Cybercrime

LockBit Ransomware – Data leak published with information about victims

Risks and Measures for Affected Parties / Victims of LockBit

In May 2025, the ransomware group LockBit itself fell victim to an attack: unknown actors compromised the group's infrastructure and published a comprehensive database of sensitive information. This contained, among other things, nearly 60,000 Bitcoin wallet addresses, internal chat logs with victims, details on ransomware builds and configurations, as well as affiliate access credentials.

 

Lockbit Ransomware Data Leak

Table of Contents

Impact on affected companies

Companies whose data was stolen by LockBit and is now publicly accessible face significant risks:

  • Increased risk of attack: Cybercriminals could use the published information to carry out targeted phishing attacks. By knowing internal communication channels and sensitive corporate data, deception attacks can be precisely designed. In addition, further extortion could take place by perpetrators threatening those affected with a second publication. 

  • Reputational damage: The disclosure of business relationships with LockBit or payments made can massively damage public trust. Companies that rely on customer data in particular, such as financial service providers or healthcare companies, risk a significant loss of trust. Even mere mention in connection with criminal activities can result in long-term reputational damage.

  • Legal consequences: Data breaches can result in significant fines under the GDPR. The failure to report an incident to the data protection authority is particularly critical and may additionally be subject to criminal penalties. Companies also face the challenge of proving that their internal security measures met the state of the art. 

Recommended measures

Affected companies should immediately consider the following steps:

  • Data Leak Check: Companies should immediately check whether and what data is included in the leak. The support of IT forensic experts can be useful in this process. We have access to the leaked data and you can assist with the review.

  • Communication: Transparent information sharing with customers, partners, and regulatory authorities regarding the incident and the measures taken is crucial. Communication should be proactive and factual to avoid further speculation.

  • Legal advice Specialized attorneys in the field of cybercrime can help review legal obligations and avoid potential fines.

  • Documentation: If you should have paid ransom to LockBit or have not informed the data protection authority about the incident, ensure that the basis for this decision is well documented. According to the GDPR, you are obligated to document security incidents. Documentation is particularly important if criminally relevant ransom payments were justified by the defense of necessity.

  • Prevention: Implementation of improved security protocols and regular employee training to raise awareness of cyber threats.
  1.  

For more information on similar incidents, please see our Blog post about the Everest ransomware group.

The law firm ATB.LAW offers companies comprehensive support in the area of ransomware and other cyber attacks. We have a dense network of selected IT specialists. Contact lawyer Roman Taudes under taudes@atb.law or by phone at +43 1 3912345.

More articles

ATB.LAW Cybercrime Lawyer

Cybercrime in Austria

Legal situation, figures, and action steps
Picture of Roman Taudes
Roman Taudes
Business Email Compromise (BEC)

Business E-Mail Compromise

Who is liable – and when does a GDPR reporting obligation apply?
Picture of Roman Taudes
Roman Taudes
Cyberattack reporting obligations NIS GDPR MAR

Reporting obligations in the event of cyber attacks

What the TeamViewer case means for Austrian companies
Picture of Roman Taudes
Roman Taudes