you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 11 min ago 255 onions tracked
home / news / market watch
02 September 2026 market watch 5 min read

LockBit 5.0 lists Actua: dispersed leaks and the end of easy takedowns

LockBit has spent years as ransomware's most recognizable brand, surviving a coordinated international takedown in 2024 and rebuilding under version numbering that now reads 5.0. Its latest listing shows how little the extortion playbook has slowed down. According to findings reported by ZATAZ, the crew claims a breach of Actua, a French staffing and temporary-work group, and says it will begin releasing stolen files in early September.

The threatened haul is specific enough to sting. LockBit's darkweb entry describes a set of documents including passports, diplomas, CVs and insurance attestations concerning more than 100,000 recruited persons. Actua is no boutique target: the group runs 37 agencies, works with over 1,800 partner companies and places roughly 3,000 temporary workers every month. A staffing firm is, by design, a warehouse of exactly the identity paperwork ransomware crews love to wave around.

The claim versus what anyone can verify

Here is where caution earns its keep. ZATAZ notes that nothing LockBit has published so far allows independent verification of either the volume or the intrusion vector. The figure of 100,000 people comes straight from the attackers, and it does not follow that every named person appears in every document category. The claim says nothing about how intruders got in, when they first gained access, or how long they lingered. It remains entirely possible, as ZATAZ observes, that the criminals touched nothing more than a single computer in one regional office. That gap between headline number and provable reality is not a quirk of this case. Leak-site listings are marketing documents. Victim counts inflate, document categories blur together, and the most alarming phrasing wins attention whether or not the underlying archive matches. History offers plenty of examples where claimed megabytes shrank dramatically once dumps actually landed. Until files surface and someone counts them, the honest description of the Actua claim is: unverified, plausible in shape, unproven in scale. Actua, for its part, did not respond to comment requests. Silence is common in the early days of a listing, especially while French data-protection obligations around breach notification are being sorted out. But it leaves candidates and temporary workers in an uncomfortable position: the threat is public, the evidence is not, and September is close.

Ten storage locations at once

The genuinely new element is tactical. Rather than promising a single dump URL, LockBit 5.0 announces its intention to distribute the leak across ten different storage locations simultaneously. ZATAZ reads this correctly as a strategy of dispersion: multiplying points of availability so that removing any one of them accomplishes little, and so that rapid takedown becomes a whack-a-mole exercise across jurisdictions and providers. The context makes the move legible. In February 2024, Operation Cronos seized LockBit infrastructure across dozens of servers, replaced leak-site pages with law-enforcement banners and generally humiliated the brand (KrebsOnSecurity). The operation worked because LockBit concentrated its publishing on infrastructure that could be located and taken. Dispersed leaks are a direct answer to that lesson: if the payload lives in ten places before anyone knows where they are, seizing one changes almost nothing.

What dispersion means for tracking

For anyone who follows leak-site availability, this matters more than the victim count. The old model assumed a chokepoint: take down the extortion blog or its CDN, and the pressure campaign stalls. Dispersion removes the chokepoint. Uptime of a single endpoint stops being a meaningful signal, because the campaign survives partial outages by design. Monitoring has to widen from one onion address to a shifting set of mirrors, buckets and paste-style hosts, some of which may not be onion services at all. This mirrors a pattern long familiar from darknet market history, where official-link lists and redundant mirrors became survival equipment after repeated seizures. We covered the mechanics of that arms race in our piece on why mirrors show offline, and the same dynamics apply here: redundancy defeats single-point removal, but it also multiplies the surfaces where stale links, impostor copies and dead endpoints accumulate. A dispersed leak guarantees that some of the ten locations will be fake, broken or booby-trapped within days.

Reading the next few weeks

The practical takeaway splits three ways:
  • For tracked individuals, the sensible posture is precaution without panic: treat the 100,000 figure as unconfirmed, watch for the actual publication, and assume phishing waves will exploit the headlines regardless of whether real documents ever appear.
  • For defenders, the lesson is that early September is a deadline set by the attacker, and deadlines slip constantly in this genre; countdowns exist to create urgency, not accuracy.
  • For analysts and monitors, ten simultaneous drop points means availability tracking must become distribution-aware, scoring campaigns by how many live locations remain rather than whether one site resolves.
Leak sites have been evolving away from centralization since the first Maze-era dumps proved that public shaming pays (BleepingComputer). LockBit 5.0's ten-location plan is the logical next step: publish everywhere, verify nothing, dare the takedown teams to chase all of it. Whether the Actua files materialize at anything like claimed scale, the dispersal tactic itself is now on the menu, and it will outlast this particular listing.

more notes

all news ›