US Bank is currently investigating claims made by the LockBit ransomware group, which alleges that it breached the bank and stole sensitive data.
The group has set a deadline of September 3 for the bank to meet an undisclosed extortion demand. As of now, the details of the alleged attack have not been independently verified, and US Bank has stated that there is currently no evidence indicating that its internal systems or network were accessed without authorization.
US Bank Data Breach
Lee Henderson, US Bank’s Vice President of Public Affairs, confirmed that the bank is aware of the claims regarding a potential cybersecurity incident.
However, the bank has chosen not to disclose whether it has communicated with the ransomware group or received any details about the alleged stolen data.
“At this time, there is no indication that our internal systems have been impacted, and there is no evidence of unauthorized access to our network,” Henderson stated, adding that the organization is continuing to investigate and monitor the situation.
On August 19, LockBit reportedly added US Bank to its data-leak site, giving the bank 14 days to pay up or face the publication of the purportedly stolen data.
The group did not specify the volume of data allegedly exfiltrated, the affected systems, or the nature of the files. This lack of clarity is common in double-extortion ransomware cases, where threat actors not only encrypt files but also threaten to publicly expose the stolen information.
This incident emphasizes the inherent risks associated with ransomware payments. Even if victims choose to pay, there is no guarantee that cybercriminals will delete the stolen data or abstain from further extortion attempts.
A law enforcement investigation into LockBit’s previous operations in 2024 reportedly revealed that the group retained victim data even after receiving ransom payments, undermining assurances often made during negotiations.
Despite international efforts to disrupt its activities, LockBit remains one of the most notorious names in the ransomware landscape.
Authorities seized LockBit’s infrastructure, domains, servers, and decryption keys in February 2024 during Operation Cronos, as reported by The Register.
Alleged LockBitSupp administrator Dmitry Yuryevich Khoroshev has been identified but remains at large. The group resurfaced in 2025 with its LockBit 5.0 ransomware variant, illustrating how ransomware-as-a-service operations can rebuild their infrastructure and continue targeting organizations after high-profile crackdowns.
This incident is not the first data-security issue involving US Bank customers. In a separate incident linked to vendor Fidelity National Information Services, US Bank began notifying 537 customers in Massachusetts in June after discovering on May 7 that names, mailing addresses, and credit card numbers may have been exposed.
The bank confirmed that Social Security numbers, online banking credentials, and account balances were not accessed during that breach.
For financial institutions, this latest claim underscores the need for rapid validation of extortion claims, preservation of forensic evidence, assessment of vendor exposure, and the preparation of customer notification and incident response plans before threat actors escalate public pressure.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC





