×
Thursday, May 14, 2026

LockBit 2.0 gang claims Mandiant as latest victim; Mandiant sees no evidence of it - CyberScoop

A prominent ransomware group claimed Monday it has successfully attacked cybersecurity giant Mandiant, and will release company files.

LockBit 2.0 — a ransomware-as-a-service variant that can claim thousands of victims around the world since it was first spotted as ABCD ransomware in September 2019 — posted a notice to its dark web portal Monday claiming it would release Mandiant files late Monday. There is no ransom demand posted to the page.

A Mandiant spokesperson told CyberScoop Monday that the company was aware of the claims, but “at this point, we do not have any evidence to support their claims. We will continue to monitor the situation as it develops.”

Mandiant is a prominent figure in the multibillion-dollar-per-year cybersecurity industry. In March the company announced that Google would acquire Mandiant for roughly $5.4 billion deal, and become part of Google Cloud.

The LockBit 2.0 post Monday did not identify what files the group had purportedly taken. Brett Callow, a threat analyst with cybersecurity firm Emsisoft who follows the ransomware ecosystem closely, said the group has “made a number of false claims in the past.”

“In some cases, it appeared they’d obtained data relating to Company A from an attack on Company B, but claimed A as the victim,” Callow told CyberScoop. “It’s also entirely possible that LockBit’s claims have no substance to them whatsoever. In fact, this may be the most likely explanation.”

On June 2, Mandiant published an analysis...



Read Full Story: https://www.cyberscoop.com/lockbit-2-0-claims-mandiant-ransomware-victim/