-
Samsung expects 780% quarterly operating profit jump on AI boom
-
As species decline, green turtles offer glimmer of hope
-
Guardians survive with 9-3 win over White Sox
-
Brothers Scott and Beauden Barrett named to start for All Blacks
-
Saudi Arabia says 3 dead at airports after Houthis claim attacks
-
EU trade chief seeks to dial down China tensions
-
Stocks slide as oil sees volatile trading day over Iran war fears
-
'Never again Bolsonaro': thousands march ahead of Brazil election runoff
-
Microsoft pushes AI vision with new, expensive Surface laptop
-
After botched execution, US woman was nearly taken off life support before revival
-
Five children among 28 killed in Russian strikes on Ukraine
-
Searing AIDS drama 'Elsinore' opens London film festival
-
Odell Beckham Jr signs with Minnesota Vikings
-
Evicted pensioner who sparked Spain housing protests dies: tenant union
-
Saudi Arabia says three dead at airports after Houthis claim attacks
-
Golf star Rahm quitting LIV tour over 'unacceptable' terms
-
Trump plans to turn Florida golf course into presidential retreat
-
Thousands march fearing return of a Bolsonaro presidency in Brazil
-
WHO says cannot conduct full risk assessment on Russia plague reports
-
French PM denies police ordered to confront student protesters
-
After botched execution, US woman is awake and shackled to bed
-
Rubio touts US power, calls on Europe to emerge from 'slumber'
-
New Zealand fly-half Mo'unga ruled out of Australia Tests
-
Trump says 'we don't think' Russian plague is bio-weapon
-
Protests in major Turkish city after mayor defects to Erdogan party
-
Five children among 26 killed in Ukraine after Russian strikes
-
Climate change strips island's title of largest penguin colony: study
-
Man City should 'accept' punishment for rule breaches, says Lineker
-
Rubio says West must choose between national power or decline
-
US woman who survived botched execution is awake and speaking
-
Russia's plague scare: What we know
-
From 1800s to modern pharma: a Nobel-winning chemistry quest
-
French luxury giant to fund redevelopment of two Paris streets: city hall
-
Southampton boss Eckert given suspended ban over 'Spygate'
-
Trump wants to turn Florida golf course into presidential retreat
-
Russia warns of 'false' information as second plague case reported
-
Mayor of Turkish opposition stronghold defects to Erdogan party
-
IEA ready to release more oil reserves if necessary
-
Children among heavy casualties in Ukraine after Russian strikes
-
HSBC 'consults' over UK unit job cuts amid AI adoption
-
Court orders German ex-spy chief kept in jail after spying, treason arrest
-
UK court quashes five ex-traders' Libor rate rigging convictions
-
Guinea caps bottled water prices after sachets banned
-
XM Receives “Global Customer Experience Leader Award 2026” at the TrustFinance Performance Awards
-
Spared, married, hanged: the last weeks of Iranian protester Alireza Sepahi
-
Stocks slide as oil climbs on Mideast flareup
-
Nobel physics winner's pride at pioneering AI role
-
Heavy casualties in Ukraine after Russian strikes
-
IMF preparing El Nino assistance, concerned about AI bubble burst: chief to AFP
-
French wine harvest set to hit historic low
Global operation smashes 'most harmful cyber crime group'
An international operation led by UK and US law enforcement has severely disrupted "the world's most harmful cybercrime group", the Russian-linked ransomware specialist LockBit, officials announced Tuesday.
LockBit and its affiliates have targeted governments, major companies, schools and hospitals, causing billions of dollars of damage and extracting tens of millions in ransoms from victims.
Britain's National Crime Agency (NCA), working with the Federal Bureau of Investigation, Europol and agencies from nine other countries in Operation Cronos, said it had infiltrated LockBit's network and taken control of its services.
"We have hacked the hackers, we have taken control of their infrastructure, seized their source code, and obtained keys that will help victims decrypt their systems," NCA director general Graeme Biggar told reporters in London.
LockBit's website -- selling services that allow people to organise cyber attacks and hold data until a ransom is paid appears -- was taken over on Monday evening.
A message appeared on the site stating that it was "now under control of law enforcement".
"As of today LockBit is effectively redundant, LockBit has been locked out," Biggar said.
The US Justice Department (DOJ) said the agencies had seized control of "numerous public-facing websites used by LockBit to connect to the organization's infrastructure" and taken control of servers used by LockBit administrators.
The NCA added that it had obtained more than 1,000 decryption keys and will be contacting UK-based victims in the coming days and weeks to offer support and help them recover encrypted data.
Biggar said the network had been behind 25 percent of all cyber attacks in the past year.
LockBit has targeted over 2,000 victims and received more than $120 million in ransom payments since it formed four years ago, according to the DOJ.
Those targeted have included Britain's Royal Mail, US aircraft manufacturer Boeing, and a Canadian children's hospital.
In January 2023, US law enforcers shut down the Hive ransomware operation which extorted some $100 million from more than 1,500 victims worldwide.
Since then, LockBit has been seen as the biggest current threat.
- Dark Web -
Hive and LockBit are part of what cybersecurity experts call a "ransomware as a service" style, or RaaS -- a business that leases its software and methods to others to use in extorting money.
Ariel Ropek, director of cyber threat intelligence at cybersecurity firm Avertium, told AFP last year that this structure makes it possible for criminals with minimal computer fluency to get into ransomware by paying others for their expertise.
On the so-called dark web, providers of ransomware services pitch their products openly.
At one end are the initial access brokers, who specialise in breaking into corporate or institutional computer systems.
They then sell that access to the hacker, or ransomware operator.
But the operator depends on RaaS developers like Hive or LockBit, which have the programming skills to create the malware needed to carry out the operation.
Typically, their programmes -- once inserted by the ransomware operator into a target's IT systems -- are manipulated to freeze, via encryption, the target's files and data.
RaaS developers offer a full service to the operators, for a large share of the ransom paid out, said Ropek.
When the ransomware is planted and activated, the target receives a message telling them how much to pay to get their data unencrypted.
That ransom can run from thousands to millions of dollars.
On Tuesday, the US unsealed an indictment against two Russian nationals, bringing to five the number of Russians it has charged in connection with LockBit.
In a separate notice, the US Treasury Department said it is imposing sanctions on the pair, affiliates of LockBit, who "actively engaged" in ransomware attacks.
Biggar said a "large concentration" of the cyber criminals are in Russia and are Russian-speaking, but law enforcement agencies have not seen any direct support for LockBit from the Russian state.
"There is clearly some tolerance of cyber criminality within Russia," he added.
A.Seabra--PC