Published · 3d agoSecurity3 min read
U.S. Bank's answer to LockBit: the breach happened two tiers out
The bank says its own systems are clean and points at a contractor of a contractor it will not name. That is precisely where most vendor-risk programs stop looking.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- U.S. Bancorp said recent claims of data theft by a ransomware gang are related to a breach involving a contractor for a third party, and do not impact its own systems or network.
- A U.S. Bancorp spokesperson told Recorded Future News the company investigated the claims and traced them back to "a potential cyber incident...related to a fourth party event that occurred outside" its environment.
- The spokesperson said: "At this time, there is no evidence that our systems, networks or data repositories were compromised," and that relevant information was provided to law enforcement.
- The claims emerged Thursday morning, when the LockBit ransomware gang added U.S. Bancorp to its list of victims and threatened to leak data in two weeks.
- U.S. Bancorp initially told Recorded Future News there was no indication the bank's systems were impacted and no evidence of unauthorized access to its network.
Compiled by The WatchSomething wrong?How this is made
Why it matters
The wording that matters is "systems, networks or data repositories," which is what U.S. Bancorp's spokesperson told Recorded Future News had shown no evidence of compromise [3]. All three can be true and clean while records sit inside an archive that belongs to neither the bank nor the supplier it pays. The bank's first response was narrower still: no indication its systems were impacted, no evidence of unauthorized access to its network [5]. Neither statement is about where the data was actually held.
That distance is one contract removed from the one the bank signed. Questionnaires, attestations and audit rights travel along contracts, and the entity the bank describes as the source of the potential incident was hired by the party it contracted with, not by the bank [1]. What the bank says it will do now is monitor the claims and stay vigilant about data exposure [7]. That is the available option when you hold neither the agreement nor the logs, and it is roughly the option every other customer of that same unnamed chain has today.
There is also less information in a leak-site listing than there used to be. The U.S. Treasury Department said in December that LockBit collected $252.4 million across 353 successful attacks between 2022 and 2024 [12], which works out to about $715,000 per successful attack [15]. That is a volume business, and its leverage rested on the assumption that a name on the wall meant a real intrusion by the group that posted it. After the multi-country takedown in 2024 [11] and earlier leaks of the source code that let unrelated criminals attack under the same name, including against organizations in Russia where its leaders are allegedly based [10], the badge identifies a toolset rather than an operator.
Set that against the target. U.S. Bancorp is the seventh largest bank in the United States and reported $7.7 billion last quarter [8]. For an operation that has repeatedly tried to restart and keeps running into operational trouble tied to law enforcement pressure [13], a bank of that size on the victim list is worth more in attention than the average payout is in cash [15], and it costs nothing to post if the data came from someone four tiers down the chain.
The sequence is the part worth keeping. Going by the order in the reporting, the bank located the fourth-party event after the gang's post forced it to go looking [16]. A criminal advertisement is a discovery channel, and it is the one that produced the answer here. Any inventory that lists only direct suppliers will keep producing that same sequence: a denial that is accurate about the network, followed by a trace outward to a company the bank cannot name and did not choose.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
U.S. Bancorp said recent claims of data theft by a ransomware gang are related to a breach involving a contractor for a third party, and do not impact its own systems or network.
- [2]
A U.S. Bancorp spokesperson told Recorded Future News the company investigated the claims and traced them back to "a potential cyber incident...related to a fourth party event that occurred outside" its environment.
- [3]
The spokesperson said: "At this time, there is no evidence that our systems, networks or data repositories were compromised," and that relevant information was provided to law enforcement.
- [4]
The claims emerged Thursday morning, when the LockBit ransomware gang added U.S. Bancorp to its list of victims and threatened to leak data in two weeks.
ReportedView cited source - [5]
U.S. Bancorp initially told Recorded Future News there was no indication the bank's systems were impacted and no evidence of unauthorized access to its network.
ReportedView cited source - [6]
The company declined to name the third and fourth party at the source of the breach.
ReportedView cited source
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- scworld.comSC Staff3d agoUS Bank investigates LockBit ransomware claims of data breach
- therecord.media3d agoU.S. Bank says breach claims related to fourth-party incident
Additional citations
- U.S. Bancorp, via Recorded Future News
- U.S. Bancorp spokesperson
- U.S. Treasury Department


