US Bank investigates LockBit extortion claim after ransomware gang threatens to leak stolen data

US Bank says it is investigating LockBit’s claim that the ransomware gang breached the bank and stole data, with a pay-or-leak deadline set for September 3. LockBit posted US Bank on its leak site but did not say what data was allegedly taken or how many records are involved. US Bank said it has no current evidence of unauthorized access to its network or impact to internal systems and has not confirmed the claim.
Why it matters: A claimed breach at a major U.S. bank could affect customers and employees if stolen data is eventually verified and published. Financial institutions, customers, and partners should watch for follow-up disclosures, possible notification letters, and fraud or phishing that may use any leaked information.

Sources

In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions
SecurityWeek News 2026.08.28 95% relevant
This source updates U.S. Bank's response by saying the claim appears tied to a potential incident at a fourth-party provider outside the bank's own environment, and that the bank says it has no evidence its systems or data repositories were compromised.
U.S. Bank says breach claims related to fourth-party incident
2026.08.21 93% relevant
This updates the same underlying event by adding U.S. Bancorp’s conclusion that the claim appears tied to a fourth-party incident outside its environment, with no evidence that U.S. Bank’s own systems, network, or repositories were compromised.
US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline
2026.08.20 100% relevant
This article appears to be the initial report of LockBit publicly naming US Bank on its leak site and the bank confirming it is investigating the extortion claim.
← Back to all stories