Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical GitLab Code Injection Flaw CVE-2023-5006 Actively Exploited
August 21, 2026
Critical WordPress Plugin Bug Exposes Sites to Remote Code Execution
August 21, 2026
Claude Opus 5 AI Bypasses Obfuscated Binaries, Not Defeats Them
August 21, 2026
Home/CyberSecurity News/US Bank Investigates LockBit Ransomware Attack Claiming Data Theft
CyberSecurity News

US Bank Investigates LockBit Ransomware Attack Claiming Data Theft

Key Takeaways US Bank is currently investigating claims from the LockBit ransomware group regarding a potential data breach and theft. LockBit has threatened to publish allegedly stolen data on...

Jennifer sherman
Jennifer sherman
August 21, 2026 3 Min Read
2 0

Key Takeaways

  • US Bank is currently investigating claims from the LockBit ransomware group regarding a potential data breach and theft.
  • LockBit has threatened to publish allegedly stolen data on September 3 if a ransom is not paid.
  • US Bank has not found evidence of internal system compromise or unauthorized network access, but its investigation is ongoing.
  • This incident highlights the persistent threat of data extortion by ransomware groups against financial institutions.

US Bank Probes LockBit Ransomware Group’s Data Theft Claims

US Bank is actively investigating allegations made by the notorious LockBit ransomware collective, which claims to have breached the bank’s systems and exfiltrated sensitive data. The group has issued an ultimatum, threatening to release the purportedly stolen information on September 3 unless an undisclosed ransom demand is met.

Table Of Content

  • Key Takeaways
  • US Bank Probes LockBit Ransomware Group’s Data Theft Claims
  • LockBit’s Latest Extortion Effort
  • LockBit’s Resilience Post-Disruption
  • What You Should Do

Lee Henderson, Vice President of Public Affairs at US Bank, acknowledged awareness of LockBit’s claims. In a statement, Henderson confirmed that the bank is diligently examining the situation to ascertain whether a cybersecurity incident has indeed occurred. Lee Henderson said in an emailed statement to The Register, “At this time, there is no indication that our internal systems are impacted or evidence of unauthorized access to our network. US Bank takes the security and privacy of our clients’ and employees’ information very seriously.”

As of now, US Bank has not disclosed whether it has engaged in communication with LockBit, confirmed the extent of any data exfiltration, or revealed the specific amount of the alleged ransom demand.

LockBit’s Latest Extortion Effort

LockBit added US Bank to its dark web data leak site late on a Wednesday, initiating a 14-day countdown for the organization to comply with its ransom request. The ransomware group did not provide specific details regarding the volume or nature of the files it claims to possess, nor the types of information that may have been compromised.

This incident underscores the ongoing and significant risk posed by ransomware-based data extortion, particularly targeting financial sector entities. In such attacks, threat actors often steal data prior to, or even in lieu of, encrypting systems. They then leverage the threat of public data release—including customer records, employee data, internal documents, or financial information—to pressure victims into making payments.

Security experts and law enforcement agencies have consistently warned against paying ransoms, emphasizing that such payments do not guarantee the deletion of stolen data.

LockBit’s Resilience Post-Disruption

During the 2024 Operation Cronos, a coordinated international effort to disrupt LockBit’s infrastructure, investigators uncovered evidence that the group often retained victim data even after receiving extortion payments. In February 2024, global law enforcement agencies successfully seized LockBit’s servers, domains, and decryption keys, later identifying alleged LockBit operator Dmitry Yuryevich Khoroshev, also known as LockBitSupp.

Despite these significant disruptions, the group demonstrated resilience, resurfacing with a new LockBit 5.0 ransomware variant in 2025. This latest claim against US Bank follows previous incidents involving customer data exposures through third-party vendors, rather than direct breaches of the bank’s core systems.

In a recent vendor-related event linked to Fidelity National Information Services, US Bank reportedly began notifying 537 customers in Massachusetts that their names, mailing addresses, and credit card numbers may have been exposed. The bank clarified that Social Security numbers, online banking credentials, and account balances were not compromised in that particular incident. A class-action lawsuit is reportedly under consideration in connection with this vendor breach.

Prior to this, US Bank experienced a larger third-party data exposure in 2022, affecting approximately 11,000 customers. This incident occurred when a vendor inadvertently shared a file containing information on closed credit card accounts, including names, addresses, Social Security numbers, dates of birth, account numbers, and outstanding balances. US Bank continues to monitor the LockBit claim as its investigation progresses.

What You Should Do

  • Monitor Accounts: Customers of US Bank should remain vigilant and closely monitor their bank statements, credit card activity, and credit reports for any suspicious or unauthorized transactions.
  • Exercise Caution with Communications: Be wary of unsolicited emails, texts, or calls claiming to be from US Bank, especially those requesting personal information or linking to external sites. Phishing attempts often follow news of potential breaches.
  • Review Privacy Settings: Regularly review and strengthen privacy and security settings across all online accounts.
  • Implement Multi-Factor Authentication (MFA): Enable MFA wherever possible for an added layer of security on financial and other sensitive online accounts.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachCybersecurityransomwareSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Critical N-able Passportal Flaw Exposes Password Vaults, 2FA Codes

Next Post

Claude Opus 5 AI Bypasses Obfuscated Binaries, Not Defeats Them

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Sandworm Exploits OAuth, WhatsApp to Hijack High-Value Accounts
August 21, 2026
Fake Google Gemini installer deploys Vidar Stealer, steals browser data
August 21, 2026
Critical Vulnerability in Dameware Mini Remote Control Exposes Networks
August 21, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us