SBU detains LockBit ransomware hackers in Ternopil Oblast

Investigators conducted searches in Ternopil
Investigators conducted searches in Ternopil

In collaboration with law enforcement from the UK, the United States, and the EU, Ukraine’s SBU security service has detained members of the prominent international hacker group LockBit in Ternopil Oblast, the SBU announced on Feb. 21.

Read also: Top Ukraine officials, NATO allies to discuss securing communications, countering hackers in Kyiv

The entire operation was conducted in various parts of the world, according to the message.

The SBU noted that the suspects included citizens of Ukraine and Russia. The suspects allegedly stole or encrypted confidential information from numerous companies and then demanded a ransom.

Over the course of nearly five years, the hackers carried out more than 3,000 cyberattacks against businesses in Western countries that provide military aid to Ukraine. In one case involving a U.S. company, the suspects demanded over $90 million, according to the SBU.

<span class="copyright">Office of the Prosecutor General</span>
Office of the Prosecutor General

To steal information, the hackers used specially designed ransomware and injected malicious software into users' computers. This computer virus gathered confidential information, crippled the workstations by encrypting the data, and demanded payments to restore functionality.

<span class="copyright">Office of the Prosecutor General</span>
Office of the Prosecutor General

Should the victims refuse to pay, the criminals threatened to leak confidential data online.

Ukrainian police reported that in Ukraine, the criminal activities were coordinated by a father and son duo. Individuals, enterprises, state institutions, and health facilities in France suffered from their actions.

Investigators conducted searches at the residences of the hackers in Ternopil, where mobile phones and computer equipment were confiscated.

Simultaneously, law enforcement has blocked over 200 cryptocurrency accounts linked to the criminal activity and has taken down 34 servers located in the Netherlands, Germany, Finland, France, Switzerland, Australia, the United States, and the UK.

Authorities stated that LockBit is considered the most prominent hacker group among ransomware operators worldwide.

Read also: Hackers leverage popular encrypted app, disguising malware payloads as military recruitment offers

We’re bringing the voice of Ukraine to the world. Support us with a one-time donation, or become a Patron!

Read the original article on The New Voice of Ukraine