US Bank is investigating LockBit’s claims of a breach and data theft, with the ransomware group threatening to publish the alleged stolen files on September 3 unless an undisclosed ransom is paid.
Lee Henderson, US Bank vice president of public affairs, confirmed that the company is aware of the claims. In a statement, Henderson said the bank is examining whether a cybersecurity incident occurred.
Lee Henderson said in an emailed statement to The Register: “At this time, there is no indication that our internal systems are impacted or evidence of unauthorized access to our network. US Bank takes the security and privacy of our clients’ and employees’ information very seriously.”
The bank has not disclosed whether it has contacted LockBit, whether any data was taken, or how much money the ransomware group allegedly demanded.
US Bank Investigates LockBit Data Breach Claim
LockBit added US Bank to its data leak site late Wednesday and gave the organization 14 days to meet its ransom demand. The group did not provide details about the number of files it claims to possess or the type of information that may have been stolen.
The incident highlights the continuing risk of ransomware-based data extortion against financial institutions. In these attacks, threat actors may steal data before encrypting systems or without deploying ransomware at all.
They then pressure victims to pay by threatening to release customer records, employee information, internal documents, or financial data.
Security researchers and law enforcement agencies have repeatedly warned that paying ransom does not guarantee stolen data will be deleted.
During the 2024 Operation Cronos disruption of LockBit infrastructure, investigators found evidence that the group retained victim data even after organizations made extortion payments.
International law enforcement agencies seized LockBit servers, domains, and decryption keys in February 2024. Authorities later identified alleged LockBit operator Dmitry Yuryevich Khoroshev, also known as LockBitSupp.
However, the group continued operating and resurfaced with a LockBit 5.0 ransomware variant in 2025. The latest LockBit claim comes after earlier incidents involving US Bank customer data through third-party vendors.
In a recent vendor-related incident linked to Fidelity National Information Services, US Bank reportedly began notifying 537 Massachusetts customers that their names, mailing addresses, and credit card numbers may have been exposed.
The bank said Social Security numbers, online banking credentials, and account balances were not accessed in that incident. A law firm is reportedly considering a class-action lawsuit related to the vendor breach.
US Bank also experienced a larger third-party data exposure in 2022. That incident reportedly affected about 11,000 customers after a vendor accidentally shared a file containing information on closed credit card accounts.
The exposed data included names, addresses, Social Security numbers, dates of birth, account numbers, and outstanding balances. US Bank continues to monitor the LockBit claim while its investigation remains ongoing.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
