CSIDB logo
Threat actor

Dmitry Yuryevich Khoroshev

Attribution profile

Type
Undetermined
Location
-
Known incidents
1 incident
Sources
0 sources
First seen
2026-08-19
Last seen
2026-08-19
Updated
2026-09-11 00:46
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor is known by the alias Dmitry Yuryevich Khoroshev.
This alias has been associated with a claim made by the LockBit ransomware group.
The association indicates that the actor is linked to the LockBit ransomware operation.
No further aliases or affiliations are publicly documented in the available sources.

On 2026-08-19, LockBit asserted that it had breached US Bank and exfiltrated undisclosed data.
The group placed US Bank on its leak site and issued a two‑week deadline to meet an unspecified demand.
LockBit warned that failure to comply would result in the release of the alleged stolen material.
No verifiable proof of the exfiltrated files was presented alongside the claim.
The assertion followed a pattern of ransomware actors using leak sites to pressure victims.

US Bank responded by stating that it has found no evidence of unauthorized access to its systems.
The bank indicated that it is reviewing logs, privileged activity, and vendor connections as part of its investigation.
Additionally, the bank is monitoring for any potential exposure resulting from the alleged incident.
The LockBit claim comes after earlier third‑party exposures that affected thousands of customers through vendors linked to the bank.

Incidents

Attributed incidents are available to members.

1 incident

Sources

Sources available to members: 0 sources.

CSIDB