/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

LockBit ransomware's leak sites suffer a DDoS attack after it claimed responsibility for breaching Entrust in June; LockBit blames Entrust for the DDoS attack

Lawrence Abrams / BleepingComputer :

BleepingComputer Lawrence Abrams

Context & Ripple Effects

Entrust had already confirmed that a ransomware gang stole internal data in June, making LockBit's claim an escalation of a confirmed breach at the identity-management provider. The DDoS outage matters because it temporarily disrupts the public infrastructure LockBit uses to turn a breach claim into extortion pressure.

Related coverage later showed LockBit using data publication against Boeing through a large claimed Boeing data leak, underscoring why availability of its leak sites is operationally important to the group.

First-order effects

  • LockBit loses access to its leak-site channel while the DDoS persists, interrupting its ability to publicly amplify the Entrust breach claim.
  • Entrust gets a temporary reprieve from leak-site pressure, but LockBit's accusation does not establish that Entrust caused the attack.

Second-order effects

  • The outage exposes a shared dependency for LockBit's ransomware-as-a-service operation: affiliates depend on centrally run publication infrastructure controlled by the operator.
  • Organizations facing LockBit extortion gain time when its sites are unavailable, although the group still retains any data it claims to have stolen.

Third-order effects

  • The incident points to ransomware leak sites themselves becoming operational targets, a pattern later reinforced by the defacement of LockBit affiliate panels.
  • If such disruptions recur, ransomware groups' centralized extortion infrastructure becomes a material weakness even when attacks are carried out through affiliates.

The trend: Ransomware-as-a-service groups are increasingly exposed by the centralized leak and affiliate infrastructure that converts stolen data into extortion leverage.

Discussion

  • @ashukuhi Azim Shukuhi on x
    someone is DDoSing the Lockbit blog hard right now. I asked LockBitSupp about it and they claim that they're getting 400 requests a second from over 1000 servers. As of this writing, the attack appears to be active. Lockbit promised more resources & to “drain the ddosers money” h…
  • @dinosn Nicolas Krassas on x
    LockBit ransomware blames Entrust for DDoS attacks on leak sites https://www.bleepingcomputer.com/ ...
  • @gossithedog Kevin Beaumont on x
    An amazing irony here is a lot of the ransomware groups have near no cybersecurity. https://twitter.com/...