A Longitudinal Analysis of LockBit 3.0's Extortion Lifecycle and Response to Law Enforcement

Conference Paper (2025)
Author(s)

Yin Minn Pa Pa (Yokohama National University)

Yuji Sekine (Yokohama National University)

Yamato Kawaguchi (Yokohama National University)

Tatsuki Yogo (Yokohama National University)

Kelvin Lubbertsen (TU Delft - Technology, Policy and Management)

Rolf Van Wegberg (TU Delft - Technology, Policy and Management, Yokohama National University)

Michel Van Eeten (TU Delft - Technology, Policy and Management, Yokohama National University)

Katsunari Yoshioka (Yokohama National University)

Research Group
Organisation & Governance
DOI related publication
https://doi.org/10.1109/RAID67961.2025.00043 Final published version
More Info
expand_more
Publication Year
2025
Language
English
Research Group
Organisation & Governance
Pages (from-to)
538-551
Publisher
IEEE
ISBN (electronic)
9798331566036
Event
28th International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2025 (2025-10-19 - 2025-10-22), Gold Coast, Australia
Downloads counter
22
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

In this study, we present a 532-day longitudinal analysis of LockBit 3.0's leak site. We track 1,856 victims across multiple states-countdown, data publication, deletion, and relisting-and reconstruct a structured, three-stage extortion lifecycle: (1) pre-listing negotiation, (2) countdown negotiation, and (3) post-leak monetization. We find that 8.5 % of countdownstate victims are deleted before their data is published, suggesting private settlements. In the post-leak phase, victims with price tags exhibit significantly more variable deletion timing compared to those without, despite sharing the same median exposure. This indicates that LockBit actively manages some listings after data publication, potentially extending monetization or negotiation efforts.We also measure the operational impact of law enforcement actions-including Operation Cronos and affiliate arrests-on LockBit's infrastructure and victim activity. While the group rapidly restored services after takedowns, we observe a sustained decline in new victim onboarding, reduced infrastructure redundancy, and delayed payment behavior, suggesting long-term weakening.To our knowledge, this is the first empirical study to model a ransomware extortion lifecycle based on continuous monitoring of leak site behavior. Our findings provide actionable insights into ransomware monetization tactics, negotiation patterns, and post-takedown adaptation.

Files

A_Longitudinal_Analysis_of_Loc... (pdf)
(pdf | 1.69 Mb)
- Embargo expired in 30-07-2026
Taverne