024, extradited to the US in March 2025, now facing a 41-count indictment. Two years passed between the first arrest and the most recent extradition, a slow, grinding, multi-year siege rather than a raid.
What Operation Cronos actually seized and disrupted

On February 20, 2024, agencies from ten countries, the NCA, FBI, Europol, plus partners from Australia and Japan, announced the takedown all at once, simultaneous and coordinated, clearly designed to maximize confusion inside LockBit's own ranks.
The haul included 34 servers seized, 14,000 rogue accounts shut down, and 200 cryptocurrency accounts frozen. Investigators even took over LockBit's own leak site and briefly used it to publish details about the group's infrastructure back at them, which is a bit like hijacking someone's Yelp page to post their kitchen's health inspection score.
More than 1,000 decryption keys came out of the seizure, according to the World Economic Forum's 2024 reporting, directly useful to victims who'd already paid or were still locked out of their own systems. Investigators also pulled affiliate panel data: IP logs, ransom negotiation transcripts, crypto wallet addresses. That's the paper trail that turned into the indictments.
One finding stands out. The operation confirmed LockBit routinely kept stolen data even after victims paid, directly contradicting the group's own promises. If you were on the fence about whether paying a ransom actually buys you safety, this settles it. It's a bit like paying a ransom note written by someone who never intended to return the hostage in the first place, because there was no hostage, just a photocopy, and they kept the original.
And there's a detail almost too clean to be true. The vulnerability reportedly used to break into LockBit's own infrastructure was an unpatched PHP vulnerability, CVE-2023-3824, meaning a group built on exploiting other people's unpatched systems got taken down through one of its own. Poetic, and also a little embarrassing if you're the guy running the operation. Q: What do you call a locksmith who forgets to lock his own door? A: Indicted.
Why the group kept operating despite earlier arrests
Here's the uncomfortable part: none of this worked the first few times. LockBit's structure was built specifically to survive individual losses. Developers, admins, and affiliates operated with enough distance between them that pulling one thread didn't unravel the sweater.
After Vasiliev's arrest in 2022, LockBit kept humming along at roughly 200 victims per quarter, barely a hiccup. Khoroshev, according to prosecutors, kept recruiting replacement affiliates and kept developing new versions of the malware straight through 2023 and into 2024, including a variant called LockBit Green, which reportedly borrowed code from the defunct Conti group. Even after Conti died, its code lived on somewhere else, like a horror movie villain who just won't stay buried.
Earlier law enforcement actions had been going after affiliates, which is a bit like arresting a delivery driver and expecting the warehouse to close. The platform stayed up, the infrastructure stayed live, and someone else just stepped in to drive.
What made Cronos different was going after the infrastructure and the administrator at the same moment, instead of picking off affiliates one at a time and hoping the group ran out of replacements. The real innovation here was the sequencing, timed to hit every layer at once.
Even so, this isn't over. Khoroshev and Matveev remain free, and some affiliates are still unidentified. The platform's down, but the roster isn't fully accounted for.
What the indictments reveal about attributing cybercrime across borders
Most of the people named in these indictments are Russian nationals, and Russia doesn't extradite its own citizens. That single fact explains why Khoroshev and Matveev are still walking around despite sanctions, indictments, and a $10 million bounty. You can charge someone with 26 felonies and it means very little if the country they're standing in has no intention of handing them over.
Panev's case is the exception, and exceptions are useful because they show you the rule. He got extradited from Israel because the treaty relationship and the political will both lined up. That almost never happens with Russian nationals tied to ransomware, which is why his case reads like a rare planetary alignment, not a repeatable pattern.
So what's the point of indicting someone you can't arrest? Turns out, plenty. Named charges, sanctions, and public reward offers box these people in. They can't travel freely, they can't bank normally, and their name is permanently tied to a federal case, whether or not they ever see a courtroom. The charges shrink the world someone's allowed to move through. Think of it as house arrest for a house that spans the globe, except the walls are extradition treaties instead of drywall.
The coordination itself is the real headline, honestly. Ten countries shared intelligence pulled from a seized admin panel, timing their announcements to the same day. This is a live, joint operation, a genuine rarity in a field where jurisdiction usually means everyone waits their turn.
And Khoroshev's reported attempt to trade information on rival ransomware groups after the seizure tells you something real: even someone running the show from behind sanctions and a keyboard understood the infrastructure hit was a genuine threat. The geography still protects him, though the operation still worried him.
Which leaves the actual question hanging over all of this. The platform is down, the servers are seized, and the decryption keys are out. Most of the architects, though, are still free, still Russian citizens, still outside the reach of anyone's handcuffs. So what stops the next version of LockBit from standing up somewhere else, under a different name, run by people who watched this whole thing happen and took notes? That's the actual, unresolved problem sitting underneath every press release calling this case closed.


