LockBit dominates ransomware operations in summer 2024, claiming significantly more victims than competing threat groups, according to tracking data. The gang operates using a ransomware-as-a-service model, recruiting affiliates worldwide to deploy their encryption malware in exchange for a cut of extortion proceeds.

Two splinter groups derived from the defunct Conti ransomware operation trail LockBit in attack volume. Conti formally disbanded in 2022 after its leadership faced international sanctions, but its infrastructure and operational playbooks migrated to successor organizations. These offshoots maintain similar tactics, targeting mid-market and enterprise organizations across healthcare, manufacturing, finance, and critical infrastructure sectors.

LockBit's ascendancy reflects operational maturity and aggressive affiliate recruitment. The group operates leaks sites where they publish stolen data from organizations that refuse to pay ransoms, amplifying pressure on victims. They exploit publicly disclosed vulnerabilities, brute-force credential attacks, and insider access to establish footholds in target networks. Once inside, operators deploy encryption that locks files and systems, rendering them inaccessible until victims pay demands typically ranging from six to seven figures.

The resurgence of ransomware volume this summer follows a period where law enforcement disruptions and sanctions against ransomware payment infrastructure created temporary friction. However, threat actors adapted quickly. LockBit and successor groups shifted money laundering tactics, diversified cryptocurrency conversion methods, and recruited new affiliates in regions with less aggressive law enforcement oversight.

Healthcare organizations face disproportionate risk. Hospitals cannot easily take systems offline during ransom negotiations, creating negotiating disadvantages. Manufacturers face production halts that cost millions daily. Financial services firms risk exposure of customer data and regulatory penalties. Critical infrastructure operators managing power grids, water treatment, and transportation networks contend with life-safety implications when systems go down.

The business model driving this rise differs from traditional cybercrime. RaaS operators handle infrastructure, tools, and ransom negotiations while affiliates focus on initial access and network penetration. This specialization increases attack frequency and professionalism. Affiliates operate like franchisees, receiving training and support from LockBit's core team. Revenue sharing incentivizes recruitment and performance.

Organizations face mounting pressure to implement defensive measures. Multi-factor authentication blocks credential-based entry points. Network segmentation isolates critical systems so encryption cannot spread laterally. Regular backup protocols ensure recovery without ransom payment. Threat intelligence feeds help security teams identify LockBit indicators of compromise before encryption deploys.

Law enforcement agencies worldwide coordinate counter-ransomware operations, but attribution and prosecution remain difficult. Threat actors operate from jurisdictions with limited extradition treaties. Cryptocurrency transactions obscure money flows. The affiliate model distributes culpability across multiple actors in different countries, complicating prosecutions.

Organizations monitoring threat feeds report increasing targeting of smaller firms. Attackers recognize larger enterprises maintain stronger defenses and potentially better insurance coverage that complicates payouts. Mid-market organizations often lack robust incident response capabilities, making them attractive targets. This shift expands the threat beyond traditional high-value targets.

The summer surge signals LockBit's operational stability and the RaaS model's continued viability despite disruption efforts. Defenders must assume ransomware remains a persistent threat, not a temporary problem.