Operation Cronos exposed that LockBit did not reliably delete stolen data after ransom payment, undermining the assumption that victims could buy data safety. The piece also shows how volatile outcomes, especially from groups like Icarus, Silent Ransom, and Dharma, are reshaping ransomware payments, tactics, and trust in extortion negotiations. #LockBit #OperationCronos #Icarus #SilentRansom #LunaMoth #Klue #Dharma
Keypoints
- LockBit kept victim data despite promises to delete it after payment.
- Operation Cronos proved ransom payments do not guarantee data removal.
- Icarus stole sensitive CRM data in a SaaS supply chain attack against Klue.
- Silent Ransom used vishing and physical infiltration to target law firms.
- Phishing, identity abuse, and exfiltration were major drivers of Q2 2026 extortion cases.
Read More: https://coveware.com/2026/07/adverse-cyber-extortions-are-more-common-than-commonly-advised/