Thursday, September 10, 2026

LockBit Ransomware Group Breached: Internal Chats and Data Leaked Online

The notorious LockBit ransomware group, once considered one of the world’s most prolific cyber extortion rings, has itself become the victim of a major cyberattack.

On May 7, attackers breached and defaced the group’s dark web sites, leaking a trove of operational data and internal chats in a stunning turn of events that sent shockwaves through the cybersecurity community.

Visitors to LockBit’s dark web portals were greeted by a defiant message: “Don’t do crime CRIME IS BAD xoxo from Prague,” along with a download link to “paneldb_dump.zip,” which contains what appears to be a comprehensive MySQL database dump.

The attackers’ identity remains unknown, but their message leaves little doubt about their intent to embarrass and expose LockBit.

Website Hacked
Website Hacked

Security researchers have authenticated the data as real, describing the leak as a “goldmine for law enforcement.”

The exposed database includes about 60,000 unique Bitcoin wallet addresses allegedly used in ransom payments, nearly 4,500 negotiation chat logs between LockBit operators and their victims dating back to December, and details on custom-built ransomware variants for specific attacks.

Plaintext Passwords, Admin Details Exposed

The leak’s most damning content may be a user table containing plaintext passwords for 75 LockBit administrators and affiliates, a glaring security oversight for a group that specialized in breaching others.

According to Alon Gal, CTO and Co-Founder of Hudson Rock, the information “could significantly aid in tracing cryptocurrency payments and attributing attacks to specific threat actors.”

Bitcoin address
Bitcoin address

In the wake of the breach, LockBit sought to downplay the incident with a message in Cyrillic on their leak site.

The group insisted that only a “light panel” with autoregistration was compromised, and claimed that no decryptors or stolen company data were affected.

Company Data
Company Data

Attempting to turn the tables, LockBit offered a reward for information about the Prague-based hacker behind the attack.

The timing couldn’t be worse for LockBit, which was already reeling from Operation Cronos, a February 2024 global law enforcement operation that temporarily disabled its infrastructure.

While the group managed to bounce back, analysts noted that recent LockBit victim claims often recycled previous attacks.

Experts draw parallels between this breach and a recent attack on the Everest ransomware operation, both tied to a PHP 8.1.2 vulnerability (CVE-2024-4577) enabling remote code execution.

For LockBit-responsible for nearly 44% of ransomware attacks globally in early 2023-this breach is more than a setback.

The exposure of affiliates’ credentials and operational details could permanently damage the group’s credibility and cripple their future activities.

Setting Up SOC Team? – Download Free Ultimate SIEM Pricing Guide (PDF) For Your SOC Team -> Free Download

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth

Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture...

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted...

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

Skullcandy Dime 3 wireless earbuds have a serious vulnerability...

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms...

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto...

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O...

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks has announced a high-severity buffer overflow...

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out...

Related Articles

Recent News