The UK National Crime Agency (NCA) has dealt a significant blow to the infrastructure of LockBit, the world’s largest ransomware group, by identifying its alleged leader, Dmitry Khoroshev, known on the internet as LockBitSupp. Khoroshev, a Russian national, has been sanctioned by the UK, US, and Australia after being unmasked.
With an overestimated confidence in his anonymity, Khoroshev went as far as offering a $10 million reward to anyone who revealed his identity. The United States government has now matched the “bet,” offering $10 million to anyone who provides information that helps apprehend him.
LockBit, considered one of the most dangerous ransomware groups in the world, has affected prominent companies such as Royal Mail and Boeing, and public organizations such as the Seville City Council. In February, law enforcement seized LockBit’s entire command and control system in a joint international operation. Graeme Biggar from the NCA emphasized that this blow has significantly reduced LockBit’s capacity and credibility.
“By unmasking one of the leaders of LockBit, we are sending a clear message to these cruel criminals. You cannot hide. You will face justice,” said British Security Minister Tom Tugendhat. However, Khoroshev is likely to reside in Russia and remain free due to Russia’s “policy” of not extraditing cybercriminals, as well as the legal impossibility due to the freezing of international relations following the invasion of Ukraine in 2022.

The NCA and its international allies would have made a strong move by revealing sensitive information from LockBit’s servers. The gang operated with an “affiliate” model, charging commissions for allowing others to use their tools, but more than half of the identified affiliates never received any money for their criminal activities, despite paying thousands of euros for subscription.
In addition, LockBit would have failed to fulfill its promise to delete the stolen data from the victims of its ransomware, according to the NCA, which found supposedly deleted information on the group’s servers.