US Bank is currently investigating claims made by the LockBit ransomware group, which alleges it breached the financial institution and exfiltrated data. LockBit has set a deadline of September 3 for US Bank to pay an extortion demand, threatening to publish the stolen information if the payment is not made.
Lee Henderson, US Bank's VP of public affairs, stated that the bank is aware of the claims regarding a potential cybersecurity incident. However, US Bank has not confirmed whether it has engaged in communication with the extortionists or disclosed the amount of the demanded ransom.
Henderson emphasized that, at this time, there is no indication of impact to US Bank's internal systems and no evidence of unauthorized access to its network. The bank is continuing its investigation and monitoring the claims closely, while also maintaining vigilance against potential cyber events.
LockBit added US Bank to its leak site late on Wednesday night, giving the bank 14 days to meet its demands. The post by the ransomware group did not specify the volume or nature of the files allegedly stolen.
This incident follows previous third-party breaches that have affected US Bank customers. In one such instance, US Bank reportedly discovered on May 7 that a vendor, Fidelity National Information Services, had experienced a security issue that potentially exposed the credit card information of some US Bank customers. In June, the bank began notifying 537 Massachusetts residents that their names, mailing addresses, and credit card numbers might have been compromised. Social Security numbers, online banking credentials, and account balances were reportedly not accessed in this particular incident.
A larger event in 2022 involved a different vendor inadvertently sharing a file containing personal information for approximately 11,000 customers with closed US Bank credit card accounts. This data included names, addresses, Social Security numbers, dates of birth, closed account numbers, and outstanding balances.
LockBit, a notorious ransomware group, reemerged in September 2025 with its LockBit 5.0 variant, following an international law enforcement operation in February 2024 that aimed to dismantle the group by seizing servers, domain infrastructure, and decryption keys. In May 2024, authorities identified Dmitry Yuryevich Khoroshev, a Russian national, as "LockBitSupp," though he remains at large.






