HackMyIP
← Back to News
2026-08-21 The Record

U.S. Bancorp Says LockBit Breach Claims Stem from Fourth-Party Incident

RansomwareData BreachSupply Chain

U.S. Bancorp, the seventh-largest bank in the United States, confirmed this week that recent ransomware claims by the LockBit gang are tied to a fourth-party cyber incident rather than a direct breach of its own systems. A spokesperson told Recorded Future News that the company investigated the claims after LockBit added U.S. Bancorp to its victim list on Thursday and threatened to leak stolen data within two weeks. "At this time, there is no evidence that our systems, networks or data repositories were compromised," the spokesperson said, adding that U.S. Bancorp has provided relevant information to law enforcement and is actively supporting their investigation.

The breach originates from a contractor working with a third-party vendor in U.S. Bancorp's extended supply chain, underscoring the growing risk of fourth-party exposures for large financial institutions. LockBit has not published any sample data to validate its claims, and U.S. Bancorp has declined to name either the third or fourth party at the source of the incident. Organizations concerned about exposure from cascading supply chain incidents can run an email breach checker to determine whether credentials tied to their domains appear in known leaks, while security teams can use a SSL/TLS checker to verify the certificate posture of the vendors and partners they rely on.

LockBit was one of the most active and destructive ransomware operations before a coordinated international takedown in 2024 disrupted its infrastructure. The U.S. Treasury Department reported in December that the group extorted approximately $252.4 million through 353 successful attacks between 2022 and 2024. Despite repeated attempts to revive operations—including through leaked source code that has allowed affiliates to deploy variants, even against Russian organizations—the group has struggled with operational issues and continued law enforcement pressure. U.S. Bancorp is the second bank added to a ransomware leak site this week, following Cameroon's Crédit Communautaire d'Afrique Bank, which was listed by another group after reporting operational issues two weeks ago. For individuals and businesses monitoring their own exposure amid rising third- and fourth-party risk, performing a regular privacy checkup can help identify where personal data may be vulnerable across service providers and online accounts.

Source: The Record →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →