Sunday , September 13 2026

US Bank investigates LockBit’s Data Breach Claims

US Bank is looking into LockBit’s claims about a breach and stolen data. The ransomware group says they will share the supposed stolen files on September 3 if a secret ransom is not paid. Lee Henderson, US Bank vice president of public affairs, confirmed that the company is aware of the claims. In a statement, Henderson said the bank is examining whether a cybersecurity incident occurred.

Lee Henderson said in an emailed statement to The Register: “At this time, there is no indication that our internal systems are impacted or evidence of unauthorized access to our network. US Bank takes the security and privacy of our clients’ and employees’ information very seriously.”

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Critical Check Point VPN flaws allow remote code execution attacks

Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
Critical Check Point VPN flaws allow remote code execution attacks

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used...
Read More
Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

A Russian-speaking hacker has used artificial intelligence like never before. They sent out hundreds of AI agents to find and...
Read More
Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Six Chinese AI companies ran large-scale attacks on American AI models since late 2024, according to U.S. cybersecurity and intelligence...
Read More
CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

An unknown security expert called Nightmare Eclipse has drops a new Microsoft Defender flaw called "ShieldCrash" right after Microsoft released...
Read More
Nightmare Eclipse Drops New Microsoft Defender ‘ShieldCrash’ zero-day

cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

cPanel has shared CVE-2026-67401, a serious SQL injection flaw in EmailTrack. This flaw could allow attackers with permission to take...
Read More
cPanel Flaw Lets Hosting Accounts With Mail Privileges Execute Code as Root

FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

An ongoing attack is focused on FortiGate firewalls. Hackers use a serious flaw to install a special Node.js remote access...
Read More
FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

“We have provided relevant information to law enforcement and continue to support their investigation,” Henderson continued. “The security and privacy of our customers’ information is our highest priority. We will continue to provide updates as warranted.”

The bank has not said if it has talked to LockBit, if any data was stolen, or how much money the ransomware group asked for.

US Bank Investigates LockBit Data Breach Claim

LockBit put US Bank on its data leak site late Wednesday and gave them 14 days to pay the ransom. The group did not share details about how many files they have or what kind of information was stolen.

The event shows that financial institutions still face the danger of ransomware attacks to steal data. In these attacks, criminals might take data before locking systems or even without using ransomware. They then pressure victims to pay by saying they will share customer records, employee details, internal papers, or financial information.

Security experts and police have said many times that paying a ransom does not ensure that stolen data will be erased. During the 2024 Operation Cronos, investigators found that LockBit kept victim data even after companies paid ransoms.

International police took LockBit servers, websites, and decryption keys in February 2024. Later, they named Dmitry Yuryevich Khoroshev, known as LockBitSupp, as the suspected LockBit operator.

The group kept working and returned with a LockBit 5.0 ransomware version in 2025. The new LockBit claim follows past issues with US Bank customer data from third-party vendors.

In a recent issue with a vendor connected to Fidelity National Information Services, US Bank reportedly began telling 537 customers from Massachusetts that their names, addresses, and credit card numbers might have been revealed.

US Bank had a bigger data leak in 2022. This incident affected around 11,000 customers because a vendor mistakenly shared a file with details about closed credit card accounts.

Related News:

LockBit’s seized darknet site resurrected by police, teasing new revelations
LockBit Ransomware Operation Shut Down; Decryption Keys Released

Check Also

Bdjobs

After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

A group of hackers named “Madarax” claims they have stolen and are offering to sell …