LIVE · cybersecurity feed
Live wire
ransomware

US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline

Follow the money

zeroday.news ·

US Bank is currently investigating claims made by the LockBit ransomware group, which alleges it breached the financial institution and exfiltrated data. LockBit has set a deadline of September 3 for US Bank to pay an extortion demand, threatening to publish the stolen information if the payment is not made.

Lee Henderson, US Bank's VP of public affairs, stated that the bank is aware of the claims regarding a potential cybersecurity incident. However, US Bank has not confirmed whether it has engaged in communication with the extortionists or disclosed the amount of the demanded ransom.

Henderson emphasized that, at this time, there is no indication of impact to US Bank's internal systems and no evidence of unauthorized access to its network. The bank is continuing its investigation and monitoring the claims closely, while also maintaining vigilance against potential cyber events.

LockBit added US Bank to its leak site late on Wednesday night, giving the bank 14 days to meet its demands. The post by the ransomware group did not specify the volume or nature of the files allegedly stolen.

This incident follows previous third-party breaches that have affected US Bank customers. In one such instance, US Bank reportedly discovered on May 7 that a vendor, Fidelity National Information Services, had experienced a security issue that potentially exposed the credit card information of some US Bank customers. In June, the bank began notifying 537 Massachusetts residents that their names, mailing addresses, and credit card numbers might have been compromised. Social Security numbers, online banking credentials, and account balances were reportedly not accessed in this particular incident.

A larger event in 2022 involved a different vendor inadvertently sharing a file containing personal information for approximately 11,000 customers with closed US Bank credit card accounts. This data included names, addresses, Social Security numbers, dates of birth, closed account numbers, and outstanding balances.

LockBit, a notorious ransomware group, reemerged in September 2025 with its LockBit 5.0 variant, following an international law enforcement operation in February 2024 that aimed to dismantle the group by seizing servers, domain infrastructure, and decryption keys. In May 2024, authorities identified Dmitry Yuryevich Khoroshev, a Russian national, as "LockBitSupp," though he remains at large.

ransomwarebreachfinance
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

security

China Is Strapping ‘Digital Bombs’ to Civilian Infrastructure—Is the US Ready?

This week on “Uncanny Valley,” Andy Greenberg discusses sitting in on a war game simulating a cyberattack from the Chinese hacking group Volt Typhoon

nation-state

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. These clusters include UNC6293, UNC7005, and UNC5976. "These clusters engage in persistent, adaptive

malware

China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware

Suspected military-grade hackers based in China used artificial intelligence to develop malware in a campaign to penetrate Central Asian governments.

security

What We Missed: Delta Flight Disrupted With Wi-Fi Hack

In this video, Dark Reading editors discuss some of the news they didn't get a chance to cover, including some scary airplane security risks and the US government's newest "hack back" strategy.

security

Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist

Kyle Spitze led an offshoot of the violent extremist collective and victimized dozens of girls, coercing them to degrade themselves under threats of doxing and swatting. The post Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist appeared first on CyberScoop.