US Bank Investigates Alleged Data Breach by LockBit Ransomware Group
US Bank is currently embroiled in a serious investigation concerning allegations made by the LockBit ransomware group, which claims to have breached the bank and stolen sensitive data. The situation underscores ongoing concerns about cybersecurity threats that financial institutions face in today’s digital landscape.
The ransomware group has issued a deadline of September 3 for US Bank to comply with an undisclosed extortion demand. This ultimatum adds a layer of urgency to the investigation, compelling the bank to address these claims swiftly. Notably, the details of the alleged attack have yet to be independently verified; however, US Bank maintains that there is presently no evidence suggesting that its internal systems or network have been accessed without authorization.
Lee Henderson, US Bank’s Vice President of Public Affairs, has publicly confirmed the bank’s awareness of the claims surrounding a potential cybersecurity incident. Despite acknowledging the situation, the bank has refrained from indicating whether it has engaged in discussions with the ransomware group or received any specific details regarding the alleged data theft. Henderson emphasized that, “At this time, there is no indication that our internal systems have been impacted, and there is no evidence of unauthorized access to our network.” This statement reflects the bank’s commitment to investigating and actively monitoring the progress of the situation.
On August 19, the LockBit group reportedly added US Bank to its data-leak site, a platform commonly used to pressure organizations into complying with ransom demands. The group granted the bank a generous 14-day window to comply, with the ominous warning of publishing the purportedly stolen data should the bank fail to do so. However, the group has not disclosed specifics regarding the volume of data allegedly exfiltrated, the systems affected, or the nature of the files in question. This lack of clarity is a hallmark of double-extortion ransomware attacks, where offenders not only encrypt files but also threaten to reveal sensitive information to increase coercive pressure.
The incident highlights the inherent risks that accompany ransomware payments. Even if victims opt to pay ransoms to retrieve their data, they are often left with no guarantees that cybercriminals will erase the stolen data or refrain from further attempts at extortion. A prior law enforcement investigation into LockBit’s operations revealed unsettling findings: even after ransom payments were made, the group retained victim data, thus rendering assurances made during negotiations primarily worthless.
LockBit has established itself as one of the most notorious entities in the ransomware ecosystem, remaining remarkably active despite significant international efforts to disrupt its activities. In February 2024, authorities executed Operation Cronos, successfully seizing LockBit’s infrastructure, domains, servers, and decryption keys. Reportedly, this operation led to the identification of Dmitry Yuryevich Khoroshev, an alleged administrator of LockBitSupp, although he continues to evade capture. The situation took a concerning turn in 2025 when the group resurfaced with an updated version of its ransomware, dubbed LockBit 5.0, further exemplifying how ransomware-as-a-service operations can quickly rebuild their infrastructure and renew their targeting of organizations after facing serious crackdowns.
This incident is not an isolated one for US Bank; it follows a separate data-security breach linked to vendor Fidelity National Information Services. In June, the bank started notifying 537 customers in Massachusetts following the discovery that names, mailing addresses, and credit card numbers may have been compromised. Fortunately, during that breach, it was confirmed that critical information such as Social Security numbers, online banking credentials, and account balances remained secure and were not accessed.
For financial institutions like US Bank, this latest claim serves as a sharp reminder of the importance of swiftly validating extortion claims, preserving forensic evidence, assessing potential vendor vulnerabilities, and preparing robust customer notification and incident response plans. As the landscape of cybersecurity threats evolves, the risks associated with these incidents require immediate and concerted attention to prevent further escalation and protect sensitive customer information.
