Desk live·
ForensicPost
Ransomware/Primary source/File 25-0508

LockBit Affiliate Panel Breached, Defaced and Its Database Published

On 7 May 2025 LockBit’s affiliate panel was breached, defaced and its database published. It is the second attacker-internals leak of the year and it does not resemble the first.

Constructed geometry · not a chart of case data
TargetLockBit
ActorUnattributed
D. Kennedy13 min readConfidence: high4 sources reviewed

On 7 May 2025 LockBit’s Tor infrastructure was defaced by an actor signing themselves from Prague, and an archive containing an SQL dump of the group’s affiliate administration panel was published alongside the defacement.

The corpus filed the Black Basta chat archive at 25-0211 as the largest primary source on a ransomware operation it had been able to read about. Three months later there is a second, of a different kind: not conversation, but the operational database itself.

What Was In It

Analyses report roughly 62,400 unique bitcoin addresses, over 4,400 negotiation messages, affiliate accounts and build configurations, covering a window from mid-December 2024 to 29 April 2025. Sources differ on whether the window opens on 18 or 19 December; this desk does not resolve it.

The dump is reported to pertain mainly to a lower-tier affiliate programme rather than to the operation’s whole business. That qualification runs through every file in this cluster and is the reason none of them describes LockBit as a whole.

A Database Is A Different Kind Of Evidence From A Chat Log

The Black Basta archive is people talking. It has to be read, interpreted and weighed, and the published readings of it do not entirely agree — this desk recorded that disagreement at 25-0225.

A panel dump is records. It is closer to an accounting system than to a transcript, and the numbers in it were generated by the operation for its own use rather than asserted to anyone. That is why this file is graded high while several downstream ones are not.

The Authenticity Question Was Answered The Same Way

A research team reported validating the dump against its own knowledge of the panel and concluded with high confidence that it came from the genuine administration system. As at 25-0211, that is the strongest available test short of a prosecution.

And as at 25-0211, it is a test of provenance rather than of completeness. Nothing establishes that the dump is the whole database, or that nothing was removed before publication.

Who Did It Is Not Established

The defacement text is a signature, not an identification. Reporting has noted stylistic similarity to a defacement of another operation weeks earlier, which is a resemblance and is recorded here as one.

This corpus records tradecraft resemblance as an assessment and never as an identification, whether the subject is a state actor, an affiliate or whoever is doing this to ransomware panels.

How we reported this

Compiled from published analyses of the leaked panel database and contemporaneous reporting, listed below. This desk has not obtained or examined the dump and relies on others’ readings of it. Record counts vary between analyses and are given as reported. The dump is understood to cover a lower-tier affiliate programme rather than the operation in full. Corrections: corrections@forensicpost.com.

Sources
  1. LockBit hacked: what does the leaked data show?Help Net Security
  2. Inside LockBit’s admin panel leak: affiliates, victims and millions in cryptoTrellix
  3. LockBit ransomware admin panel hacked, leaks reveal inside detailsSecurityWeek
  4. LockBit leak provides insight into RaaS enterpriseTRM Labs
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary