US Bank is investigating claims from ransomware group LockBit that the gang broke into the financial institution and took data, according to a report published by The Register on August 20, 2026. The cybercriminals are threatening to release the stolen information on September 3 unless the bank meets their extortion demands. Lee Henderson, US Bank's VP of public affairs, confirmed the bank is aware of the allegations but wouldn't answer questions about whether it has been in contact with the attackers or how much money LockBit is demanding.
LockBit posted US Bank to its leak site late Wednesday night, giving the institution 14 days to pay or face having its data dumped online. The posting doesn't reveal how many files the crew says it stole or what those files contained. Henderson stated that so far, there's no sign the bank's internal systems have been affected and no proof of unauthorized network access. The bank has dealt with previous third-party breaches that affected customer data, including an incident disclosed in June involving 537 Massachusetts residents whose names, mailing addresses, and credit card numbers may have been compromised through vendor Fidelity National Information Services. A larger 2022 incident affected roughly 11,000 customers when a different vendor accidentally shared a file with personal details from closed credit card accounts, including names, addresses, Social Security numbers, birth dates, closed account numbers, and outstanding balances.
"US Bank takes the security and privacy of our clients' and employees' information very seriously," Henderson said in an emailed statement. "We continue to investigate and closely monitor these claims and remain, as always, vigilant in our efforts to mitigate potential exposure to cyber events." The report notes that even if the extortionists' allegations are accurate and the bank pays, there's no assurance the digital thieves will actually delete the stolen files. When law enforcement dismantled an earlier version of LockBit in 2024, they discovered evidence the criminals kept victim data even after victims paid the ransom demands.
The current threat comes from a ransomware operation that international police tried to shut down but has since returned. In February 2024, cops seized servers, domain infrastructure, and decryption keys in an attempt to dismantle the notorious group, and in May 2024, they revealed LockBitSupp's real identity as Dmitry Yuryevich Khoroshev, a Russian national who remains at large. However, LockBit came back in September 2025 with its new LockBit 5.0 ransomware variant. The group's resilience shows how difficult it is to permanently eliminate ransomware operations, especially when key operators stay beyond the reach of Western law enforcement. Meanwhile, at least one law firm is considering a class-action lawsuit against US Bank National Association, the primary banking subsidiary of US Bancorp, on behalf of a small group of customers whose credit card information may have been exposed in the third-party security incident involving Fidelity National Information Services. For institutions like US Bank, the September 3 deadline presents a stark choice between paying criminals with no guarantee of data destruction or risking a public leak that could expose customer information and trigger regulatory scrutiny. Even after law enforcement wins appear to cripple ransomware gangs, the groups can rebuild and resume operations, forcing organizations to maintain constant defensive vigilance rather than relying on periodic enforcement actions to solve the threat.

