U.S. Bancorp is currently investigating claims of data theft linked to the LockBit ransomware gang, which recently added the bank to its list of victims. The bank stated that these claims are associated with a breach involving a contractor for a third party and do not affect its own systems or network. According to reporting by The Record, a spokesperson for U.S. Bancorp confirmed that the investigation traced the incident back to a “potential cyber incident…related to a fourth party event that occurred outside” of their environment.
At this time, U.S. Bancorp has found no evidence that its systems, networks, or data repositories were compromised. The bank has provided relevant information to law enforcement and is supporting their ongoing investigation. The claims surfaced on Thursday when LockBit threatened to leak data within two weeks.
U.S. Bancorp, the seventh largest bank in the United States, reported $7.7 billion in revenue last quarter. The company has not disclosed the identities of the third and fourth parties involved in the breach but has stated it will continue to monitor the situation closely.
LockBit has not provided any samples of the purported stolen information to substantiate their claims. Historically, the ransomware group has been one of the most active and destructive, reportedly earning $252.4 million in ransoms from 353 successful attacks between 2022 and 2024, according to the U.S. Treasury Department. Despite facing operational challenges and increased law enforcement scrutiny, LockBit has attempted to revive its operations.
U.S. Bancorp is the second bank to be added to a ransomware leak site this week, following Cameroon’s Crédit Communautaire d’Afrique Bank, which was listed by another group.
Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.



