U.S. Bancorp, the seventh-largest bank in the United States, has stated that recent claims of data theft by the LockBit ransomware group are linked to a cyber incident involving a fourth-party vendor, rather than a direct compromise of the bank's own systems or network. The bank confirmed it has investigated the claims and found no evidence that its internal systems, networks, or data repositories were breached.
The LockBit ransomware gang added U.S. Bancorp to its list of victims on Thursday morning, threatening to publish stolen data within two weeks. However, LockBit did not provide any samples of the alleged stolen information to substantiate its claims. U.S. Bancorp initially reported no indication of impact to its systems or unauthorized network access.
A spokesperson for U.S. Bancorp indicated that the incident originated with a contractor for a third-party vendor, making it a "fourth-party event" that occurred outside the bank's direct environment. The company declined to identify the specific third or fourth parties involved in the breach. U.S. Bancorp has provided relevant information to law enforcement and is supporting an ongoing investigation.
This incident marks the second time a bank has appeared on a ransomware leak site this week, following Cameroon’s Crédit Communautaire d Afrique Bank, which was listed by a different group on Friday. Crédit Communautaire d Afrique Bank had reported operational issues two weeks prior.
The LockBit ransomware group, despite facing significant disruption from a coordinated international law enforcement takedown in 2024, continues to attempt to revive its operations. Before the takedown, the group was considered one of the most active and destructive ransomware operations. In December, the U.S. Treasury Department reported that LockBit had extorted $252.4 million in ransoms from 353 successful attacks between 2022 and 2024. The group has experienced operational challenges and other issues due to increased law enforcement pressure, and leaks of its source code have enabled other cybercriminals to utilize LockBit in their own attacks.






