Inside LockBit’s Countdown
Zachary Lewis is CISO of the University of Health Sciences and Pharmacy in St. Louis, one of the oldest pharmacy schools in the country. In 2023, the university was hit by LockBit, then the most active ransomware group in the world.
“It started in April of 2023. We thought it was just an IT outage; some hardware had failed because it was end of life. We responded the way we’d trained for: business continuity, following the playbook. We got most of the environment back up. Then it crashed again.
That’s when the threat actor, still in our system and unknown to us, triggered the ransomware. It was LockBit. When we got into the hypervisor, we found a readme file. It was the ransom note: they’d encrypted our data, claimed 75 gigabytes of it, wanted a million and a half dollars, and left instructions to contact them on the dark web.
We stopped everything—no more IT work, nothing that could jeopardize forensics. I notified leadership and made three calls that night. The first was to our cyber insurance provider. The second was to the FBI. The third was to my wife: we’ve had a ransomware attack, this might be a resume-generating event, so maybe dial back the spending for a while.
Finding that note is a stone-sinking feeling. You feel like the program failed, like you let these people in. It’s bad for the organization, but it’s very personal too. We’ve seen a lot of CISOs get fired for this. You think: am I going to be fired now?
“Finding that note is a stone-sinking feeling. You feel like the program failed, like you let these people in.”
Leadership was worried. I reported to the board, and most of them had never been through something like this—they’d heard about ransomware, maybe seen a credit monitoring notice land in their own mailbox, but they hadn’t lived it. They wanted to know everything at once: how the attackers got in, what data was taken, what we were going to do. These questions we simply didn’t have answers to yet.
As the CISO, you have to lead through it while your team feels it too. You don’t want to be running around with your hair on fire—they need to see a plan. That’s what gives them the motivation to keep going instead of being beaten down by what’s happening. The technology working was their job. The negotiation, the legal exposure became my responsibility, and the forensics team’s responsibility.
What stayed with me was not knowing whether the threat actor was still inside. Since LockBit had brought our whole environment down and encrypted it, we could rebuild clean and be reasonably sure they were gone. If they hadn’t done that—if they’d just left backdoors and new accounts scattered through a system that was still technically running—that’s a different kind of stress. Wondering if there’s a ghost in the machine that’s going to come back and hit you again.
The negotiation runs through a dark web support site. There is a forum page, a customer ID number. They know exactly who they’re working with, what data they have, what the ransom is. We didn’t have any way to tell if the stolen data was sensitive, so we were staring at file names, trying to guess what was inside and basing our response on that guess.
Assuming the attackers were still watching us, we set up out-of-band communication. This meant email accounts for leadership, so the attackers couldn’t see our recovery plan. Then we hit our own wall: the server handling authentication was encrypted, and our backup password was locked inside a password manager on another encrypted server. We only got back in because one team member had saved a cloud backup login to his personal password manager.
LockBit had also found and wiped one of our backup locations outright. They were clearly trying to make sure we couldn’t recover without paying.
“They were clearly trying to make sure we couldn’t recover without paying.”
We rebuilt on new hardware from backup. This is how most recovery happens now. A lot of threat actors have actually moved away from encryption altogether, because backup and recovery has gotten so much better. Why waste time encrypting if the target’s just going to restore from backup? If they can’t delete your backups, they steal the data. LockBit did both.
A few weeks in, once they realized we’d likely recovered, their tactics shifted: they dropped the ransom price, since we no longer needed the decryption key, but said they’d still leak our data unless we paid to have it deleted.
We stayed quiet for the first few weeks. There’s a reason for that caution: we later came to believe LockBit had contacted our regulator, the Department of Education, before we’d told anyone ourselves. Attackers notify compliance bodies directly to apply pressure. We had to scramble to explain what was happening before it was public knowledge.
LockBit began emailing individuals across the university directly— students, staff—telling them their personal data had been stolen, that leadership hadn’t paid, and that they should pressure us to pay.
Then they posted a public countdown clock on their forum page with our name, our logo, and seven days until they’d publish everything. Once people scrape these sites for names, the story takes on its own momentum: social media picks it up, then local media starts calling. With under a week left, we decided not to pay.
For us, the backend took the real hit: building temperature control, water flow, security cameras, authentication. But our cloud-hosted coursework was untouched, so students kept attending classes. We never had to shut down or send anyone home.”
Zachary, United States