U.S. Bancorp says its review of U.S. Bank LockBit claims points to a potential cyber incident involving a contractor for one of the bank’s third parties, rather than a compromise of the bank’s own environment. LockBit has alleged it stole data from the company, but the group has not published samples that would substantiate that claim.
A U.S. Bancorp spokesperson told Recorded Future News that the potential incident occurred outside the bank’s environment. The bank said it has found no evidence that its systems, networks or data repositories were compromised.
The distinction is narrow but material: the ransomware group’s assertion remains unverified, while the bank’s account describes a possible issue further down its supplier chain. U.S. Bancorp declined to identify either the third party or the contractor involved.
What did U.S. Bank say about the LockBit claims?
The bank said it investigated the allegation and provided relevant information to law enforcement, according to Recorded Future News. It said it would continue to support the investigation, monitor the claims and watch for possible data exposure.
Earlier, U.S. Bank told The Register it was aware of the claim and investigating it. At that point, the bank said it had no indication its internal systems were affected and no evidence of unauthorized access to its network.
In the reported case, the potential incident involved a contractor serving one of U.S. Bancorp’s third parties. The bank has not publicly named those companies or said that its own systems, networks or data repositories were breached.
What evidence has LockBit provided?
LockBit added U.S. Bancorp to its leak site and threatened to publish data after a two-week deadline, Recorded Future News reported. The group did not provide examples of the data it says it obtained. The Register separately reported that the leak-site post did not describe the alleged files’ volume or contents.
That leaves no public evidence in the reporting that independently verifies either that data was taken or what information, if any, may be involved.
Separate from an earlier customer-data incident
The current allegation should not be treated as the same event as an earlier third-party incident involving some U.S. Bank customer credit-card information. The Register reported that event separately, and the available reporting does not establish a connection between it and LockBit’s latest claim.
LockBit was disrupted in a multinational law-enforcement operation in 2024, according to Recorded Future News, and has since attempted to resume operations. Its listing of U.S. Bancorp and threat to release data establish the group’s allegation, not proof of a breach of the bank.
For now, the confirmed public position is limited: U.S. Bancorp says it traced the claim to a potential incident involving a contractor for a third party, outside the bank’s environment, and says it has no evidence its own systems or data repositories were compromised.
This story draws on original reporting from The Record.