zerofox logo
Advisories

ZeroFox Intelligence Flash Report - Data Breach Exposes Operational LockBit Information

|by Alpha Team

banner image

ZeroFox Intelligence Flash Report - Data Breach Exposes Operational LockBit Information

Product Serial: F-2025-05-08a

TLP:CLEAR

In this Flash Report, ZeroFox researchers report on the internal LockBit data made available for download, following the recent defacement of the collective's dark web victim leak domain by an unknown actor.

Standing Intelligence Requirements

DDW

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here

Key Findings

  • On May 7, 2025, actor “Rey” posted on the social media platform X (formerly Twitter) claiming that digital infrastructure associated with the once-prominent ransomware-as-a-service (RaaS) collective LockBit had been breached.
  • As of the writing of this report, several of LockBit’s dark web [.]onion blog domains display the message "Don't do crime CRIME IS BAD xoxo from Prague”, accompanied by a download link containing a MySQL data dump.
  • Tables available within a MySQL download include information pertaining to ongoing LockBit operations, including victim negotiations, Bitcoin addresses, and malware build configurations.
  • At the time of writing, it is unclear who is responsible for the breach, though an almost-identical message was posted on the [.]onion victim leak side of the ransomware collective Everest in April 2025.
  • This incident will very likely exacerbate LockBit’s ongoing efforts to re-establish operational continuity, maintain a steady attack tempo, and attract affiliates, following the collective’s February 2024 disruption by law enforcement (LE) entities.

Tags: tlp:clear,  dark web,  data breach,  threat actor, MAL Ransomware