US Bank Examines Alleged Data Breach After LockBit Ransomware Extortion Claim | #ransomware | #cybercrime


US Bank is investigating claims by the LockBit ransomware operation that it breached the financial institution and stole undisclosed data, as the cybercriminal group threatens to publish the alleged material unless an extortion demand is paid by September 3.

The bank said it is aware of the claims but has not confirmed that a compromise occurred. Lee Henderson, US Bank’s vice president of public affairs, said the organization is reviewing the situation and monitoring for potential exposure.

“At this time, there is no indication that our internal systems are impacted and no evidence of unauthorized access to our network,” Henderson said.

US Bank Examines Alleged Data Breach

The bank did not disclose whether it had engaged with LockBit, received a ransom demand, or identified the type and volume of data allegedly taken. LockBit reportedly added US Bank to its data-leak site late Wednesday, granting the financial institution 14 days to meet its demands.

The group’s listing did not include samples of the alleged stolen files, a file count, or details about affected systems, customers, or employees. The incident illustrates the continuing risk posed by ransomware groups using double-extortion tactics.

Rather than relying solely on encryption to disrupt operations, attackers increasingly steal data first and threaten public release if a victim declines to pay. This approach allows gangs to maintain leverage even when organizations can restore systems from backups.

Paying, however, offers little assurance that stolen information will be deleted. When law enforcement agencies disrupted LockBit infrastructure in 2024, investigators found evidence indicating that the group had retained victim data even after receiving extortion payments.

That finding reinforces a central challenge for incident responders: a ransom payment may reduce immediate pressure but cannot reliably eliminate the risk of data exposure, resale, or subsequent extortion.

LockBit was one of the most prolific ransomware-as-a-service operations before Operation Cronos, the international law-enforcement action that seized servers, domains, and decryption keys in February 2024.

Authorities later identified alleged LockBitSupp administrator Dmitry Yuryevich Khoroshev, who remains at large. Despite the disruption, the operation resumed activity, including the emergence of its LockBit 5.0 ransomware variant in late 2025.

The alleged breach also arrives amid renewed scrutiny of third-party data exposures involving US Bank customers.

In a separate vendor-linked incident disclosed earlier this year, the bank reportedly began notifying 537 Massachusetts customers that their names, mailing addresses, and credit card numbers may have been exposed through Fidelity National Information Services.

According to The Register, that incident did not involve Social Security numbers, online banking credentials, or account balances. A law firm has nevertheless said it is considering a potential class-action case on behalf of affected individuals.

US Bank has also faced a prior large-scale vendor-related exposure. In 2022, approximately 11,000 customers were affected after a third party accidentally shared a file containing information tied to closed US Bank credit-card accounts.

The data reportedly included names, addresses, Social Security numbers, dates of birth, account numbers, and outstanding balances. For defenders, LockBit’s latest claim highlights the need to treat leak-site postings as an incident-response trigger rather than proof of compromise.

Organizations should rapidly validate access logs, privileged account activity, data exfiltration telemetry, vendor connections, and cloud storage events while preparing legal, regulatory, customer notification, and communications workflows.

Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN



Click Here For The Original Source.

——————————————————–

..........

.

.