CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Threat actor

LockBit

ransomware245 leak-site claims, all timeLatest observed leak-site post 2026-09-10Malpedia ↗ETDA ↗ORKL search ↗
aka lockbit5
Operator-curated identity decision: lockbit5 is folded into lockbit. lockbit has no surviving claim-source observation. lockbit5 was supplied by RansomLook and ransomware.live. The feeds supplied these spellings; neither asserted that they are one actor.

Portable threat brief

LockBit

Versioned profile fields only · no model narrative

Opens the browser print dialog; choose Save as PDF.

PDF export is unavailable. The threat brief remains available below; use your browser's Print command.

Executive facts

Actor
LockBit
Kind
ransomware
Aliases
lockbit5
Actor record created
2026-07-10
Latest observed
2026-09-10
Leak-site claims
245
Catalogued techniques
0

Scope

Tracked sectors
Manufacturing, Business & Professional Services, Healthcare, Construction & Engineering, Retail
Claim records
2026-01-19 to 2026-09-10
Independent reporting
2025-05-13 to 2026-09-10

Decisive signals with dates

No dated decisive signals are attached to this actor's linked vulnerabilities.

Verified techniques

No verified ATT&CK mapping in this corpus.

Defensive actions

No defensive actions are attached to this profile.

Most-claimed sectorsManufacturingBusiness & Professional ServicesHealthcareConstruction & EngineeringRetail
Activity window in this corpus

This is only the tracker's observed corpus window. It is not this actor's lifetime or evidence of dormancy outside these dates.

Claim records
First observed Latest observed
Independent reporting
First observed Latest observed
Verified ATT&CK phases represented

No verified ATT&CK mapping in this corpus

Origin and motivation

Origin and motivation not attributed.

Research trail

Bibliography via Malpedia (Fraunhofer FKIE), CC BY-NC-SA 3.0; links go to the original publisher.

No MITRE ATT&CK group mapping exists for this actor yet. Mappings here are strict: an actor links to a MITRE group only when the group's own name, aliases, or MITRE-published description match, and MITRE has not catalogued this group. Technique and defensive action data will appear automatically if a verified mapping lands.

Claims attributed to this actor or leak site
245 in this corpus
View all on Breaches →
Leak-site claim activity

0 additional claims without a disclosure date

2026-012026-09
Independent reporting that mentions this actor
10 in this corpus

Ransomware claim data is unverified: RansomLook (CC BY 4.0) and ransomware.live (No data licence; credited voluntarily).

Glossary