LockBit Claims Data Breach at US Bank, Threatens September 3 Leak
Ransomware group LockBit claims to have breached US Bank and stolen data, setting a September 3 deadline for ransom payment or data leak.

US Bank is currently investigating claims made by the ransomware group LockBit, which alleges a successful breach and exfiltration of sensitive data. The cybercriminal organization has issued a stark ultimatum: pay an unspecified ransom demand by September 3, or face the public release of the stolen information. Lee Henderson, US Bank's VP of public affairs, confirmed the bank's awareness of the claims in a statement to The Register, stating, "We’re aware of claims regarding a potential cybersecurity incident." The bank has declined to provide further details regarding communications with the threat actors or the specifics of the ransom demand.
While the investigation is ongoing, US Bank has emphasized that there is currently "no indication that our internal systems are impacted and no evidence of unauthorized access to our network." The institution reiterated its commitment to client and employee data security, stating, "US Bank takes the security and privacy of our clients' and employees' information very seriously. We continue to investigate and closely monitor these claims and remain, as always, vigilant in our efforts to mitigate potential exposure to cyber events."
LockBit added US Bank to its data leak site on Wednesday night, initiating a 14-day countdown for the ransom payment. The group has not disclosed the volume or nature of the data allegedly stolen. This incident occurs despite previous law enforcement actions against LockBit. In February 2024, international law enforcement agencies seized LockBit's infrastructure, including servers and decryption keys, in an effort to dismantle the group. Despite these efforts, LockBit resurfaced in September 2025 with a new variant, LockBit 5.0.
Adding to the concern, the bank has a history of data exposures affecting its customers, often stemming from breaches at third-party vendors. Most recently, US Bank notified approximately 537 customers in Massachusetts about potential exposure of their credit card information, including names and addresses, due to a security lapse at its vendor, Fidelity National Information Services. While Social Security numbers and online banking credentials were not believed to be compromised in that incident, a larger breach in 2022 affected around 11,000 customers whose personal data was shared by another vendor.
Even if US Bank were to meet LockBit's demands, there is no guarantee that the stolen data would be deleted. Evidence gathered when law enforcement disrupted an earlier iteration of LockBit in 2024 indicated that the group continued to retain victim data even after ransoms were paid. This history raises serious questions about the efficacy of paying ransoms to such groups.
The potential legal ramifications for US Bank are also mounting. At least one law firm has indicated it is considering a class-action lawsuit on behalf of affected customers, particularly those whose credit card details may have been compromised through the third-party vendor incident. The ongoing nature of these breaches and the persistent threat from ransomware groups like LockBit underscore the critical need for robust cybersecurity measures and vigilant oversight of third-party risks.