LockBit has listed US Bank on its leak site and claims it stole data from the financial institution, giving the bank 14 days to pay before publishing the material. Reporting on the incident describes it as a ransomware-linked extortion attempt targeting usbank.com, with the gang threatening to leak the allegedly stolen information on September 3 if its demands are not met.
US Bank said it is investigating the claim but reported no indication that its internal systems were impacted and no evidence of unauthorized access to its network at the time of its statement. LockBit did not specify what data was allegedly taken, and the claim comes as the group continues operating under LockBit 5.0 after reemerging following a major 2024 law-enforcement disruption and the public identification of alleged operator Dmitry Yuryevich Khoroshev.

TTPs, infrastructure, and targeting history in one profile.
11 events from the most recent confirmed update back to the earliest known activity.
U.S. Bancorp said LockBit's claim of stolen bank data was tied to a breach involving a contractor for a third party, stemming from a fourth-party incident outside the bank's environment. The bank said it found no evidence its own systems, networks, or data repositories were compromised and that it shared relevant information with law enforcement.
US Bank said it is investigating LockBit's claims of a potential cybersecurity incident. The bank stated it had no indication internal systems were impacted and no evidence of unauthorized access to its network at that time.
LockBit added US Bank to its leak site late Wednesday night, claiming it had breached the bank and stolen data. The group gave the bank 14 days to pay before publication of the alleged stolen information.
The incident affecting US Bank was reportedly discovered on August 20, 2026 at 10:36 UTC. The source describes the event as a ransomware-related data breach.
The reported breach of US Bank occurred on August 20, 2026 at 10:08 UTC and was attributed to LockBit5. The incident was described as a ransomware attack and data breach affecting usbank.com.
In September 2025, LockBit reemerged with a new ransomware variant called LockBit 5.0. This marked the group's return after prior law-enforcement disruption.
In May 2024, authorities publicly identified LockBitSupp's alleged true identity as Dmitry Yuryevich Khoroshev. The article says he is a Russian national and remains at large.
In February 2024, law enforcement seized LockBit servers, domain infrastructure, and decryption keys as part of an effort to dismantle the ransomware group. The action targeted a prior iteration of LockBit.
A separate third-party incident in 2022 affected around 11,000 US Bank customers after a vendor accidentally shared a file tied to closed US Bank credit card accounts. The exposed file included names, addresses, Social Security numbers, dates of birth, closed account numbers, and outstanding balances.
In June, US Bank began notifying 537 customers in Massachusetts that their names, mailing addresses, and credit card numbers may have been stolen in the third-party incident. The bank reportedly told customers that Social Security numbers, online banking credentials, and account balances were not accessed.
US Bank reportedly learned on May 7 of a third-party security incident that reached the bank through vendor Fidelity National Information Services. The incident involved customer credit card information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcetherecord.media
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcetheregister.com
Open sourcehookphish.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.