A Longitudinal Analysis of LockBit 3.0's Extortion Lifecycle and Response to Law Enforcement
Yin Minn Pa Pa (Yokohama National University)
Yuji Sekine (Yokohama National University)
Yamato Kawaguchi (Yokohama National University)
Tatsuki Yogo (Yokohama National University)
Kelvin Lubbertsen (TU Delft - Technology, Policy and Management)
Rolf Van Wegberg (TU Delft - Technology, Policy and Management, Yokohama National University)
Michel Van Eeten (TU Delft - Technology, Policy and Management, Yokohama National University)
Katsunari Yoshioka (Yokohama National University)
More Info
expand_more
Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.
Abstract
In this study, we present a 532-day longitudinal analysis of LockBit 3.0's leak site. We track 1,856 victims across multiple states-countdown, data publication, deletion, and relisting-and reconstruct a structured, three-stage extortion lifecycle: (1) pre-listing negotiation, (2) countdown negotiation, and (3) post-leak monetization. We find that 8.5 % of countdownstate victims are deleted before their data is published, suggesting private settlements. In the post-leak phase, victims with price tags exhibit significantly more variable deletion timing compared to those without, despite sharing the same median exposure. This indicates that LockBit actively manages some listings after data publication, potentially extending monetization or negotiation efforts.We also measure the operational impact of law enforcement actions-including Operation Cronos and affiliate arrests-on LockBit's infrastructure and victim activity. While the group rapidly restored services after takedowns, we observe a sustained decline in new victim onboarding, reduced infrastructure redundancy, and delayed payment behavior, suggesting long-term weakening.To our knowledge, this is the first empirical study to model a ransomware extortion lifecycle based on continuous monitoring of leak site behavior. Our findings provide actionable insights into ransomware monetization tactics, negotiation patterns, and post-takedown adaptation.