US Bank Probes LockBit’s Data Breach Claim

US Bank is looking into allegations from the LockBit ransomware gang, which claims to have stolen data from the bank and has threatened to publish it unless a ransom is paid by September 3. These claims are currently unverified, and US Bank says it is assessing whether any breach or unauthorized access has occurred. ([cybersecuritynews.com](https://cybersecuritynews.com/us-bank-investigating-data-breach-lockbit-claim/))

What US Bank is Saying

Lee Henderson, vice president of public affairs at US Bank, confirmed awareness of LockBit’s declaration and stated the financial institution is investigating. At this time, there’s no sign that US Bank’s internal systems have been compromised or that there has been unauthorized access. The bank emphasized the seriousness with which it treats client and employee data privacy. ([cybersecuritynews.com](https://cybersecuritynews.com/us-bank-investigating-data-breach-lockbit-claim/))

The bank has not shared whether it has communicated with LockBit, what kind of data might be involved, if any data was stolen, or the size of any ransom being demanded. LockBit added US Bank to its data leak site late Wednesday, giving the bank a two-week deadline to meet their demands. Details such as how many files are held or the sensitivity of the claimed stolen data remain vague. ([cybersecuritynews.com](https://cybersecuritynews.com/us-bank-investigating-data-breach-lockbit-claim/))

Context: LockBit’s History & Vendor Incidents

LockBit remains one of the most active ransomware groups. Despite law enforcement actions—like the 2024 Operation Cronos disruption, which seized infrastructure and revealed that LockBit retained victim data even after ransom payments—the group resurfaced with its LockBit 5.0 variant in 2025. ([cybersecuritynews.com](https://cybersecuritynews.com/us-bank-investigating-data-breach-lockbit-claim/))

US Bank has experienced prior data exposure through third-party vendors. Earlier this year, over 500 customers in Massachusetts were notified that names, mailing addresses, and credit card numbers may have been exposed after a vendor issue. More seriously, a 2022 incident involved exposure of closed credit card account data for about 11,000 customers—including names, Social Security numbers, dates of birth, addresses, account numbers, and balances. ([cybersecuritynews.com](https://cybersecuritynews.com/us-bank-investigating-data-breach-lockbit-claim/))

The prevalence of these incident types highlights a broader trend: ransomware groups increasingly target data theft, sometimes even without deploying encryption. Threat actors use the possibility of releasing personal, financial, or internal documents to pressure victims into paying ransom. ([cybersecuritynews.com](https://cybersecuritynews.com/us-bank-investigating-data-breach-lockbit-claim/))

US Bank says it continues to watch the situation as its investigation proceeds. It remains unclear whether LockBit’s claims are accurate or if any breach has really occurred. ([cybersecuritynews.com](https://cybersecuritynews.com/us-bank-investigating-data-breach-lockbit-claim/))

This episode underscores the ongoing threat ransomware groups pose to financial institutions, especially via data extortion. Companies can’t rely solely on containment—trustworthy third-party risk management, rapid incident response, and robust threat intelligence are all essential. What to watch now: whether US Bank confirms unauthorized data access, what type of data might be compromised, and whether LockBit follows through on its September 3 deadline.