BTC$84,744-0.06% LTC$70.31+4.13% XMR$539.16-1.74%
TorPortal TorPortalMarkets, mirrors, dark web news
The Record · Aug 21, 2026 · 2 min read · Original story

U.S. Bank says breach claims related to fourth-party incident

U.S. Bank says breach claims related to fourth-party incident
U.S. Bank says breach claims related to fourth-party incident

U.S. Bancorp said recent claims of data theft by a ransomware gang are related to a breach involving a contractor for a third-party, and do not impact its own systems or network.

A spokesperson told Recorded Future News that U.S. Bancorp has investigated the claims and traced it back to “a potential cyber incident…related to a fourth party event that occurred outside” of their environment.

“At this time, there is no evidence that our systems, networks or data repositories were compromised,” the spokesperson said. “We have provided relevant information to law enforcement and continue to support their investigation.”

The claims emerged on Thursday morning, when the LockBit ransomware gang added U.S. Bancorp to its list of victims and threatened to leak data in two weeks.

U.S. Bancorp initially told Recorded Future News that there was no indication the bank’s systems were impacted and no evidence of unauthorized access to their network.

The company declined to name the third and fourth party at the source of the breach. U.S. Bancorp said it will continue to monitor the claims and remain vigilant about data exposure.

U.S. Bancorp is the 7th largest bank in the United States and reported $7.7 billion last quarter.

LockBit did not provide any samples of the stolen information to legitimize their claims. Past leaks of the ransomware source code have allowed an array of other cybercriminals to use LockBit in attacks, even on organizations in Russia — where its leaders are allegedly based.

The ransomware gang was one of the most active and destructive groups for years before law enforcement agencies in multiple countries coordinated on a much-heralded takedown in 2024.

In December, the U.S. Treasury Department said LockBit earned $252.4 million in ransoms through 353 successful attacks from 2022 to 2024.

The group has repeatedly tried to revive its operation but has faced operational issues and other problems tied to increased law enforcement action.

U.S. Bancorp is the second bank added to a ransomware leak site this week after Cameroon’s Crédit Communautaire d'Afrique Bank was listed by another group on Friday. The bank reported operational issues two weeks ago.

References in this story

  1. Hackmanac (@H4ckmanac) on X x.com 🚨Cyber Alert ‼️ 🇺🇸United States - 𝗨𝗦 𝗕𝗮𝗻𝗸 LockBit 5.0 ransomware group claims to have breached US Bank. Threat actor: LockBit 5.0 Sector: Financial / Insurance Data exposure (claimed): Not specified Data type: Not…
  2. New hacker group uses LockBit ransomware variant to target Russian companies therecord.media In its latest campaign this spring, DarkGaboon was observed deploying LockBit 3.0 ransomware against victims in Russia, Positive Technologies said in a report last week.
  3. LockbitSupp identified as Dmitry Khoroshev and indicted for ransomware crimes therecord.media Dmitry Yuryevich Khoroshev, a 31-year-old Russian national, ran the LockBit ransomware gang under the alias LockbitSupp, said authorities from the U.S., U.K. and Australia.
  4. LockBit ransomware gang disrupted by international law enforcement operation therecord.media LockBit — the most prolific ransomware group in the world — had its website seized Monday as part of an international law enforcement operation that involved the U.K.’s National Crime Agency, the FBI, Europol and…
  5. More than $2 billion in payments from 4,000 ransomware incidents reported to Treasury in recent years therecord.media The Financial Crimes Enforcement Network (FinCEN) released a study covering 4,194 ransomware incidents that were reported through the Bank Secrecy Act over the three-year period.
  6. LockBit ransomware gang attempts to relaunch its services following takedown therecord.media There's a new extortion site on the dark web displaying a handful of apparent victims of the cybercrime operation. It does not show any listings from before the takedown.
  7. LockBit takedown: Police shut more than 14,000 accounts on Mega, Tutanota and Protonmail therecord.media Accounts with third-party service providers were used “for exfiltration or infrastructure,” according to a post by law enforcement on LockBit’s seized darkweb domain.
  8. Comparitech (@Comparitech) on X x.com 🚨CCA-Bank 🇨🇲 has been added to the data leak site of ransomware gang Everest. 19.04 GB allegedly stolen. The Cameroonian bank said it was experiencing a technical incident on August 7, 2026. It caused a temporary outage…
  9. Error www.facebook.com
  10. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  11. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  12. jon greig (@jgreigj) on X twitter.com @TheRecord_Media cybersecurity reporter. formerly @zdnet @cambodiadaily @haitiantimes_ — send tips to [email protected] or signal: jgreig.51
  13. jon greig (@jgreig.bsky.social) bsky.app cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to [email protected] or signal: jgreig.51

← Back to all news