LockBit Ransomware Group Reportedly Suffers Data Breach, Extortion Tactics Revealed

LockBit group’s admin and affiliate panels were reportedly defaced and replaced with a message and link to MySQL database.

Advertisement
Written by Akash Dutta, Edited by Siddharth Suvarna | Updated: 9 May 2025 18:39 IST
Highlights
  • The panels said to show the message “Don’t do crime[.]Crime is bad”
  • The MySQL database dump reportedly contains twenty tables
  • It also shows negotiation messages between LockBit and victims

As many as 75 admin and affiliate names were also listed in a “users” table

Photo Credit: Unsplash/Desola Lanre-Ologun

LockBit, the notorious ransomware group, reportedly suffered a massive data breach on Wednesday. As per the report, the group's dark web platform's admin and affiliate panels were compromised to show a message and link to a MySQL database dump. The database reportedly contains 20 tables that include sensitive information around the cybercriminal group's affiliate network, extortion tactics, details around malware builds, as well as nearly 60,000 Bitcoin addresses. Notably, this is the second time the ransomware group has been hacked, with the previous attack occurring in 2024.

LockBit Hack Reveal Insights Into The Gang's Workings

The data breach was first spotted by X (formerly known as Twitter) user Rey, who posted a screenshot of the admin panel. All of the admin and affiliate panels were reportedly taken over to display the message, “Don't do crime[.]CRIME IS BAD xoxo from Prague.” The text is followed by the MySQL link "paneldb_dump.zip."

According to a BleepingComputer report, the link leads to a MySQL file containing a massive database. The data reportedly features 20 different tables, where some tables revealed information about how the ransomware group functioned, as well as its malware builds.

Advertisement

One of the tables, labelled “btc_addresses,” reportedly features as many as 59,975 unique Bitcoin addresses. Another “builds” table is said to feature individual malware builds that were created by the group's affiliates. These are said to be different versions of the same ransomware that the group used to attack others. Some of the builds reportedly also mentioned the names of the targeted companies. This table is also said to feature public keys to the builds, but no private keys. Private keys are necessary to access the ransomware.

Advertisement

Apart from this, the database reportedly featured a “builds_configurations” that revealed information about different configurations used for each version of the malware. The most interesting information, however, was reportedly contained in the “chats” table.

The table is said to contain 4,442 negotiation messages between the LockBit ransomware operators and victims. The messages reportedly were dated between December 19, 2024 and April 29. This list highlighted different extortion techniques used by the gang.

Advertisement

Further, a “users” table reportedly revealed the names of 75 admins and affiliates of the group. These names were said to belong to individuals who had access to the panels. Additionally, the table also contained passwords used by the admins in plaintext.

In a separate post, Rey shared a conversation with a LockBit operator, who goes by the username “LockBitSupp”, confirming the data breach. The operator stated that the source code of the ransomware and private keys were not lost during the hack. The group or individual behind the LockBit hack is currently not known.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement
Popular Mobile Brands
  1. Apple Launches iPhone 17 at 'Awe Dropping' Event With These Upgrades
  2. Apple Launches iPhone 17 Pro, 17 Pro Max With These Massive Upgrades
  3. Apple Watch Series 11, Ultra 3, SE Launched With These Health Features
  4. Apple MacBook Air M4 Available With Up to Rs. 16,000 Discount via Amazon
  5. Xiaomi Confirms Authorised Retailers Ahead of Amazon, Flipkart Festive Sales
  6. Tecno Spark Slim Listed Online; Colour Options, Specifications Revealed
  7. Apple Launches iPhone Air as the Slimmest iPhone to Date
  8. iPhone 17 Launch Highlights: iPhone 17 Series, AirPods 3, and More Launched
  9. Flipkart Big Billion Days Sale: Google Pixel 9 to Get This Huge Price Cut
  10. iQOO 15, iQOO Neo 11 Series Details Tipped; Might Feature 7,000mAh Battery
  1. iPhone 17 Pro, iPhone 17 Pro Max Are Here: Massive Camera Upgrades, and A19 Pro Chip
  2. iPhone Air Launched: Ultra-Slim Form Factor, Apple Intelligence Features, and More
  3. iPhone 17 Launched: A19 Chip, Apple Intelligence, and More
  4. Apple Watch Series 11, Ultra 3, and SE Launched: Thinner Design and New Health Sensors
  5. AirPods Pro 3 Launched: Featuring Lossless Audio and a Redesigned Case
  6. Tecno Spark Slim Full Specifications Revealed; Features MediaTek Helio G200 SoC, 5.93mm Thick Build
  7. Samsung Galaxy S26 Ultra Tipped to Feature Thicker Rear Camera Module Comprising 50-Megapixel Telephoto Camera
  8. Hollow Knight: Silksong Has Reportedly Crossed 5 Million Players in 3 Days
  9. Apple Powerbeats Fit Colour Options, Key Features Leaked; May Offer Up to 30 Hours Total Battery Life
  10. Global Premium Smartphone Sales Hit Record High in H1 2025 as Google Re-Enters Top Five: Counterpoint
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.