LockBit Claims US Bank Scalp With September Leak Deadline
US Bank is looking into claims from ransomware outfit LockBit that it broke into the bank's systems and made off with data. The criminals have set a September 3 deadline: pay up or the files go public.
Lee Henderson, VP of public affairs at US Bank, confirmed the bank is aware of the claims but offered little else. The bank wouldn't say whether it's in contact with the attackers, or what ransom figure LockBit is demanding. The official line: no sign of compromised internal systems, no evidence of unauthorised network access, and lots of vigilance.
Take that reassurance with a pinch of salt. When law enforcement dismantled an earlier version of LockBit in early 2024, investigators found that the group had kept hold of victim data even after ransoms were paid. So even if US Bank wrote a cheque tomorrow, the data might not go anywhere useful.
LockBit added US Bank to its leak site late Wednesday, giving the bank a 14-day window. The post is light on specifics, with no mention of file counts or what kind of data was taken.
The group has had a turbulent couple of years. International police seized LockBit's servers, domains, and decryption keys in February 2024, and by May had publicly named alleged ringleader Dmitry Yuryevich Khoroshev, a Russian national who remains, predictably, at large. Despite that takedown, LockBit resurfaced in September 2025 with a new variant, LockBit 5.0. Apparently nearly getting dismantled by a global police operation is just a minor inconvenience.
This latest claim lands against an already messy backdrop for US Bank. The bank has already been dealing with fallout from a separate third-party breach involving Fidelity National Information Services, one of its vendors. US Bank learned about that incident in May, and in June started notifying 537 customers, all Massachusetts residents, that their names, addresses, and credit card numbers may have been exposed. Social Security numbers, login credentials, and account balances were reportedly not accessed.
At least one law firm is already circling, weighing a class-action suit against US Bank National Association on behalf of affected customers. Whether LockBit's current claims add fuel to that fire remains to be seen.