Menu
Browse

Cyber Incident Victim: US Bank

Date

Aug 2026

Location

United States of America

Status

Ongoing

Updated

2026-08-21 17:02

Timeline
Occurred
Undetermined
Discovered
Undetermined
Disclosed
Aug 2026
Resolved
Pending
Summary

US Bank is investigating a claim by the LockBit ransomware group that it stole undisclosed data and threatened to publish it unless an extortion demand was met. The bank said it has found no evidence of unauthorized access to its network and is reviewing the situation while monitoring for potential exposure. LockBit added the institution to its data‑leak site, giving a deadline to meet its demands but provided no samples or details of the alleged stolen files. Separately, the bank has disclosed prior vendor‑related incidents in which customer information including names, addresses, credit card numbers, and in one case Social Security numbers, dates of birth, account numbers and balances was exposed.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 0 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

On August 21 2026 US Bank disclosed that it was investigating claims made by the LockBit ransomware operation that it had breached the institution and stolen undisclosed data. LockBit had added US Bank to its data‑leak site late on the preceding Wednesday, giving the bank a 14‑day window to meet an extortion demand that would expire on September 3. The bank said it was aware of the allegations but had not confirmed that a compromise had occurred. Lee Henderson, US Bank’s vice president of public affairs, stated that the organization was reviewing the situation and monitoring for any potential exposure. At the time of the statement Henderson noted there was no indication that internal systems were impacted and no evidence of unauthorized access to the network. The bank did not reveal whether it had engaged with LockBit, received a ransom demand, or identified the type or volume of data allegedly taken, and the leak‑site posting contained no file samples, counts, or details about affected systems, customers or employees.

Cyber Incident Image

LockBit had been one of the most prolific ransomware‑as‑a‑service groups before Operation Cronos, the international law‑enforcement action in February 2024 that seized servers, domains and decryption keys. Authorities later identified the alleged LockBitSupp administrator Dmitry Yuryevich Khoroshev, who remains at large. Despite the 2024 disruption the operation resumed activity, including the emergence of the LockBit 5.0 variant in late 2025. The group’s current tactic involves stealing data first and then threatening public release if the victim declines to pay, a double‑extortion approach that maintains leverage even when systems can be restored from backups. Law‑enforcement investigations after the 2024 disruption found evidence that LockBit had retained victim data even after receiving extortion payments, underscoring that payment does not guarantee deletion of stolen information.

The LockBit claim comes amid renewed scrutiny of third‑party data exposures involving US Bank customers. Earlier in 2026 the bank began notifying 537 Massachusetts customers that their names, mailing addresses and credit‑card numbers may have been exposed through a vendor‑linked incident with Fidelity National Information Services; that exposure did not involve Social Security numbers, online banking credentials or account balances, and a law firm has said it is considering a potential class‑action case on behalf of those individuals. In 2022 US Bank experienced a separate vendor‑related incident in which approximately 11,000 customers were affected after a third party accidentally shared a file containing information tied to closed credit‑card accounts; the compromised data reportedly included names, addresses, Social Security numbers, dates of birth, account numbers and outstanding balances. These prior incidents, together with the recent LockBit allegation, have contributed to heightened attention on the bank’s data‑protection posture.

Sources
Sources available to members
1 source