The LockBit ransomware gang added U.S. Bancorp to its list of victims, threatening to leak data within two weeks. This claim prompted an investigation by the bank.
U.S. Bancorp stated that the claims are related to a breach involving a contractor for a third-party, which constitutes a fourth-party incident. The bank confirmed that its own systems, networks, or data repositories were not compromised. Relevant information has been provided to law enforcement for their investigation.
LockBit was a prominent ransomware group before a coordinated law enforcement takedown in 2024. The group has attempted to revive its operations despite facing operational issues and increased law enforcement action. LockBit did not provide samples of the stolen information to substantiate its claims against U.S. Bancorp.
U.S. Bancorp is the second bank listed on a ransomware leak site this week, following Cameroon’s Crédit Communautaire d'Afrique Bank. The U.S. Treasury Department previously reported that LockBit earned $252.4 million in ransoms from 353 successful attacks between 2022 and 2024.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
U.S. Bancorp stated that recent data theft claims by the LockBit ransomware gang are linked to a breach involving a contractor for a third-party, not its own systems. The bank confirmed no evidence of compromise to its internal networks or data repositories.