ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

LockBit threatens to leak CDW's data after ransom negotiations break down

In a concerning turn of events, the notorious cybercrime gang LockBit has threatened to leak the data of CDW, one of the world’s largest resellers, after negotiations over a ransom fee reached an impasse.

 

This revelation comes from a spokesperson for the cybercriminal gang who goes by the alias LockBitSupp. In an interview, LockBitSupp suggested that the breakdown in negotiations was due to CDW offering a sum that the group deemed insultingly low.

 

LockBitSupp did not divulge the original ransom demand made by LockBit or specify the amount CDW offered during the negotiations. Furthermore, they declined to provide information about the nature of the stolen data and the methods used to breach CDW’s security.

 

According to a countdown timer on LockBit’s victim blog, CDW’s files are scheduled to be published in the early hours of October 11. This incident appears to have been ongoing since at least September 3, when CDW was first posted on LockBit’s blog.

 

CDW has not yet stated the incident. The UK Information Commissioner’s Office (ICO) confirmed that it had not received a breach report from CDW.

 

Cybersecurity analyst and researcher Dominic Alvieri noted that CDW was technically posted on LockBit’s victim blog three times. Initially, it was "flashed," a tactic aimed at eliciting a swift response from the victim by quickly posting and deleting the victim’s information. Alvieri explained, "When deadlines come and go, it is a sign the company is negotiating or has at least acknowledged the incident. The report is usually in the final stages. The ransom process can take weeks or even months."

 

LockBit’s history includes setting deadlines and not releasing stolen data, as evidenced by the Royal Mail International attack earlier this year. In that case, LockBit posted a full negotiation history when the deadline expired rather than releasing the stolen data as initially threatened.

 

LockBit also has a history of employing various tactics to create confusion and increase its notoriety, such as orchestrating "fake" ransomware attacks on prominent organizations and setting countdown timers to publish stolen files. In some cases, as with Thales, they have followed through with data publication after countdowns expired.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543