US Bank Investigates LockBit Ransomware Attack Claiming Data Theft
Key Takeaways US Bank is currently investigating claims from the LockBit ransomware group regarding a potential data breach and theft. LockBit has threatened to publish allegedly stolen data on...
Key Takeaways
- US Bank is currently investigating claims from the LockBit ransomware group regarding a potential data breach and theft.
- LockBit has threatened to publish allegedly stolen data on September 3 if a ransom is not paid.
- US Bank has not found evidence of internal system compromise or unauthorized network access, but its investigation is ongoing.
- This incident highlights the persistent threat of data extortion by ransomware groups against financial institutions.
US Bank Probes LockBit Ransomware Group’s Data Theft Claims
US Bank is actively investigating allegations made by the notorious LockBit ransomware collective, which claims to have breached the bank’s systems and exfiltrated sensitive data. The group has issued an ultimatum, threatening to release the purportedly stolen information on September 3 unless an undisclosed ransom demand is met.
Table Of Content
Lee Henderson, Vice President of Public Affairs at US Bank, acknowledged awareness of LockBit’s claims. In a statement, Henderson confirmed that the bank is diligently examining the situation to ascertain whether a cybersecurity incident has indeed occurred. Lee Henderson said in an emailed statement to The Register, “At this time, there is no indication that our internal systems are impacted or evidence of unauthorized access to our network. US Bank takes the security and privacy of our clients’ and employees’ information very seriously.”
As of now, US Bank has not disclosed whether it has engaged in communication with LockBit, confirmed the extent of any data exfiltration, or revealed the specific amount of the alleged ransom demand.
LockBit’s Latest Extortion Effort
LockBit added US Bank to its dark web data leak site late on a Wednesday, initiating a 14-day countdown for the organization to comply with its ransom request. The ransomware group did not provide specific details regarding the volume or nature of the files it claims to possess, nor the types of information that may have been compromised.
This incident underscores the ongoing and significant risk posed by ransomware-based data extortion, particularly targeting financial sector entities. In such attacks, threat actors often steal data prior to, or even in lieu of, encrypting systems. They then leverage the threat of public data release—including customer records, employee data, internal documents, or financial information—to pressure victims into making payments.
Security experts and law enforcement agencies have consistently warned against paying ransoms, emphasizing that such payments do not guarantee the deletion of stolen data.
LockBit’s Resilience Post-Disruption
During the 2024 Operation Cronos, a coordinated international effort to disrupt LockBit’s infrastructure, investigators uncovered evidence that the group often retained victim data even after receiving extortion payments. In February 2024, global law enforcement agencies successfully seized LockBit’s servers, domains, and decryption keys, later identifying alleged LockBit operator Dmitry Yuryevich Khoroshev, also known as LockBitSupp.
Despite these significant disruptions, the group demonstrated resilience, resurfacing with a new LockBit 5.0 ransomware variant in 2025. This latest claim against US Bank follows previous incidents involving customer data exposures through third-party vendors, rather than direct breaches of the bank’s core systems.
In a recent vendor-related event linked to Fidelity National Information Services, US Bank reportedly began notifying 537 customers in Massachusetts that their names, mailing addresses, and credit card numbers may have been exposed. The bank clarified that Social Security numbers, online banking credentials, and account balances were not compromised in that particular incident. A class-action lawsuit is reportedly under consideration in connection with this vendor breach.
Prior to this, US Bank experienced a larger third-party data exposure in 2022, affecting approximately 11,000 customers. This incident occurred when a vendor inadvertently shared a file containing information on closed credit card accounts, including names, addresses, Social Security numbers, dates of birth, account numbers, and outstanding balances. US Bank continues to monitor the LockBit claim as its investigation progresses.
What You Should Do
- Monitor Accounts: Customers of US Bank should remain vigilant and closely monitor their bank statements, credit card activity, and credit reports for any suspicious or unauthorized transactions.
- Exercise Caution with Communications: Be wary of unsolicited emails, texts, or calls claiming to be from US Bank, especially those requesting personal information or linking to external sites. Phishing attempts often follow news of potential breaches.
- Review Privacy Settings: Regularly review and strengthen privacy and security settings across all online accounts.
- Implement Multi-Factor Authentication (MFA): Enable MFA wherever possible for an added layer of security on financial and other sensitive online accounts.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.