Lockbits SpA A.I CyberSecurity Scoring
Lockbits SpA
Company Information
Website:http://www.lockbits.cl
Employees number:4
Number of followers:886
NAICS:541514
Industry Type:Computer and Network Security
Homepage:lockbits.cl
Lockbits SpA Risk Score (AI oriented)
Between 0 and 549
Lockbits SpAComputer and Network Security
Updated:
09/07/2026
09/07/2026
543/1000
Critical
C
Lockbits SpA Global Score (TPRM)
xxxx
Lockbits SpAComputer and Network Security
Score locked

Lockbits SpACritical
Current Score
543C (CRITICAL)
01000
2 incidents
-149 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
543
JUNE 2026
539
MAY 2026
534
APRIL 2026
674
Ransomware
01 Apr 2026 • Lockbits SpA
LockBit and FulcrumSec: Ransomware ecosystem grows, but ‘four-headed monster’ dominates
Ransomware Surge in Q2 2026: U.S. and Germany Top Targets as AI Amplifies Threat Actor Tactics
525
CRITICAL-149
LOCCYB1783614618
Ransomware Surge in Q2 2026: U.S. and Germany Top Targets as AI Amplifies Threat Actor Tactics
The U.S. remained the most targeted country for ransomware attacks in Q2 2026, accounting for 40% of global victims though its share declined from previous quarters, when nearly half of all incidents involved American organizations. Germany followed closely at 32%, reflecting a shift in focus by prominent ransomware groups, including The Gentlemen, Qilin, and LockBit, which increasingly targeted victims outside the U.S.
A key trend in the quarter was the growing use of AI by cybercriminals, not to launch novel attacks but to streamline existing tactics. The FulcrumSec group leveraged large language models (LLMs) to analyze stolen data, identifying overlaps across databases a task that would have required deep technical expertise or extensive manual effort. AI-generated negotiation messages further strengthened the group’s leverage, allowing them to justify ransom demands with precision. Similarly, DragonForce used LLMs to craft convincing (though likely false) claims of having legal counsel, exploiting victims’ fears of reputational and regulatory risks.
Despite the proliferation of ransomware groups with more active in Q2 2026 than any prior quarter the threat landscape remains dominated by a handful of high-volume actors. The "four-headed monster" Qilin, The Gentlemen, Akira, and DragonForce collectively accounted for over 40% of all recorded attacks, underscoring the outsized impact of a few prolific gangs. Qilin alone was responsible for 13% of incidents.
Overall, ransomware activity rose 7% quarter-over-quarter and 43% year-over-year, with 2,279 victims reported in Q2 2026. While AI has yet to enable the "catastrophic" attacks some feared, its role as a productivity multiplier for cybercriminals is clear, reducing the effort required for tasks like data analysis and social engineering. The ransomware ecosystem’s resilience was also highlighted, with multiple groups positioned to absorb affiliates if law enforcement disrupts a major player.
INCIDENT DETAILS -
TYPE
MOTIVATION
REFERENCES
MARCH 2026
674
FEBRUARY 2026
673
JANUARY 2026
671
DECEMBER 2025
670
NOVEMBER 2025
668
OCTOBER 2025
667
SEPTEMBER 2025
665
AUGUST 2025
663
JUNE 2024
748
Ransomware
16 Jun 2024 • Lockbits SpA
Qilin, Akira, LockBit, DragonForce and Safepay: Ransomware activity never dies, it multiplies
Ransomware Attacks Hit Record Highs in 2025 Despite Major Disruptions
635
CRITICAL-113
QILAKILOCDRASAF1768585619
Ransomware Attacks Hit Record Highs in 2025 Despite Major Disruptions
A new study by Symantec and the Carbon Black Threat Hunter Team reveals that ransomware attacks surged to unprecedented levels in 2025, with threat actors adapting rapidly to law enforcement crackdowns and evolving their extortion tactics.
The report documented 4,737 claimed ransomware attacks the highest annual total on record despite the collapse of two major operations. RansomHub, the most active group at the time, abruptly shut down in April 2025, causing a brief dip in activity. However, former affiliates quickly migrated to other groups, restoring attack volumes within weeks. LockBit (tracked as Syrphid) also failed to recover after late-2024 law enforcement actions.
New leaders emerged to fill the void. Akira and Qilin each accounted for 16% of attacks, while Inc, Safepay, and the newly identified DragonForce contributed smaller but significant shares. The fluid movement of affiliates, access brokers, and tooling between groups sustained overall activity levels.
Beyond traditional encryption-based ransomware, extortion campaigns without encryption surged in 2025. These attacks focused on data theft and public leaks pushed total extortion incidents to 6,182, a 23% increase from 2024. Snakefly’s Cl0p operation played a key role, exploiting vulnerabilities in enterprise software to target government and industrial sectors at scale.
Social engineering also became a dominant attack vector, with groups like ShinyHunters and Scattered Spider using phone-based impersonation, credential harvesting, and OAuth abuse to breach cloud environments. Attackers tricked employees into authorizing malicious apps or sharing authentication codes, reducing reliance on malware.
A new ransomware strain, Warlock, drew attention for its ties to older espionage tooling. Exploiting a zero-day in Microsoft SharePoint and using DLL sideloading, Warlock incorporated components linked to Chinese state-sponsored activity, blending ransomware with broader intrusion campaigns.
Despite these shifts, attack chains remained consistent. Threat actors relied on "living off the land" techniques, leveraging PowerShell, remote management tools, and credential dumping to evade detection. Malware often appeared late in the intrusion, just before encryption or data theft.
The findings underscore how ransomware operations continue to thrive, even as law enforcement disrupts key players, by diversifying extortion methods and exploiting shared infrastructure.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Lockbits SpA ??
What was Lockbits SpA's A.I Rankiteo Cyber Score in June 2026 ??
What was Lockbits SpA's A.I Rankiteo Cyber Score in May 2026 ??
What was Lockbits SpA's A.I Rankiteo Cyber Score in April 2026 ??
What was Lockbits SpA's A.I Rankiteo Cyber Score in March 2026 ??
What was Lockbits SpA's A.I Rankiteo Cyber Score in February 2026 ??
What was Lockbits SpA's A.I Rankiteo Cyber Score in January 2026 ??
What was Lockbits SpA's A.I Rankiteo Cyber Score in December 2025 ??
What was Lockbits SpA's A.I Rankiteo Cyber Score in November 2025 ??
What was Lockbits SpA's A.I Rankiteo Cyber Score in October 2025 ??
What was Lockbits SpA's A.I Rankiteo Cyber Score in September 2025 ??
What was Lockbits SpA's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on Lockbits SpA's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Lockbits SpA ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Lockbits SpA's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?