In February of 2024, a consortium of law enforcement agencies took down LockBit ransomware group. The discovery that LockBit retained victims’ stolen data despite promises to delete it demonstrates a critical flaw in the advice often given to ransomware victims. At the time, many legal and incident response professionals recommended payment on the assumption that LockBit had a strong financial incentive to honor its commitments and that the likelihood of data being publicly released after payment was relatively low.