On 7 May 2025 LockBit’s Tor infrastructure was defaced by an actor signing themselves from Prague, and an archive containing an SQL dump of the group’s affiliate administration panel was published alongside the defacement.
The corpus filed the Black Basta chat archive at 25-0211 as the largest primary source on a ransomware operation it had been able to read about. Three months later there is a second, of a different kind: not conversation, but the operational database itself.
What Was In It
Analyses report roughly 62,400 unique bitcoin addresses, over 4,400 negotiation messages, affiliate accounts and build configurations, covering a window from mid-December 2024 to 29 April 2025. Sources differ on whether the window opens on 18 or 19 December; this desk does not resolve it.
The dump is reported to pertain mainly to a lower-tier affiliate programme rather than to the operation’s whole business. That qualification runs through every file in this cluster and is the reason none of them describes LockBit as a whole.
A Database Is A Different Kind Of Evidence From A Chat Log
The Black Basta archive is people talking. It has to be read, interpreted and weighed, and the published readings of it do not entirely agree — this desk recorded that disagreement at 25-0225.
A panel dump is records. It is closer to an accounting system than to a transcript, and the numbers in it were generated by the operation for its own use rather than asserted to anyone. That is why this file is graded high while several downstream ones are not.
The Authenticity Question Was Answered The Same Way
A research team reported validating the dump against its own knowledge of the panel and concluded with high confidence that it came from the genuine administration system. As at 25-0211, that is the strongest available test short of a prosecution.
And as at 25-0211, it is a test of provenance rather than of completeness. Nothing establishes that the dump is the whole database, or that nothing was removed before publication.
Who Did It Is Not Established
The defacement text is a signature, not an identification. Reporting has noted stylistic similarity to a defacement of another operation weeks earlier, which is a resemblance and is recorded here as one.
This corpus records tradecraft resemblance as an assessment and never as an identification, whether the subject is a state actor, an affiliate or whoever is doing this to ransomware panels.
Compiled from published analyses of the leaked panel database and contemporaneous reporting, listed below. This desk has not obtained or examined the dump and relies on others’ readings of it. Record counts vary between analyses and are given as reported. The dump is understood to cover a lower-tier affiliate programme rather than the operation in full. Corrections: corrections@forensicpost.com.