Friday, August 21, 2026

US Bank Investigates Alleged Data Breach After LockBit Ransomware Extortion Claim

US Bank is currently investigating claims made by the LockBit ransomware group, which alleges that it breached the bank and stole sensitive data.

The group has set a deadline of September 3 for the bank to meet an undisclosed extortion demand. As of now, the details of the alleged attack have not been independently verified, and US Bank has stated that there is currently no evidence indicating that its internal systems or network were accessed without authorization.

US Bank Data Breach

Lee Henderson, US Bank’s Vice President of Public Affairs, confirmed that the bank is aware of the claims regarding a potential cybersecurity incident.

However, the bank has chosen not to disclose whether it has communicated with the ransomware group or received any details about the alleged stolen data.

“At this time, there is no indication that our internal systems have been impacted, and there is no evidence of unauthorized access to our network,” Henderson stated, adding that the organization is continuing to investigate and monitor the situation.

On August 19, LockBit reportedly added US Bank to its data-leak site, giving the bank 14 days to pay up or face the publication of the purportedly stolen data.

The group did not specify the volume of data allegedly exfiltrated, the affected systems, or the nature of the files. This lack of clarity is common in double-extortion ransomware cases, where threat actors not only encrypt files but also threaten to publicly expose the stolen information.

This incident emphasizes the inherent risks associated with ransomware payments. Even if victims choose to pay, there is no guarantee that cybercriminals will delete the stolen data or abstain from further extortion attempts.

A law enforcement investigation into LockBit’s previous operations in 2024 reportedly revealed that the group retained victim data even after receiving ransom payments, undermining assurances often made during negotiations.

Despite international efforts to disrupt its activities, LockBit remains one of the most notorious names in the ransomware landscape.

Authorities seized LockBit’s infrastructure, domains, servers, and decryption keys in February 2024 during Operation Cronos, as reported by The Register.

Alleged LockBitSupp administrator Dmitry Yuryevich Khoroshev has been identified but remains at large. The group resurfaced in 2025 with its LockBit 5.0 ransomware variant, illustrating how ransomware-as-a-service operations can rebuild their infrastructure and continue targeting organizations after high-profile crackdowns.

This incident is not the first data-security issue involving US Bank customers. In a separate incident linked to vendor Fidelity National Information Services, US Bank began notifying 537 customers in Massachusetts in June after discovering on May 7 that names, mailing addresses, and credit card numbers may have been exposed.

The bank confirmed that Social Security numbers, online banking credentials, and account balances were not accessed during that breach.

For financial institutions, this latest claim underscores the need for rapid validation of extortion claims, preservation of forensic evidence, assessment of vendor exposure, and the preparation of customer notification and incident response plans before threat actors escalate public pressure.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Deepfake Ads Funnel Investors Into WhatsApp Groups Controlled by Fake Financial Analysts

Investment fraud is increasingly exploiting the one action banks...

UAT-10147 Compromises Web Servers to Deploy BadIIS for SEO Fraud and Data Theft

A Chinese-speaking cybercrime group, tracked as UAT-10147, targeting vulnerable...

Critical N-Able PassPortal Extension Flaw Gives Attackers Full Password Vault Access

Cybersecurity researchers have revealed a critical vulnerability in N-able’s...

OpenAI Frontier Models Get Zero Data Retention With Private Safety Processing

OpenAI has reaffirmed its commitment to Zero Data Retention...

Hackers Hide Agent Tesla Malware Behind Emojis to Steal Browser and Email Passwords

A business email compromise campaign is using emoji-filled JScript...

Quarkslab Says Anti-Reversing Software Should Return Plausible Wrong Answers Instead of Crashing

Quarkslab has argued that LLM-assisted reverse engineering does not...

Related Articles

Recent News