Loading...
Research & Insights

After the Indictment: Three Years of Named Cyber Attributions, Measured

October 7, 2026 · Jason Ellis

Modern Los Angeles Federal Courthouse, aerial perspective, sunny day.
Photo by RDNE Stock project on Pexels

On May 7, 2024, the U.S. Department of Justice put a name to the administrator of LockBit, at that point the most prolific ransomware operation in the world. Dmitry Yuryevich Khoroshev, a 31-year-old Russian national, faced a 26-count federal indictment in New Jersey carrying a theoretical maximum of 185 years in prison. The State Department offered $10 million for information leading to his arrest, and the United States, the United Kingdom and Australia sanctioned him the same day. By the Justice Department's own accounting, the operation he ran had struck more than 2,500 victims in at least 120 countries and collected ransom payments exceeding half a billion dollars.

Three months earlier, Operation Cronos had seized roughly three dozen LockBit servers, taken control of the affiliate panels crews used to manage attacks and negotiate ransoms, replaced the gang's dark web leak site with a seizure notice, and pulled decryption keys that covered about 7,000 victims. Attorney General Merrick Garland framed the moment plainly: the government was "taking away the keys to their criminal operation."

Khoroshev's answer, delivered days later in an interview with the cybercrime outlet The Record, was that Cronos had been "additional advertising." He quoted Nietzsche on what does not kill you.

The taunt has held up better than the indictment. LockBit's leak site returned on new Tor infrastructure within days of the seizure, and its administrator posted that 133 new affiliates had registered in the days that followed, a figure nobody outside the gang could verify. New victim listings followed within weeks. By the fourth quarter of 2024, leak-site analysts measured listing volume back at pre-takedown levels, and by January 2026 the brand, in its fifth numbered generation, had posted more than 100 alleged victims to a fresh site. Its victim list over the years included more than 100 hospitals and health systems, and in some incidents patients had to be diverted to other facilities.

The roughly three years from the ALPHV and Evil Corp actions of late 2023 to the autumn of 2026 make up the densest naming campaign in the short history of cybercrime enforcement: servers seized, administrators identified, sanctions imposed, bounties posted, decryption keys handed out. The question worth asking is narrow and testable: what measurable difference has any of it made to the next attack? The record assembled from Justice Department records, National Crime Agency operations, Europol actions, leak-site monitoring and vendor telemetry supports a specific answer. In the crews that absorbed the most enforcement attention, the next attack was not delayed. The changes showed up somewhere else: in the speed of the rebuild, the shape of the enterprise, and, in exactly one well-measured case, the size of the damage.

Who actually ends up in a courtroom

An indictment is a precise instrument that mostly cannot reach the people it names. Russia has never extradited a cybercriminal to the United States, and the administrators of the most-prosecuted crews live there openly. Khoroshev remains free. Maksim Yakubets, indicted for Evil Corp in December 2019 with a $5 million bounty attached, spent the following years reindicted once more, in July 2025, but never in custody. The State Department priced TrickBot's leadership at $10 million in February 2023; no arrests followed. When the FSB detained more than a dozen REvil suspects at Washington's request in January 2022, subsequent reporting indicated the case quietly evaporated and the suspects went free.

Custody happens at borders, to the tier that travels. Yaroslav Vasinskyi, charged in the 2021 REvil indictments, was arrested in Poland, extradited, and later sentenced in a U.S. federal court to more than 13 years in prison. Mikhail Vasiliev, a LockBit affiliate, received four years in Canada. Rostislav Panev, described as a LockBit developer, was arrested in Israel in August 2024 and faces a 41-count indictment. Count the named administrators of the major crews, and the arrest yield inside Russia rounds to zero.

Close-up of server racks in a data center highlighting modern technology infrastructure.
Photo by panumas nikhomkhai on Pexels

The British doctrine accepts this arithmetic and builds around it. When the NCA named Khoroshev, it paired the charges with sanctions and a public argument that even without custody, a named and sanctioned administrator cannot spend or travel freely, and the brand he runs becomes a liability for the affiliates who staff it. That argument is testable against what happened next, and the evidence supports only parts of it.

Days, not months: how fast the crews rebuilt

The clearest before-and-after measurement in the ransomware record belongs to ALPHV, also called BlackCat. On December 19, 2023, the FBI announced a court-authorized seizure of the gang's servers; the Justice Department put its ransom take near $300 million from more than 1,000 victims. Within about two days the gang claimed it had restored operations. Two months later, on February 21, 2024, an ALPHV affiliate attacked Change Healthcare, the clearinghouse that routes a large share of American medical claims and prescriptions. The attack delayed pharmacy and claims processing nationwide for weeks. UnitedHealth Group's chief executive later told the U.S. Senate that the company had paid a ransom, reported by Reuters and other outlets at roughly $22 million. In March 2024, ALPHV's administrators exit-scammed their own affiliate, who then offered the stolen data through a rival, RansomHub.

The next attack, in other words, was not delayed by the disruption of the last one. It was the largest in the crew's history, run on rebuilt infrastructure, and its aftermath, an internal theft, a defection and a second extortion, displayed the trust damage that law enforcement would later claim as a win.

LockBit's rebuild ran on the same clock. A leak site that had operated under the same brand since 2021 was back within days of the February 2024 seizure. Listing volume dipped in the second quarter of 2024 and recovered to pre-Cronos levels by the fourth, and a successor administrator went on to announce LockBit 4 and later LockBit 5 on rebuilt Tor infrastructure, claiming continuity with the original brand. Whether Khoroshev still runs that brand is not settled; leak-site analysts describe a successor, while a February 2026 reconstruction of the gang's history treats the original administrator as still present, and nobody outside the crew can say which is true. The builder outlived everyone in any case: the LockBit 3.0 builder, leaked in September 2022, was still being deployed in 2026 by DragonForce and unrelated smaller crews.

The infostealer market, where crews sell credential logs harvested from compromised machines, has the best measurement of all, because one vendor built a before-and-after dataset. Flare, a monitoring company, tracked roughly 44 million stealer logs ingested between June 2024 and June 2026 and computed what each major takedown did to daily volume. Most takedowns did nothing to the market and less than nothing to their targets. RedLine, the target of the Dutch-led Operation Magnus in October 2024, tripled in volume over the following 90 days (p = 0.045), and total market volume grew 70 percent over the same window (p = 0.032). The Endgame waves against dropper and loader infrastructure in 2024 and 2025 left market volume higher as well, a result Flare's analysts read as background ecosystem growth rather than any operational effect. A separate, earlier action that named LummaC2 among its targets was followed by a 75 percent increase in Lumma volume over 90 days (p = 0.004).

Across the cases, the pattern repeats: infrastructure that once lived for years gets rebuilt in days, and the seizure is survivable by design. Leak-site analysts put it flatly: infrastructure seizure alone "moves the needle for months, not years."

Where the affiliates went

A close-up photo of a computer screen showing the settings button with a cursor hovering over it.
Photo by Pixabay on Pexels

The workforce is the asset seizures cannot touch, and it was never going to sit idle. The template was set in May 2022 by Conti, the syndicate that dissolved itself after 170,000 internal chat messages leaked in the wake of its public backing of Russia's invasion of Ukraine. Conti's members did not retire. They dispersed into smaller operations including BlackCat, Hive, AvosLocker, HelloKitty and BlackByte, while data-only extortion units like Karakurt continued under other names. The U.S. government's ledger on Conti, more than $150 million in traced ransom payments, was never a measurement of a dead organization. It was a measurement of one that had changed its names.

Operation Cronos scattered LockBit's affiliate base the same way. Tracking tooling fingerprints, target selection and forum-account overlaps, leak-site analysts watched the displaced capacity recombine within roughly six months. A meaningful share went to Qilin, which became the top-volume ransomware operator of 2025 and 2026. Another tranche went to RansomHub, which absorbed both former LockBit and former ALPHV affiliates, briefly led the market with roughly 10 percent of known attacks, and then went quiet after March 31, 2025, for reasons nobody has publicly established. A smaller tier left the brand economy entirely, running direct extortion with no leak site, which makes it nearly invisible to the standard counting methods.

Counting the ecosystem now shows what the naming campaign actually dispersed. Malwarebytes tracked 41 new ransomware groups between July 2024 and June 2025, the first time more than 60 groups operated at once in its dataset. The ten most active groups account for roughly half of all attacks, down from 69 percent in 2022. The typical active group attacks about five targets a month. Flashpoint found that many of the newcomers are rebrands running on leaked code: SafePay shares code with LockBit, and Conti's fingerprints appear across current encryptors.

Recorded Future's Allan Liska reads that as a behavioral change rather than a market failure. It has become, in his words, "incredibly dangerous" to run a large, open-recruitment ransomware-as-a-service brand, because open recruitment is how the FBI and the NCA got inside. Affiliates face what he called two choices: join closed groups like Qilin or Akira, or start their own operations. "All the tools are still there for small groups," he said, from leaked encryptors to purchasable network access to free or cracked tooling.

How indicted crews changed the way they attack

Evil Corp is the longest-running controlled experiment in what naming and sanctions do to a crew's tradecraft. Sanctioned and indicted since December 2019, its operators kept working through a chain of renamed operations: Dridex and BitPaymer, then WastedLocker, then PayloadBIN, then by 2023 deployments under other people's brands, first LockBit and then Play ransomware. Microsoft's threat analysts and the UK's National Crime Agency described the rebranding explicitly as an attempt to evade sanctions, because a victim paying a sanctioned crew risks violating U.S. law. The NCA sanctioned 16 people linked to Evil Corp in December 2023 in part to close that door. The crews' own behavior is the clearest available evidence that the financial instrument bites: they keep changing names because the money is otherwise trapped.

The sanctions logic now hangs over every named crew. After Khoroshev's designation, paying a LockBit ransom could itself constitute a sanctions violation, which converts each LockBit extortion from a business decision into a legal exposure for the victim.

Close-up of handcuffed hands under blue police light, signifying arrest or detention.
Photo by Kindel Media on Pexels

The trust weapon is quieter, and the evidence for it is stronger. The FBI had been inside Hive's network since July 2022, handing more than 300 victims decryption keys and saving an estimated $130 million before the public takedown; the Hive brand never recovered its affiliate base, and affiliates migrated rather than re-up under a name the FBI had occupied for six months. The NCA disclosed that it kept the seized LockBit infrastructure running after Cronos, watching affiliates log in with their own credentials, and new affiliate signups under the LockBit name collapsed almost immediately. Trellix's John Fokker describes the resulting underground as a Mexican standoff, with affiliates offering the same stolen data across multiple leak sites and exit scams on the rise. "The hierarchy days of big groups, in my opinion, are over," he said. The Change Healthcare affiliate's journey, from ALPHV, to an exit scam, to RansomHub, to eviction, happened in public view.

So the measurable post-attribution tradecraft looks like this: smaller cells, closed recruitment, vetting of affiliates, disposable brands, data shopped across multiple sites to extend the extortion window, and direct extortion with no leak site at all. None of it is a decrease in capability. All of it is a decrease in trust, which is the one thing law enforcement has actually removed from the market.

Did any of it touch the money

The sharpest legal instrument attached to naming is sanctions. The Treasury's advisory on ransomware payments, first issued in October 2020 and expanded in September 2021, warned that paying a sanctioned crew can itself violate U.S. law regardless of the victim's motives. Sanctions are why Evil Corp keeps renaming itself. Sanctions are why paying LockBit after May 2024 became a legal hazard rather than a cost of doing business.

On the money itself, the record finally bends. Chainalysis, tracing cryptocurrency payments to attacker wallets, counted roughly $814 million in ransomware payments in 2024, down from about $1.25 billion in 2023: the first annual decline the firm had recorded, with its early 2025 figures pointing the same direction. The firm credits a mix of causes, from more victims refusing to pay to better defenses to cumulative law-enforcement pressure, Operation Cronos among them. The number deserves its caveats. Traced payments are a floor, not a ceiling, and the harm runs far past the ransom. But it is the only aggregate that has moved the way deterrence is supposed to move.

No single indictment can claim the decline. What the indictment record does show is which inputs the crews themselves treat as dangerous: not the names, and not the servers, but the payment rails and the recruiting channels.

The one operation that bent the curve

In Flare's dataset, exactly one operation reduced both its target and the market around it: the May 2025 action against LummaC2, an infostealer sold by subscription on criminal forums and Telegram channels. The FBI won court orders to seize Lumma's U.S.-hosted command infrastructure, with Europol and Microsoft's Digital Crimes Unit acting in parallel, and estimated that Lumma had infected roughly 394,000 Windows machines in the two months before the seizure.

Numerous bundles of US one dollar bills symbolizing wealth, finance, and savings.
Photo by Pixabay on Pexels

Flare measured the result. Lumma log volume fell 46 percent in the two weeks after the operation (p = 0.042) and stayed 39 percent below its pre-operation baseline over the following 90 days (p = 0.001). More striking, total infostealer market volume contracted across every window Flare measured: 55 percent at 14 days, 34 percent at 30, 19 percent at 60, and 38 percent at 90 days (p = 0.011). It was the only contraction in the entire dataset. Whatever rebuild attempts followed, the volume did not come back inside the window measured.

What made it different, in Flare's analysis, was structure. The earlier operations hit infrastructure: servers, domains, panels. The Lumma action hit infrastructure, distribution, monetization and trust at once, including the channels and services the malware depended on and the affiliates themselves, who were exposed by the seizure. The finding compresses to one line: coordinated pressure across the whole business moved the number. Pressure on any single part moved it nowhere, or up.

The caveats matter. Flare sells the monitoring it used, the corpus is its own telemetry, attributing logs to malware families is fingerprinting rather than ground truth, and one successful operation is one data point. The open question is whether the same four-part pressure can be applied to ransomware crews whose monetization runs through negotiators and insurers rather than log markets. The Endgame waves that targeted droppers and initial-access brokers were an attempt at exactly that, and in Flare's windows the market grew anyway.

Three doctrines, one ceiling

The main practitioners name people differently, and the differences show up in the outcomes. The United States is criminal-first: it indicted two LockBit affiliates, Artur Sungatov and Ivan Kondratyev, on the day of the takedown, and named the administrator three months later, bundled with sanctions and a bounty. The United Kingdom is sanctions-first and psychologically forward: the NCA ran LockBit's seized infrastructure as an intelligence source and treats the loss of anonymity itself as the weapon. Europe, through Europol's coordinated waves, rarely names anyone: it seizes at scale and its arrests fall on whoever is physically reachable in participating states.

None of the three doctrines measurably delayed the next attack. The differences show up elsewhere: in custody yield, which tracks borders; in financial reach, which tracks sanctions; and in trust damage, which tracks how long the seized infrastructure stays live after the seizure. On calendars, all three hit the same ceiling.

What the evidence actually measures

Three years of named attributions did not delay the next attack from the most-prosecuted crews. That is the central measurement, and it survives its exceptions. ALPHV ran the largest raid of its existence two months after the FBI took its servers. LockBit was listing new victims within weeks of losing its panels and its administrator's anonymity, and returned to pre-takedown listing volume within a year. RedLine tripled. Lumma's operators attempted their comeback within days of a seizure that did, uniquely, hold them down for the measured window.

What the campaign measurably changed is the shape of the enterprise. The megabrand with open recruitment is dying out: the top ten crews account for about half of attacks, down from 69 percent in 2022, and the workforce has redistributed into smaller, closed, harder-to-infiltrate units with disposable names. The payment curve bent down for the first time in 2024, for reasons that include this campaign but are not exhausted by it. And the underground's internal trust, which law enforcement broke deliberately, now produces exit scams, multi-listed data and infighting that researchers can watch in public.

Counter-evidence belongs in the ledger too. Notoriety functions as advertising in a market where reputation is the product; LockBitSupp called Cronos free publicity, and Malwarebytes concluded that leaked code, commoditized tooling and abundant AI are lowering the barrier to entry rather than raising it. RansomHub did not die of law-enforcement pressure; its portals went silent for reasons nobody has named. And one takedown, Lumma, moved the number the way strategy papers say it should, which is an argument that the tool works when it is built properly, not proof that it never does.

The measurable effect, stated as plainly as the evidence allows: naming people damages brands and trust. It does not damage calendars. What damages calendars is simultaneous pressure on money, distribution and recruiting, which is rare, and which happened once in the measured record. The unresolved question is whether the 2024 decline in payments was this campaign arriving late, or defense finally outpacing offense. Khoroshev, meanwhile, remains free in Russia. LockBit in 2026 is a thinner brand posting modest volumes under a name law enforcement spent years trying to bury. The next indictment is being drafted somewhere right now, with a name in it, aimed at a person who will most likely never see a U.S. courtroom. What the last three years measured is what that document will actually be worth.

Sources and references

A vintage world map illuminated by warm, yellow light creating a dramatic and atmospheric effect.
Photo by Nothing Ahead on Pexels
  1. U.S. Department of Justice, "U.S. and U.K. Disrupt LockBit Ransomware Variant," press release, February 20, 2024. https://www.justice.gov/archives/opa/pr/us-and-uk-disrupt-lockbit-ransomware-variant
  2. Aniruddha Mukhopadhyay, "The Gang That Refused to Die: LockBit Is Back, and This Time It Learned From Its Mistakes," Cyber Uncensored, February 24, 2026. https://cyberuncensored.substack.com/p/the-gang-that-refused-to-die-lockbit
  3. Ransomnews Research Team, "LockBit, 2 years after Operation Cronos: where are they now?," May 11, 2026. https://ransomnews.com/lockbit-after-operation-cronos-2026/
  4. Jonathan Greig, "Ransomware gang takedowns causing explosion of new, smaller groups," The Record, August 29, 2025. https://therecord.media/ransomware-gang-takedown-proliferation
  5. Andréanne Bergeron, "Infostealer Takedowns: Real-World Market Impact," Flare, September 25, 2026. https://flare.io/learn/resources/blog/infostealer-market-takedowns-impact
  6. Lawrence Abrams, "Conti ransomware shuts down operation, rebrands into smaller units," BleepingComputer, May 19, 2022. https://www.bleepingcomputer.com/news/security/conti-ransomware-shuts-down-operation-rebrands-into-smaller-units/
  7. BleepingComputer, reporting on LockBit's post-takedown relaunch and new affiliate claims, February 2024.
  8. U.S. Department of Justice, announcement of charges and sanctions against Dmitry Yuryevich Khoroshev, LockBit administrator, May 7, 2024.
  9. U.S. Department of Justice, press release announcing the disruption of Hive ransomware, January 26, 2023.
  10. U.S. Department of Justice, announcement of the disruption of ALPHV/BlackCat ransomware, December 19, 2023.
  11. U.S. Department of Justice, announcement of the court-authorized disruption of Lumma (LummaC2) infostealer malware, May 2025.
  12. U.S. Department of Justice, announcement of the sentencing of Yaroslav Vasinskyi for REvil ransomware attacks, 2024.
  13. U.S. Department of State, Rewards for Justice notice offering up to $10 million for information on TrickBot Group leadership, February 2023.
  14. Microsoft Threat Intelligence, analysis of Evil Corp's rebranding into ransomware-as-a-service operations, including LockBit and Play, to evade sanctions, September 2023.
  15. UK National Crime Agency, sanctions and statements concerning 16 individuals linked to Evil Corp, December 2023, and public updates on Operation Cronos, including the operation of seized LockBit infrastructure, 2024.
  16. Europol, press announcements on Operation Endgame, 2024 and 2025.
  17. U.S. Department of the Treasury, Office of Foreign Assets Control, "Advisory on Potential Sanctions Risks for Facilitating Ransomware Scheme," October 2020, updated September 2021.
  18. Chainalysis, 2025 Crypto Crime Report, ransomware payment analysis (2023–2024 payment totals).
  19. Reuters, reporting on the Change Healthcare ransomware payment of approximately $22 million, March 2024.
  20. Testimony of UnitedHealth Group chief executive Andrew Witty before the U.S. Senate on the Change Healthcare cyberattack, May 1, 2024.
Share this article

Comments (3)

  • Nadia C. Oct 7, 2026

    I want to push back gently on the framing that the December 2023 ALPHV disruption produced no meaningful delay. The article rightly notes that the Change Healthcare attack followed within two months, but the same timeline also shows the FBI seizure yielded decryption tools that responders handed to victims during that window. If "measurable difference" includes the roughly 7,000 LockBit victims covered by recovered keys, the ledger looks less like a null result and more like a tradeoff: rebuild speed against concrete recovery for the people actually hit. I keep wondering whether "delay of the next attack" is even the right yardstick, or whether the test the article is running sets enforcement up to look weaker than it really is.

  • owen.nakamura Oct 7, 2026

    We tracked the same pattern in our incident response work last year, with three LockBit-affiliated intrusions hitting healthcare targets within six weeks of the February 2024 seizure, which lines up with the leak-site volume the article describes.

  • A. Nakamura Oct 7, 2026

    The article frames the ALPHV exit-scam and the affiliate's defection to RansomHub as trust damage that enforcement can claim as a win, but I cannot tell from the data whether affiliates were really fleeing a poisoned brand or simply migrating to a platform that paid out more reliably. Is there telemetry that separates those two readings?

Comments are reviewed before they appear.

Continue exploring