Threat actor

LockBit

LockBit is a ransomware-as-a-service operation that has been active since late 2019 or early 2020. It is known for affiliate-based intrusions, data theft, double extortion, and rebranded variants, including LockBit 2.0, LockBit 3.0/Black, and subsequent activity claimed to be 5.0.

Incidents
12
High impact
1
First seen
Sep 10, 2021
Latest seen
Apr 9, 2026

Linked incidents

12 incidents
Ransomware

LockBit 5.0 Claims Responsibility for Attack on the Fund for Standardization and Quality Certification (FONDONORMA)

Screenshots of local evidence show a list of Lockbit 5.0 leak sites for fondonorma.org.It includes an upload timestamp of April 9, 2026, a deadline of April 24, 2026, and references to additional links containing alleged stolen data. Ransomware.live and DeXpose also indexed or reported a Lockbit 5.0 claim against Fondonorma in April 2026. No official confirmation or independently verified leaked data has been found, so the incident should be treated as a claim by a threat actor rather than a confirmed breach.

Fondo para la Normalización y Certificación de la Calidad (FONDONORMA)
Ransomware

LockBit 5.0 Claims Responsibility for Attack on Toncan Digital Corporation

In March 2026, Lockbit 5.0 allegedly launched a ransomware attack against Toncan Digital Corporation, a private organization operating in the industrial sector in Venezuela. The incident may have exposed confidential business data. It is unclear whether any data was leaked or whether there were any material losses resulting from the incident.

Corporacion Toncan Digital
Ransomware

LockBit 5.0 Claims Responsibility for Attack on TEALCA Transferencias y Encomiendas Angulo Lopez C.A.

In December 2025, the Lockbit 5.0 ransomware group claimed to have compromised TEALCA, a Venezuelan logistics company, and posted the data on its leak site with a deadline of January 14, 2026. It is unclear whether any data was leaked or whether there was any material loss resulting from the incident.

TEALCA Transferencias y Encomiendas Angulo Lopez C.A.
Ransomware

LockBit 5.0 Claims Responsibility for an Attack on Comercializadora Construtodo

In December 2025, the LockBit 5.0 ransomware group claimed responsibility for an attack on Comercializadora Construtodo, a Venezuelan building materials company. The threat actor listed the company on its data leak site with a deadline of January 15, 2026, although it is unclear whether any data was actually exfiltrated or leaked.

Comercializadora Construtodo
Ransomware

LockBit Claims Responsibility for Attack on Miranda Produce / Alimentos Serimar (Yolo)

In 2024, public trackers recorded a LockBit 3.0 claim associated with Miranda Produce / mirandaproduce.com.ve, and the business relationship with Alimentos Serimar (Yolo) warrants caution. The publicly available evidence supports a ransomware list for that related domain, but does not confirm any operational impact, the authenticity of the data, or specific details such as ID numbers or cards.

Alimentos Serimar, C.A. (Yolo)
Ransomware

LockBit 3.0 Claims Responsibility for Attack on Granja Alconca, C.A.

In August 2024, the Lockbit 3.0 ransomware group claimed responsibility for an attack on Granja Alconca, C.A., a Venezuelan animal feed producer. The threat actor listed the company on its dark web leak site on August 29, 2024, setting a deadline of September 12, 2024. Following the incident, the company’s website became inaccessible. It is unclear whether any data was ultimately leaked or what material impact the attack had on the organization’s operations.

Granja Alconca, C.A
Ransomware

LockBit 3.0 Claims Responsibility for Attack on Banco de Venezuela, S.A.

In April 2023, Banco de Venezuela, S.A. was the target of a ransomware attack attributed to the Lockbit 3.0 group. The threat actors added the bank to their dark web leak site on April 19, 2023, threatening to publish stolen confidential information—including Venezuelan ID cards, tax documents (RIF), INCES certificates, and corporate financial records— by May 10, 2023, unless a ransom in cryptocurrency was paid. In response to the incident, the bank issued a statement assuring its customers that its platforms and electronic channels were operating normally with full integrity and security, although it neither explicitly confirmed nor denied the data exfiltration.

Banco de Venezuela, S.A.
Ransomware

LockBit 3.0 claims responsibility for an attack on 100%Banco (100x100 Bank)

In January 2023, the Lockbit 3.0 ransomware group claimed responsibility for an attack on 100%Banco, a Venezuelan commercial bank. The threat actors posted the bank on their leak site on January 7, 2023, setting a publication deadline of January 19, 2023. It is still unclear whether any data was actually leaked or whether the bank suffered any financial losses.

100%Banco (100x100 banco)
Ransomware

LockBit 3.0 Claims Responsibility for Attack on Amazing Global

In December 2022, Amazing Global, a private IT organization based in Venezuela, was listed by LockBit as an alleged ransomware victim. The Breachsense public registry dates the discovery to December 12, 2022; Ransomware.live maintains a later entry associated with Dispossessor as a repost/duplicate. There is no official confirmation from the company or public validation of the volume, data categories, or operational impact.

Amazing Global
Ransomware

LockBit 3.0 Claims Responsibility for Attack on Grupo MAKLER

In September 2022, makler.com.ve / Grupo MAKLER was listed by LockBit as an alleged victim of ransomware. Ransomware.live and Breachsense have preserved the metadata from the claim between September 14 and 15, 2022. There is no official confirmation from the company or public validation of the volume, data categories, or operational impact.

Grupo MAKLER
Ransomware

LockBit Claims Responsibility for Attack on Destilerías Unidas, S.A.

In October 2021, Destilerias Unidas, S.A. (DUSA), a major Venezuelan spirits producer, was the target of a ransomware attack. Although the incident was initially attributed to the LockBit 2.0 group with a disclosure date of October 8, 2021, forensic evidence from screenshots of the data leak site indicates the presence of files dated 2022 on the LockBit 3.0 infrastructure. The attack involved the possible encryption and exfiltration of corporate data, although the specific volume of leaked information and the total material impact on the company’s operations remain unconfirmed by official sources.

Destilerías Unidas, S.A.
Ransomware

LockBit Claims Responsibility for Attack on Cencozotti S.A.

In August/September 2021, public trackers recorded a LockBit 2.0 ransom note targeting cenco-zotti.com / Cencozotti S.A. The details regarding 44.7 GiB and the RT35V.zip file have been removed as verifiable facts because they relied on non-public onion URLs or unrecoverable sources. There is no official confirmation of a data exfiltration or material impact.

Cencozotti S.A.