U.S. Bancorp Investigates LockBit Ransomware Claims Linked to Fourth-Party Breach

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

U.S. Bancorp is currently investigating claims of data theft linked to the LockBit ransomware gang, which recently added the bank to its list of victims. The bank stated that these claims are associated with a breach involving a contractor for a third party and do not affect its own systems or network. According to reporting by The Record, a spokesperson for U.S. Bancorp confirmed that the investigation traced the incident back to a “potential cyber incident…related to a fourth party event that occurred outside” of their environment.

At this time, U.S. Bancorp has found no evidence that its systems, networks, or data repositories were compromised. The bank has provided relevant information to law enforcement and is supporting their ongoing investigation. The claims surfaced on Thursday when LockBit threatened to leak data within two weeks.

U.S. Bancorp, the seventh largest bank in the United States, reported $7.7 billion in revenue last quarter. The company has not disclosed the identities of the third and fourth parties involved in the breach but has stated it will continue to monitor the situation closely.

LockBit has not provided any samples of the purported stolen information to substantiate their claims. Historically, the ransomware group has been one of the most active and destructive, reportedly earning $252.4 million in ransoms from 353 successful attacks between 2022 and 2024, according to the U.S. Treasury Department. Despite facing operational challenges and increased law enforcement scrutiny, LockBit has attempted to revive its operations.

U.S. Bancorp is the second bank to be added to a ransomware leak site this week, following Cameroon’s Crédit Communautaire d’Afrique Bank, which was listed by another group.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Attacker Compromises AI Coding Assistant, Spreads Shai-Hulud Worm to 100 Repositories

Mandiant has reported that an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider, subsequently spreading the Shai-Hulud worm across approximately...

Norwegian Authorities Investigate Telenor for Alleged Complicity in Myanmar Junta’s Crimes Against Humanity

Law enforcement agencies in Norway are investigating telecommunications giant Telenor for potential complicity in crimes against humanity linked to its operations with Myanmar's military...

Ransomware Incidents Surge in the Gulf, Targeting Businesses Amid Increased Cyber Threats

Ransomware incidents in the Gulf region have surged dramatically, with organized criminal groups increasingly targeting businesses in sectors where disruption can compel victims to...

Palo Alto Networks Develops Behavioral Clustering Model for Cloud Identity Security

Mapping Cloud Identities: A New Approach to Security As organizations increasingly migrate to cloud environments, the complexity of managing identities—human, machine, and autonomous agents—has become...