U.S. Bancorp Investigates LockBit Ransomware Claims Linked to Fourth-Party Breach

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

U.S. Bancorp is currently investigating claims of data theft linked to the LockBit ransomware gang, which recently added the bank to its list of victims. The bank stated that these claims are associated with a breach involving a contractor for a third party and do not affect its own systems or network. According to reporting by The Record, a spokesperson for U.S. Bancorp confirmed that the investigation traced the incident back to a “potential cyber incident…related to a fourth party event that occurred outside” of their environment.

At this time, U.S. Bancorp has found no evidence that its systems, networks, or data repositories were compromised. The bank has provided relevant information to law enforcement and is supporting their ongoing investigation. The claims surfaced on Thursday when LockBit threatened to leak data within two weeks.

U.S. Bancorp, the seventh largest bank in the United States, reported $7.7 billion in revenue last quarter. The company has not disclosed the identities of the third and fourth parties involved in the breach but has stated it will continue to monitor the situation closely.

LockBit has not provided any samples of the purported stolen information to substantiate their claims. Historically, the ransomware group has been one of the most active and destructive, reportedly earning $252.4 million in ransoms from 353 successful attacks between 2022 and 2024, according to the U.S. Treasury Department. Despite facing operational challenges and increased law enforcement scrutiny, LockBit has attempted to revive its operations.

U.S. Bancorp is the second bank to be added to a ransomware leak site this week, following Cameroon’s Crédit Communautaire d’Afrique Bank, which was listed by another group.

Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

IDScan Confirms Data Breach Exposing 153 Million Driver’s License Scans for Sale on Dark Web

Identity verification firm IDScan has confirmed a data breach that has exposed scans of approximately 153 million driver’s licenses, with the information reportedly available...

NVIDIA and Palantir Collaborate to Enhance Supply Chain Sovereignty with AI Solutions

Palantir Technologies Inc. and NVIDIA have announced a strategic collaboration aimed at enhancing supply chain sovereignty through advanced artificial intelligence (AI) solutions. This partnership...

Microsoft Warns of AI-Enhanced Executive Impersonation and Invoice Fraud Campaigns

In a concerning trend, threat actors are leveraging artificial intelligence (AI) to enhance their tactics in executing executive impersonation and invoice fraud schemes. Recent...

NASA’s SARSAT technology aids in rescue of five fishermen at sea

NASA's Search and Rescue Satellite-Aided Tracking (SARSAT) technology played a crucial role in the rescue of five fishermen off the Gulf Coast of Mississippi...