Operation Cronos dismantled LockBit’s infrastructure in February 2024. The FBI seized the servers, took down the leak site, published the faces and names of operators. Weeks later, ALPHV/BlackCat got the same treatment: infrastructure seized, December 2023. Both were declared, more or less, decisive victories.
By mid-2024, RansomHub was the most active ransomware group in the world. Staffed largely by former LockBit and ALPHV affiliates.
If you’re trying to understand why this threat never seems to go away, the answer isn’t that law enforcement isn’t trying. It’s that they’re targeting the wrong layer.
How the Franchise Actually Works
Modern ransomware isn’t a gang. It’s a franchise operation, and like any franchise, the brand is not the business.
The developers build and maintain the platform: the ransomware code, the payment infrastructure, the negotiation portals, the backend that makes the operation run. Small groups, sometimes five to fifteen people, with genuine software engineering capability. Based in jurisdictions where extradition is either impossible or politically inconvenient. These are the people law enforcement can actually prosecute if they can get to them.
The affiliates are the operators. They break into organisations, move laterally, exfiltrate data, deploy the ransomware, and conduct the ransom negotiation. They’re running on a revenue-sharing model, typically keeping 70–80% of any payment, with the remainder going to the developers as a platform fee. At any given time, an active ransomware programme might have dozens to hundreds of affiliates working simultaneously, independently, across different sectors and geographies.
The initial access brokers are a separate market that feeds the affiliate layer. They specialise in a single capability: getting into organisations and establishing persistent access. Then they sell that access. A broker might sell credentials into a hospital network for $10,000 to an affiliate who deploys ransomware and collects $2 million. The broker never needs to know what happened next.
Takedowns Hurt the Developers. Affiliates Just Switch Platforms.
When the FBI seizes LockBit’s infrastructure, they’re removing the backend that the developers built and operated. This is genuinely disruptive. It imposes real cost. It’s worth doing.
It’s nearly irrelevant to the affiliates.
An affiliate who spent three years developing expertise in breaking into corporate networks, evading endpoint detection, and navigating the access controls of healthcare IT environments doesn’t lose any of that when LockBit goes down. They lose access to one platform. The process of registering with RansomHub or BlackSuit typically takes less than a week. The skills, the tooling, the access broker relationships: all of it transfers.
The initial access brokers aren’t affected at all. They sold access before the takedown. They’re selling access now. Their market doesn’t care which ransomware platform their customers prefer this week.
The Threat Model That Actually Matters
Understanding the franchise structure changes the question you should be asking.
Not: is the specific group that hit your competitor last month still operational? Probably yes, in some form. Irrelevant either way.
The question is whether the conditions that made your competitor an attractive target (unpatched VPN appliances, weak MFA adoption, a detection capability that doesn’t see lateral movement) are present in your own environment.
Affiliates don’t choose targets based on brand affinity or industry ideology. They choose based on a calculation: effort required to get in and deploy, relative to the likely payout. High-friction environments, where getting in, moving laterally, and executing without triggering detection all require meaningful effort, get passed over for easier options. There are always easier options.
The defensive investments that change this calculation are not glamorous. Current patch state on externally-facing systems. MFA enforced on remote access without exceptions for senior staff who find it inconvenient. Network segmentation that actually limits how far lateral movement can go. Backups that are genuinely offline, not just on a different VLAN. None of this requires knowing which ransomware group is most active this quarter. All of it remains relevant regardless.
What Law Enforcement Actually Contributes
There is something genuinely useful that comes out of law enforcement operations, even when they don’t stop the threat long-term.
When LockBit was dismantled, the FBI published internal communications, affiliate agreements, negotiation transcripts, and details of the group’s operational tradecraft. That intelligence has real value, not for predicting the next attack, but for understanding the economics, the tooling, and the techniques that the people actually conducting these operations use. It informs defensive product development. It produces better red team scenarios. It tells you whether your controls would have caught the specific technique LockBit affiliates were using most successfully.
The FBI’s most durable contribution to ransomware defence may not be the infrastructure seizures. It’s the intelligence that comes out of them afterwards.