News

LockBit Ransomware Group Adopts Triple Extortion After High-Profile Attack

Updated 8 min read1735 words
LockBit logo used on the group's leak site
LockBit logo used on the group's leak site. Image: LockBit via Wikimedia Commons, Public domain

When a ransomware gang's own leak site gets knocked offline by a DDoS attack, most operators would scramble to restore service. LockBit did that, but then went further: they decided to add DDoS attacks to their standard extortion toolkit. In September 2022, the lockbit ransomware group announced this shift after a confrontation with Entrust, a digital security company that refused to pay a ransom following a June breach. The incident marked a turning point in how ransomware operators pressure victims, layering network disruption on top of encryption and data theft.

The Entrust Breach and the DDoS Counterattack

On June 18, 2022, LockBit compromised Entrust and exfiltrated company data. Entrust confirmed the breach but declined to pay the ransom. LockBit announced it would publish the stolen files on August 19, but the release was delayed when someone launched a distributed denial-of-service attack against the gang's leak site. Security researchers widely suspected that Entrust or a party acting on its behalf commissioned the DDoS to prevent the data from becoming public.

The attack temporarily blocked access to the leak site, frustrating LockBit's ability to shame the victim and demonstrate credibility to future targets. LockBitSupp, the public representative of the operation, acknowledged the disruption in posts on underground forums. Rather than retreat, the group upgraded its infrastructure with additional mirrors and randomized victim-specific links in ransom notes to make future DDoS campaigns harder to execute.

By late August, LockBit released a 343-gigabyte torrent labeled "entrust.com" and shared it through multiple file-hosting services to ensure availability. The gang also distributed the data privately to anyone who requested it before the public torrent went live, maximizing reputational damage to Entrust.

What Triple Extortion Ransomware Means

Traditional ransomware encrypts files and demands payment for the decryption key. Double extortion, which became common around 2019, adds a second lever: the threat to publish stolen data if the victim refuses to pay. Triple extortion ransomware layers a third pressure tactic on top of encryption and data leaks.

For lockbit 3.0 and similar operations, that third tactic is typically a DDoS attack against the victim's public-facing infrastructure. The goal is to disrupt business operations in real time, forcing the victim to negotiate while customers and partners see downtime. In LockBitSupp's own words on a hacker forum, the operator said they were "looking for DDoSers in the team" and planned to "attack targets and deploy triple blackmail, encryption plus data leak plus DDoS."

This approach raises the stakes for defenders. A company that has offline backups and can restore encrypted systems still faces public data exposure and potential service outages that harm revenue and reputation. The lockbit ransomware group calculated that victims under simultaneous pressure from all three vectors would be more likely to pay quickly.

How LockBit Hardened Its Infrastructure

After the Entrust incident, LockBit implemented several technical changes to resist future takedown attempts. The gang introduced unique, randomized links in ransom notes so that each victim received a distinct onion address. This made it harder for defenders or rival actors to identify and target the leak site with automated DDoS tools.

LockBit also expanded the number of mirror sites and duplicate servers hosting stolen data. The group announced plans to publish leaks on clearnet file-storage services in addition to onion sites, broadening the attack surface and ensuring that even if one mirror went down, the data would remain accessible elsewhere. The 343-gigabyte Entrust torrent exemplified this strategy: it was seeded through multiple channels, making complete suppression nearly impossible.

These infrastructure upgrades reflect a broader trend among top-tier ransomware operations. Groups that survive law enforcement pressure and rival attacks tend to adopt redundancy, decentralization and operational security practices borrowed from legitimate content-delivery networks. For victims, this means that paying a ransom to prevent publication is less reliable than it once was, because copies of the data may already be distributed beyond the original attacker's control.

LockBit leak site after the February 2024 law-enforcement takeover (Operation Cronos)
LockBit leak site after the February 2024 law-enforcement takeover (Operation Cronos). Image: Darknetlive via Wayback Machine

LockBit Black and the Evolution of the Brand

LockBit has operated under several names and versions since its emergence in September 2019. The lockbit black ransomware variant, also marketed as LockBit 3.0, introduced a ransomware-as-a-service model with a polished affiliate program. Affiliates could customize ransom notes, set their own payment demands and access a panel that tracked victim negotiations.

The group's leak site listed more than 700 victims at the time of the Entrust incident, spanning healthcare, manufacturing, legal services and technology sectors. LockBit's public persona, managed by LockBitSupp, combined technical competence with a provocative communication style. Posts on underground forums mixed operational updates with taunts directed at victims and competitors.

This branding strategy served a dual purpose: it attracted skilled affiliates who wanted a reliable platform, and it intimidated victims by projecting an image of invincibility. The decision to adopt triple extortion after the Entrust DDoS was framed not as a defensive reaction but as an offensive innovation, reinforcing the group's reputation for adaptability.

Context: How Ransomware Ecosystems Adapt

Public law enforcement press releases from agencies including the FBI and Europol describe ransomware operations as franchises, where core developers lease malware to affiliates who conduct the actual intrusions. This structure allows groups like LockBit to scale quickly while insulating leadership from direct attribution. When one affiliate is arrested or one server is seized, the operation can continue with minimal disruption.

Security-vendor incident reports from firms that negotiate with ransomware actors note that payment does not guarantee data deletion. Victims who pay often receive decryption keys, but copies of exfiltrated files may remain in the hands of affiliates or be sold to third parties. This reality undermines the value proposition of triple extortion: even if a victim capitulates under DDoS pressure, the data may still surface later.

Court records from ransomware prosecutions reveal that many affiliates are recruited from forums where they previously sold DDoS services, carding tools or access to compromised networks. The addition of DDoS to the extortion playbook reflects this talent pool. For defenders, the lesson is that ransomware groups are not static adversaries; they absorb techniques from adjacent cybercrime markets and iterate on their business models faster than many organizations can update their incident-response plans.

What Defenders and Ordinary Users Should Know

Organizations facing a lockbit ransomware group intrusion should assume that paying the ransom will not prevent data publication or future attacks. Backups stored offline and tested regularly remain the most reliable defense against encryption. Network segmentation and endpoint detection can limit lateral movement if an affiliate gains initial access.

For individuals, the risk from LockBit and similar operations is indirect but real. When a healthcare provider, law firm or financial institution is breached, customer and patient data often ends up in the leak. Monitoring for exposed credentials on breach-notification services and enabling multi-factor authentication on sensitive accounts reduces the downstream harm from these incidents.

The Entrust case also illustrates the limits of offensive countermeasures. A DDoS attack against a ransomware leak site may delay publication, but it does not recover stolen data or prevent the attacker from distributing it through alternative channels. Some security experts argue that such tactics can escalate conflicts and provoke retaliatory attacks, while others see them as a necessary deterrent. Either way, the technical and legal risks of commissioning a counter-DDoS are significant, and most organizations are better served by investing in prevention and resilience.

Lessons from the Triple Extortion Shift

The move to triple extortion ransomware signals that ransomware operators view their work as a negotiation game where leverage matters more than technical sophistication. Encryption alone is no longer enough to force payment, because many targets have improved their backup and recovery processes. Data theft adds reputational risk, but some victims are willing to absorb that cost rather than fund criminal enterprises. DDoS attacks introduce a third dimension of pain that is harder to mitigate in real time.

This escalation also reflects the competitive pressure within ransomware markets. Groups that fail to innovate lose affiliates to rivals offering better tools, higher payouts or more reliable infrastructure. LockBit's public announcement of the triple extortion model was as much a recruitment pitch as a threat to victims.

For readers tracking dark web news and ransomware trends, the key takeaway is that these operations are businesses with marketing strategies, customer service and product development cycles. Understanding how they evolve helps defenders anticipate the next shift and allocate resources accordingly. The Entrust incident was not an isolated event but a preview of tactics that other groups would adopt in the months and years that followed.

Frequently asked questions

What is LockBit ransomware?

LockBit is a ransomware operation that emerged in September 2019 and operates as a service, leasing its malware to affiliates who carry out attacks. The group encrypts victim files, steals data before encryption and threatens to publish that data on a leak site if the ransom is not paid. LockBit 3.0, also called LockBit Black, introduced triple extortion by adding DDoS attacks to the standard encryption and data-leak tactics.

How does triple extortion ransomware work?

Triple extortion combines three pressure tactics: encrypting the victim's files and demanding payment for the decryption key, threatening to publish stolen data on a public leak site, and launching DDoS attacks against the victim's network to disrupt operations in real time. The goal is to force payment by maximizing the immediate and reputational costs of refusing to negotiate. LockBit adopted this model after experiencing a DDoS attack on its own infrastructure during the Entrust incident in 2022.

Can paying a ransomware group guarantee data will not be leaked?

No. Security-vendor incident reports and court records show that paying a ransom often results in a decryption key, but there is no reliable mechanism to verify that all copies of stolen data have been deleted. Affiliates may retain copies, sell them to other actors or leak them later. Some ransomware operations have been caught re-extorting victims who already paid, and data from paid ransoms has appeared in subsequent breaches and underground markets.

What happened to LockBit after the Entrust attack?

After the Entrust breach and the subsequent DDoS attack on its leak site, LockBit upgraded its infrastructure with randomized victim links, additional mirrors and plans to distribute stolen data via clearnet file-hosting services and torrents. The group publicly announced its shift to triple extortion and continued to list hundreds of victims on its leak site. The operation remained active for years after the Entrust incident, though its status and leadership have been the subject of ongoing law enforcement actions and reporting.

How can organizations defend against triple extortion ransomware?

Effective defenses include offline backups that are tested regularly, network segmentation to limit lateral movement, endpoint detection and response tools, and incident-response plans that assume data exfiltration has already occurred. Organizations should also prepare for DDoS attacks by working with their hosting providers and content-delivery networks to implement rate limiting and traffic filtering. Paying the ransom does not reliably prevent data publication, so prevention and resilience are more cost-effective than negotiation.

lockbit 3.0lockbit black ransomwarelockbit ransomware grouptriple extortion ransomwareransomware as a servicedata leak sitedouble extortionDDoS extortion