Dmitry Khoroshev, LockBit Leader: 2026 Status and Reward

- Dmitry Khoroshev and LockBit in 2026: the short answer
- Timeline: from the LockBit takedown to LockBit 5.0
- What changed since 2024
- Risks and scams around the LockBit name (our analysis)
- What to do if LockBit or a copycat hits you
- What is still unknown
- Our original 2024 report
- Lockbit underground site was taken down in February
- Attempts to resurface
- If caught, Khoroshev could face up to 185 years in jail
- Related guides on 2-Spyware
Dmitry Khoroshev and LockBit in 2026: the short answer
Dmitry Yuryevich Khoroshev is still wanted. The U.S. indictment, the sanctions and the State Department reward of up to $10 million announced on May 7, 2024 are the latest official actions we found against him.[6][7][9] We found no report of his arrest or extradition as of 2026.
Prosecutors say Khoroshev, known online as LockBitSupp, ran LockBit from about September 2019 to May 2024. They say he alone received at least $100 million in bitcoin through his 20% developer share of ransom payments.[6] LockBit itself did not disappear after the takedown, but it never got back to its old scale, as the timeline below shows.
| Question | Answer |
|---|---|
| Who is he | Dmitry Yuryevich Khoroshev, 31 at the time of the charges, of Voronezh, Russia[6] |
| Online aliases | LockBitSupp, LockBit and putinkrab[6] |
| Charges | A 26-count indictment from a grand jury in the District of New Jersey[6] |
| Money he allegedly kept | At least $100 million in digital currency disbursements[6] |
| Reward | Up to $10 million from the U.S. State Department for information leading to his arrest or conviction[7] |
| Status in 2026 | Not in custody, as far as we found; sanctions by the US, UK and Australia remain[5][7] |
Timeline: from the LockBit takedown to LockBit 5.0

| Date | Event |
|---|---|
| September 2019 | Khoroshev allegedly starts acting as LockBit developer and administrator[6] |
| February 2024 | U.K. and U.S. authorities disrupt LockBit and seize its sites[3][6] |
| May 7, 2024 | Indictment unsealed, sanctions imposed, reward of up to $10 million announced[6][7][9] |
| March 2025 | Russian-Israeli developer Rostislav Panev is extradited to the United States[8] |
| May 2025 | LockBit infrastructure is breached and its data leaked[9] |
| September 2025 | LockBit 5.0 is released[9] |
What changed since 2024
The case against Khoroshev himself has not moved in public. What moved is the case around him. The Justice Department said six LockBit members had been charged by the time his indictment was unsealed, and two of them were in custody awaiting trial.[6] In March 2025 developer Rostislav Panev was extradited from Israel to the United States.[8]
The group also took a hit from the criminal side. In May 2025 its infrastructure was breached and defaced. The leaked data exposed bitcoin wallet addresses, chats with victims, affiliate details and other internal information.[9] Even so, LockBit kept going and released LockBit 5.0 in September 2025.[9] So the brand survives, though the 2024 indictment says the takedown greatly damaged its reputation.[6]
One fact from the indictment matters for victims. Seized servers showed that Khoroshev kept copies of data stolen from victims who had paid, even though they had been promised deletion.[6] Paying LockBit never guaranteed that the stolen files were gone.
Risks and scams around the LockBit name (our analysis)
This section is our own analysis of how criminals reuse a famous case. It is not taken from an official advisory.
- Fake reward claims. Messages that promise a share of the $10 million reward in exchange for a fee or your ID documents. The official program does not ask for payment.
- Fake decryptors. Downloads that claim to restore LockBit files for free. Many carry other malware. Use only tools linked from official law enforcement pages.
- Copycat extortion. Emails that claim to be from LockBit and demand money without any real breach. Check your logs before you react.
- Old leak data reused. Data from earlier LockBit victims can be reused in phishing that quotes real details. Treat unexpected messages with care.
What to do if LockBit or a copycat hits you

1. Isolate systems. Disconnect affected computers and servers from the network so the encryption cannot spread further.
2. Keep evidence. Save the ransom note, logs and a few encrypted files. Investigators need them, and they help match the attack to a known variant.
3. Report it. Contact the police and your national cyber agency. Europol said its centre shared thousands of intelligence packages about LockBit victims with dozens of countries.[4]
4. Check decryptors. Law enforcement collected thousands of LockBit decryption keys after the takedown.[4] Ask the authorities whether a key exists for your case before you consider anything else.
5. Restore safely. Rebuild from clean backups kept offline. Do not restore onto a machine that may still hold the intruder's tools.
6. Reset access. Change passwords, revoke old sessions and review remote access tools. Check whether staff email addresses appear in leaks with our leak check.
What is still unknown
- Where Khoroshev lives now. Officials named Voronezh, Russia in 2024, and we found no newer official statement.[6]
- Whether anyone has claimed or received any part of the reward. We found no public statement on that.
- Who runs LockBit 5.0 day to day, and whether Khoroshev is still involved. The sources we read do not say.
We will update this page if a court, a government or a law enforcement agency announces a new step in the case.
Our original 2024 report
The text below is our report as first published in 2024. We keep it unchanged for the record; the sections above bring it up to date.
The person responsible for the operation of the LockBit ransomware campaign has been revealed to be 31-year-old Russian national Dmitry Yuryevich Khoroshev. This revelation came through coordinated efforts by law enforcement agencies including the UK's National Crime Agency, the U.S. Department of Justice, and the Australian government.
As a consequence, Khoroshev is now subjected to international sanctions that include asset freezes and travel bans, particularly by the US, UK, and Australia. In the media release, Australia's Minister for Foreign Affairs Hon Penny Wong said:[1]
The new sanction under the cyber sanctions framework makes it a criminal offence to provide assets to Dmitry Yuryevich Khoroshev, or to use or deal with his assets. The framework is intended to disrupt and deter the perpetrators of malicious cyber activity, such as ransomware.
Khoroshev, also known by his online alias LockBitSupp, was determined to have personally benefited from ransomware attacks that accrued over $100 million in Bitcoin payments.
Lockbit underground site was taken down in February
LockBit operates by encrypting the data of its victims and demanding ransom for the decryption keys, primarily in cryptocurrency, making the transactions difficult to trace. The ransomware has targeted large-scale organizations worldwide, including more than 100 hospitals, schools, and major companies, causing extensive financial and operational damage.[2]
In a significant countermove earlier this year in February,[3] international law enforcement agencies seized LockBit's website, used it to unmask Khoroshev, and continued to operate it to disrupt ongoing ransomware activities. This action followed a pattern where authorities initially replaced hacker communications with official law enforcement messages to undermine the gang's operations. Britain's NCA and U.S. FBI have arrested several members of the gang at the time.
As of the latest efforts, Europol and other agencies have managed to gather over 2,500 decryption keys, offering relief to some victims previously targeted by cybercriminals. According to Europol, the recovery effort is significant:[4]
Europol has been exploiting the vast amount of data gathered during the investigation and the first phase of action to identify these victims, who are located all over the world. Its European Cybercrime Centre (EC3) has disseminated some 3 500 intelligence packages containing information about Lockbit victims to 33 countries.
Attempts to resurface
Up to February 2024, the gang launched over 7,000 attacks using their services, according to recent evidence that highlights the scope and severity of the LockBit ransomware attacks, which predominantly targeted five key countries: the U.S., the U.K., France, Germany, and China.[5] This wide regional distribution draws attention to both the sophisticated network that powers these operations and the enormous disruption that LockBit has created.
Following significant legal and law enforcement actions, LockBit's attempts to rebuild and maintain its operations have been largely unsuccessful. They've attempted to create a semblance of ongoing activity by launching a new leak site and posting outdated and fictitious victim data to exaggerate their operational capacity.
However, these efforts have not restored their previous capabilities, and the overall threat from LockBit has significantly diminished. This downturn is further evidenced by the reduced number of active affiliates, which has dropped from 194 to just 69, and many of these affiliates have failed to successfully negotiate ransoms, indicating a decline in their operational effectiveness.
If caught, Khoroshev could face up to 185 years in jail
After being identified, Dmitry Khoroshev is charged with several offenses, including conspiracy to commit fraud and deliberate damage to protected computers, according to a 26-count U.S. indictment. The charges could result in up to 185 years in jail, emphasizing the serious consequences associated with high-level cybercrimes.
On Tuesday, international law enforcement agencies took a strategic turn by leveraging the gang's own platform to expose Dmitry Khoroshev. They published a wanted poster on the site, announcing a $10 million reward for any information that could directly contribute to Khoroshev's capture.
Related guides on 2-Spyware
Frequently asked questions
Who is Dmitry Yuryevich Khoroshev?
He is the Russian national that U.S., UK and Australian authorities named in May 2024 as the developer and administrator of LockBit ransomware.{6}{7} The Justice Department described him as 31, from Voronezh, and known online as LockBitSupp, LockBit and putinkrab. Prosecutors say he ran the group from around September 2019.{6}
Where is Dmitry Khoroshev now?
We found no public report that he has been arrested as of 2026. The 2024 charging documents list Voronezh, Russia as his home.{6} The U.S., UK and Australian sanctions and travel bans against him remain, and the State Department reward is still the official appeal for information.{5}{7}
How much money did Khoroshev make from LockBit?
Prosecutors say Khoroshev alone received at least about $100 million in bitcoin disbursements.{6} That came from his developer share, typically 20% of each ransom. The indictment says Khoroshev and his affiliates extracted at least $500 million in ransom payments in total, and caused billions of dollars in wider losses.{6}
What are the 26 counts in the Khoroshev indictment?
The indictment lists one count of conspiracy to commit fraud, extortion and related computer activity, and one count of conspiracy to commit wire fraud.{6} It adds eight counts of intentional damage to a protected computer and sixteen counts of extortion tied to protected computers. The original report below notes a possible sentence of up to 185 years.
How big is the reward for information on the LockBit leader?
The U.S. State Department offers up to $10 million for information leading to Khoroshev's arrest or conviction.{7} The offer was announced on the same day as the indictment and the sanctions, in May 2024.{6} We found no report that the reward has been paid.
Is LockBit still active in 2026?
Yes, in a weaker form. LockBit tried a comeback after the February 2024 takedown, suffered a breach and data leak of its own infrastructure in May 2025, and released LockBit 5.0 in September 2025.{9} Organisations should still treat it as an active ransomware threat.
Log in to comment
No comments yet. Be the first.