SECURITY Signal 400
LockBit claims US Bank breach, sets September 3 pay-or-leak deadline
US Bank is investigating LockBit's claim that it breached the bank and stole data, with the ransomware group threatening to leak the data on September 3 unless a ransom is paid.
The incident highlights the ongoing threat from LockBit, which reemerged with a new variant in September 2025 after a 2024 law enforcement takedown. Even if US Bank pays, there's no guarantee the data will be deleted, as past LockBit operations retained victim data after payment. The bank says there's no evidence of unauthorized access, but the investigation is ongoing.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
LockBit added US Bank to its leak site and gave the bank 14 days to pay or have data leaked on September 3.
US Bank says it is investigating the claims and has found no evidence of unauthorized access to its network.
Previous LockBit takedowns revealed that the group retained victim data even after ransoms were paid.
THE READ
What the cluster adds up to.
LockBit has publicly claimed a breach of US Bank and set a concrete deadline: pay by September 3 or see data leaked. US Bank acknowledges the claim and says it is investigating, but states there is no indication of internal system impact or unauthorized access. The bank declined to answer specific questions, including whether it has communicated with the extortionists or the ransom amount. This leaves the situation unresolved and the claim unverified.
If the claim is true, the bank faces significant costs: potential exposure of sensitive client and employee data, reputational damage, and possible legal action. Even paying the ransom does not ensure data deletion, as law enforcement found in 2024 that LockBit retained victim data after payments. The bank's statement emphasizes vigilance and monitoring, but the uncertainty around the data's fate remains a core risk.
LockBit's history adds context. In February 2024, international police seized servers and decryption keys, and in May 2024 they identified LockBitSupp as Dmitry Yuryevich Khoroshev, who remains at large. The group reemerged in September 2025 with LockBit 5.0, indicating resilience despite takedown efforts. This latest claim against US Bank follows that reemergence and shows the group's continued operational activity.
The bank's response is cautious, noting no evidence of unauthorized access while continuing to investigate. The leak site post does not specify how many files were allegedly stolen or their contents, adding to the ambiguity. This mirrors previous incidents where third-party breaches affected US Bank customers, including a 2022 incident affecting around 11,000 customers and a more recent one involving 537 Massachusetts residents. A law firm is considering a class-action lawsuit over the third-party incident, highlighting the legal exposure the bank faces.
The incident underscores the persistent challenge of ransomware: even when a victim investigates and finds no immediate impact, the threat of data exposure looms. The lack of guarantee that paying leads to deletion makes the decision to pay or not a difficult one. For engineers and security professionals, this case reinforces the importance of robust incident response and the need to assume that data may be compromised, regardless of initial findings.
Written by elseif from the cluster below · checked for specifics the sources never containedTHE CLUSTER