Desk live·
ForensicPost
Ransomware/Aftermath/File 22-1218

LockBit Apologised to SickKids and Handed Back a Free Decryptor

LockBit said the affiliate who encrypted a children’s hospital had broken its rules, expelled them, and provided a free decryption tool. The rule permits pharmaceutical companies and dentists. It draws the line where death becomes plausible.

Constructed geometry · not a chart of case data
JurisdictionCanadaTorontothe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetHospital for Sick Children
ActorLockBit
S. Rosler11 min readConfidence: high3 sources reviewed

On 18 December 2022 the Hospital for Sick Children in Toronto was hit by ransomware, affecting internal systems, phone lines and its website. At the end of December the LockBit operation published an apology, stating that the affiliate responsible had violated its rules, had been blocked and removed from the affiliate programme, and that a decryptor was being provided free of charge.

The operation’s stated rule permitted affiliates to encrypt pharmaceutical companies, dentists and plastic surgeons, while prohibiting attacks on medical institutions where the consequence could be death. SickKids said it was assessing the decryptor with external experts and had made no payment.

Read It As Risk Management, Not Remorse

The temptation is to file this as a criminal enterprise showing a limit. The desk reads it differently, and the rule itself is the evidence: pharmaceutical companies and dental practices are permitted, and the boundary falls precisely where a death could be attributed.

That is not a line drawn around suffering. It is a line drawn around the attention a death attracts — the point at which a financially motivated operation acquires the kind of law-enforcement priority we have recorded at 23-0404 and 26-0725. The apology is a public statement to affiliates and to police about what the operation will not be blamed for.

The Affiliate Model Makes This Necessary

Ransomware-as-a-service separates the people who write the tooling from the people who use it. The operator sets rules and takes a share; the affiliate picks the target.

So the operator carries reputational and legal exposure for choices it does not make, and expelling an affiliate is the only enforcement available. We have recorded the same structural distance at 26-0705 and across the Cl0p and LockBit files — and it is why "the group attacked X" is frequently the wrong sentence.

A Free Decryptor Is Not A Remedy

The hospital still had to validate an attacker-supplied tool before running it on clinical systems, which is work, and cannot be done quickly or trustingly.

It also does nothing about data already taken, and it does not return the days of degraded operation we have recorded as the actual harm at 22-1002 and 22-1104. SickKids paid nothing, which matters. What it got back was a key, not the fortnight.

How we reported this

Compiled from contemporaneous reporting and the hospital’s public statements, listed below. The operation’s stated rules are quoted from reporting of its own statements; this desk records what was claimed, not that the rules were consistently applied. The reading of the apology as risk management is this desk’s analysis and is presented as such. Graded high on the events. Corrections: corrections@forensicpost.com.

Sources
  1. Ransomware gang apologizes, gives SickKids hospital free decryptorBleepingComputer
  2. Ransomware group LockBit apologizes saying "partner" was behind SickKids attackCBC News
  3. LockBit ransomware gang says sorry, gives free decryptor to SickKids hospitalTripwire
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary