Security2 publishersIndependently confirmed3 min readPublished Updated
U.S. Bank's answer to LockBit: the breach happened two tiers out
The bank says its own systems are clean and points at a contractor of a contractor it will not name. That is precisely where most vendor-risk programs stop looking.
The Watch · Security desk

What happened
- LockBit added U.S. Bancorp to its victim list on Thursday morning and said it would leak data in two weeks.
- The bank says it investigated and traced the claims to a potential incident at a fourth party, outside its own environment.
- The gang posted no sample data to back the listing.
- It is the second bank on a ransomware leak site this week, after Cameroon's Credit Communautaire d'Afrique was listed by a different group.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint With neither the third nor the fourth party named, no other institution buying through the same chain can check whether it is in the same pool of exposed data.
- exposure If records were taken, the duty to identify and notify affected people rests with a company the public cannot name, while the bank's brand absorbs the headline.
- contradiction A listing with no samples against a denial scoped to the bank's own estate gives outsiders no way to test either side, so both can stand unchallenged for two weeks.
- precedent Naming a large bank on the strength of an incident two tiers out is cheap leverage for a degraded crew, and it invites more listings that the named company can truthfully deny.
The wording that matters is "systems, networks or data repositories," which is what U.S. Bancorp's spokesperson told Recorded Future News had shown no evidence of compromise [3]. All three can be true and clean while records sit inside an archive that belongs to neither the bank nor the supplier it pays. The bank's first response was narrower still: no indication its systems were impacted, no evidence of unauthorized access to its network [5]. Neither statement is about where the data was actually held.
That distance is one contract removed from the one the bank signed. Questionnaires, attestations and audit rights travel along contracts, and the entity the bank describes as the source of the potential incident was hired by the party it contracted with, not by the bank [1]. What the bank says it will do now is monitor the claims and stay vigilant about data exposure [9]. That is the available option when you hold neither the agreement nor the logs, and it is roughly the option every other customer of that same unnamed chain has today.
There is also less information in a leak-site listing than there used to be. The U.S. Treasury Department said in December that LockBit collected $252.4 million across 353 successful attacks between 2022 and 2024 [13], which works out to about $715,000 per successful attack [16]. That is a volume business, and its leverage rested on the assumption that a name on the wall meant a real intrusion by the group that posted it. After the multi-country takedown in 2024 [7] and earlier leaks of the source code that let unrelated criminals attack under the same name, including against organizations in Russia where its leaders are allegedly based [12], the badge identifies a toolset rather than an operator.
Set that against the target. U.S. Bancorp is the seventh largest bank in the United States and reported $7.7 billion last quarter [10]. For an operation that has repeatedly tried to restart and keeps running into operational trouble tied to law enforcement pressure [8], a bank of that size on the victim list is worth more in attention than the average payout is in cash [16], and it costs nothing to post if the data came from someone four tiers down the chain.
The sequence is the part worth keeping. Going by the order in the reporting, the bank located the fourth-party event after the gang's post forced it to go looking [15]. A criminal advertisement is a discovery channel, and it is the one that produced the answer here. Any inventory that lists only direct suppliers will keep producing that same sequence: a denial that is accurate about the network, followed by a trace outward to a company the bank cannot name and did not choose.
What to watch
- Whether any data appears at the two-week deadline, and whether it contains bank customer records or only the unnamed contractor's own files.
- Whether the third or fourth party identifies itself, through a breach notification, a regulator filing, or another customer's disclosure.
- Whether other financial institutions sharing that supply chain report related exposure, which would show the incident was never bank-specific.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives60
- Confidence50
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
U.S. Bancorp said recent claims of data theft by a ransomware gang are related to a breach involving a contractor for a third party, and do not impact its own systems or network.
ReportedSupportedSource: U.S. Bancorp, via Recorded Future News2 sources— create a free account to open themView cited source - [2]
A U.S. Bancorp spokesperson told Recorded Future News the company investigated the claims and traced them back to "a potential cyber incident...related to a fourth party event that occurred outside" its environment.
ReportedSupportedSource: U.S. Bancorp spokesperson2 sources— create a free account to open themView cited source - [3]
The spokesperson said: "At this time, there is no evidence that our systems, networks or data repositories were compromised," and that relevant information was provided to law enforcement.
ReportedSupportedSource: U.S. Bancorp spokesperson2 sources— create a free account to open themView cited source - [4]
The claims emerged Thursday morning, when the LockBit ransomware gang added U.S. Bancorp to its list of victims and threatened to leak data in two weeks.
- [5]
U.S. Bancorp initially told Recorded Future News there was no indication the bank's systems were impacted and no evidence of unauthorized access to its network.
- [6]
The company declined to name the third and fourth party at the source of the breach.
- [7]
LockBit was one of the most active and destructive ransomware groups for years before law enforcement agencies in multiple countries coordinated on a takedown in 2024.
- [8]
LockBit has repeatedly tried to revive its operation but has faced operational issues and other problems tied to increased law enforcement action.
- [9]
U.S. Bancorp said it will continue to monitor the claims and remain vigilant about data exposure.
- [10]
U.S. Bancorp is the 7th largest bank in the United States and reported $7.7 billion last quarter.
- [11]
LockBit did not provide any samples of the stolen information to legitimize its claims.
- [12]
Past leaks of the LockBit ransomware source code have allowed an array of other cybercriminals to use LockBit in attacks, even on organizations in Russia, where its leaders are allegedly based.
- [13]
In December, the U.S. Treasury Department said LockBit earned $252.4 million in ransoms through 353 successful attacks from 2022 to 2024.
- [14]
U.S. Bancorp is the second bank added to a ransomware leak site this week, after Cameroon's Credit Communautaire d'Afrique Bank was listed by another group on Friday; that bank reported operational issues two weeks earlier.
- [15]
On the reported sequence of events, the gang's leak-site listing preceded U.S. Bancorp's investigation and its trace to the fourth-party incident.
- [16]
LockBit's reported takings average about $715,000 per successful attack.
Sources
2 independent publishers whose own reporting we read for this story.
- scworld.comUS Bank investigates LockBit ransomware claims of data breach
1 article · August 21, 2026
- therecord.mediaU.S. Bank says breach claims related to fourth-party incident
1 article · August 21, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.