LockBit ransomware website hacked, database and Bitcoin keys leaked 6 seconds ago

cryptonews
08 May

A group claiming to be from Prague has seemingly hijacked LockBit’s dark web panel and leaked sensitive data, including its internal systems and Bitcoin wallets.

LockBit, one of the most notorious ransomware gangs, appears to have been hacked by someone claiming to be from Prague, who leaked internal data and left a message mocking the group.

Analysts at blockchain security firm SlowMist revealed in a Thursday blog post that the leaked data package included over 60,000 Bitcoin (BTC) addresses, about 75 user credentials, and ransom negotiation logs. One of the records even pointed to a ransom possibly being paid from a Coinbase account.

LockBit’s internal web interface | Source: SlowMist

The attackers also appear to have gained access to a lightweight PHP-based management platform used by LockBit.

“[…] we speculate that the hacker from ‘Prague’ likely exploited a PHP 0-day or 1-day vulnerability to compromise the web backend and management console.”

SlowMist

LockBit later responded in Russian on its official channel. When asked whether the group was “pwned,” LockBit claimed that “only the lightweight panel with an authorization code was breached,” reassuring that “no decryptors were stolen, and no company data was affected.”

Ransom negotiation chat | Source: SlowMist

When asked if the hack would damage its reputation, LockBit admitted that it “affects” its reputation, but reiterated that the source code “was not stolen” and that the group is “already working on recovery.” Ironically, LockBit is now offering a bounty for information on the hacker, despite the U.S. government having previously offered up to $15 million in rewards for information on LockBit members.

Read more: Russia’s Zservers sanctioned by US, UK, and Australia for serving crypto ransomware LockBit

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Most Discussed

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10