Operator-curated identity decision: lockbit5 is folded into lockbit. lockbit has no surviving claim-source observation. lockbit5 was supplied by RansomLook and ransomware.live. The feeds supplied these spellings; neither asserted that they are one actor.
Portable threat brief
LockBit
Versioned profile fields only · no model narrative
Opens the browser print dialog; choose Save as PDF.
PDF export is unavailable. The threat brief remains available below; use your browser's Print command.
Executive facts
Actor
LockBit
Kind
ransomware
Aliases
lockbit5
Actor record created
2026-07-10
Latest observed
2026-09-10
Leak-site claims
245
Catalogued techniques
0
Scope
Tracked sectors
Manufacturing, Business & Professional Services, Healthcare, Construction & Engineering, Retail
Claim records
2026-01-19 to 2026-09-10
Independent reporting
2025-05-13 to 2026-09-10
Decisive signals with dates
No dated decisive signals are attached to this actor's linked vulnerabilities.
Verified techniques
No verified ATT&CK mapping in this corpus.
Defensive actions
No defensive actions are attached to this profile.
Most-claimed sectorsManufacturingBusiness & Professional ServicesHealthcareConstruction & EngineeringRetail
Activity window in this corpus
This is only the tracker's observed corpus window. It is not this actor's lifetime or evidence of dormancy outside these dates.
Bibliography via Malpedia (Fraunhofer FKIE), CC BY-NC-SA 3.0; links go to the original publisher.
No MITRE ATT&CK group mapping exists for this actor yet. Mappings here are strict: an actor links to a MITRE group only when the group's own name, aliases, or MITRE-published description match, and MITRE has not catalogued this group. Technique and defensive action data will appear automatically if a verified mapping lands.
Claims attributed to this actor or leak site
245 in this corpus
alphaomega-eng.comBusiness & Professional Servicessource ↗