Skip to content
Flash Briefing high HealthcareLegal & ProfessionalGovernment

LockBit Resurgence: Affiliate Network Active Across UK Healthcare and Professional Services

Operation Cronos was February 2024. Infrastructure seized, decryption keys published, affiliates arrested, administrator indicted. Within weeks, LockBit was back.

That’s not a failure of the law enforcement operation; it’s an accurate demonstration of how RaaS economics work. The administrator, Dmitry Khoroshev, remains in Russia and outside extradition reach. The affiliates are distributed globally and individually replaceable. The encryptor code, once leaked, can be rebuilt and redeployed. Law enforcement achieved something significant. It did not solve the problem.

LockBit 3.0 (LockBit Black) remains active across UK sectors. Confirmed victims over the past six months include NHS-adjacent healthcare providers, mid-market law firms, local government bodies, and manufacturing firms. This is affiliate activity, not a coordinated campaign. Different actors, different initial access techniques, different negotiation approaches. What they share is the encryptor and the leak site infrastructure.

How Affiliates Are Getting In

Three initial access patterns are appearing consistently in UK-linked incidents:

VPN credential compromise remains the most common. Credential stuffing and brute force against unpatched SSL-VPN devices, specifically Fortinet and Citrix devices with known CVEs that haven’t been patched. Not novel. Not sophisticated. Works because organisations are behind on their patch cycle, which is most organisations.

Phishing delivering Phorpiex loader, followed by LockBit deployment. The loader chain is straightforward and affiliates aren’t varying it much because it keeps succeeding.

Exposed RDP instances. Particularly prevalent in healthcare and local government, where legacy infrastructure means Windows Server versions that should have been decommissioned years ago are still internet-facing. Default or weak credentials. No MFA.

The double extortion model is standard: data exfiltration before encryption. Victims refusing to pay face both operational disruption and data release on the LockBit leak site. In healthcare and legal contexts, the data release dimension often creates more pressure than the encryption itself.

Why Healthcare Keeps Getting Hit

The leverage calculus in healthcare is exceptionally high. Patient care cannot pause for a multi-week IT recovery. Clinical systems generate and hold sensitive personal data at volume. And NHS-adjacent organisations (independent providers, dental networks, care home chains) have historically operated with security investment far below NHS core bodies.

The 2024 NHS Synnovis attack, a different group but the same operational dynamic, demonstrated that healthcare ransomware disrupts patient care at scale, creates immediate public and regulatory pressure, and generates the kind of coverage that makes paying look necessary. LockBit affiliates read the news. They draw conclusions.

NHS Trusts themselves have improved materially following sustained NCSC engagement. The targeting has partially shifted to the NHS-adjacent ecosystem, where security maturity is lower and the leverage argument is the same.

What LockBit Surviving Cronos Means for Defenders

The lesson from Operation Cronos is not that law enforcement doesn’t work. It’s that LockBit is not a problem that gets solved once. It requires persistent defensive posture, which most organisations find harder to sustain than a one-time response to a crisis.

Three controls account for a disproportionate share of LockBit initial access prevention:

Patch internet-facing VPN and RDP infrastructure. These are known vulnerabilities with published CVEs. They succeed because patching is incomplete and overloaded IT teams deprioritise devices that are “still working.” Run an external scan and find out what you’re actually exposing.

MFA on all remote access, without exceptions. Credential stuffing against VPN endpoints requires the absence of MFA. It’s a basic control. It eliminates the primary initial access path. Healthcare organisations still running legacy VPN without MFA in 2026 are materially exposed.

Test your backups before you need them. Many organisations discover during an incident that their backups are encrypted alongside production data, out of date, or restorable only over a timescale that makes paying rational. Discovering this during recovery is too late. Run a recovery test, specifically a LockBit scenario where backups are deleted before encryption, and find out now what your actual RTO looks like.