US Bank is looking into LockBit’s claims about a breach and stolen data. The ransomware group says they will share the supposed stolen files on September 3 if a secret ransom is not paid. Lee Henderson, US Bank vice president of public affairs, confirmed that the company is aware of the claims. In a statement, Henderson said the bank is examining whether a cybersecurity incident occurred.
Lee Henderson said in an emailed statement to The Register: “At this time, there is no indication that our internal systems are impacted or evidence of unauthorized access to our network. US Bank takes the security and privacy of our clients’ and employees’ information very seriously.”
“We have provided relevant information to law enforcement and continue to support their investigation,” Henderson continued. “The security and privacy of our customers’ information is our highest priority. We will continue to provide updates as warranted.”
The bank has not said if it has talked to LockBit, if any data was stolen, or how much money the ransomware group asked for.
US Bank Investigates LockBit Data Breach Claim
LockBit put US Bank on its data leak site late Wednesday and gave them 14 days to pay the ransom. The group did not share details about how many files they have or what kind of information was stolen.
The event shows that financial institutions still face the danger of ransomware attacks to steal data. In these attacks, criminals might take data before locking systems or even without using ransomware. They then pressure victims to pay by saying they will share customer records, employee details, internal papers, or financial information.
Security experts and police have said many times that paying a ransom does not ensure that stolen data will be erased. During the 2024 Operation Cronos, investigators found that LockBit kept victim data even after companies paid ransoms.
International police took LockBit servers, websites, and decryption keys in February 2024. Later, they named Dmitry Yuryevich Khoroshev, known as LockBitSupp, as the suspected LockBit operator.
The group kept working and returned with a LockBit 5.0 ransomware version in 2025. The new LockBit claim follows past issues with US Bank customer data from third-party vendors.
In a recent issue with a vendor connected to Fidelity National Information Services, US Bank reportedly began telling 537 customers from Massachusetts that their names, addresses, and credit card numbers might have been revealed.
US Bank had a bigger data leak in 2022. This incident affected around 11,000 customers because a vendor mistakenly shared a file with details about closed credit card accounts.
Related News:
LockBit’s seized darknet site resurrected by police, teasing new revelations
LockBit Ransomware Operation Shut Down; Decryption Keys Released
InfoSecBulletin Cybersecurity for mankind
