Ransomware crew LockBit has added US Bank to its leak site, giving the lender 14 days to pay an extortion demand or see data dumped online. The post does not say how many files were allegedly stolen or what they contained. US Bank said it investigated and found no evidence its systems, networks, or data repositories were compromised, and that the claim appears to relate to a fourth-party event outside its environment.
“We have provided relevant information to law enforcement and continue to support their investigation,” said Lee Henderson, US Bank vice president of public affairs.
Even if the claims prove true and the bank pays, past takedowns show payment is no guarantee of deletion. When authorities dismantled an earlier LockBit iteration in 2024, they found evidence the crooks retained victim data even after ransoms were paid. The gang re-emerged in September 2025 with the LockBit 5.0 variant.
The listing follows a separate third-party incident that reached US Bank customers through vendor Fidelity National Information Services. In June the bank began notifying 537 customers, all Massachusetts residents, that names, mailing addresses, and credit card numbers may have been stolen; Social Security numbers, online banking credentials, and account balances were reportedly not accessed. At least one law firm says it is considering a class action over that exposure.
For CISOs, the episode is a reminder that extortion groups routinely target financial brands through vendors, and that a denial of compromise does not settle the question of customer data held by suppliers.
