LockBit 5.0 claims U.S. Bank breach
The LockBit 5.0 ransomware group has listed U.S. Bank as a victim, claiming access to tens of thousands of user credentials and internal data.
Ransomware.live's tracking indicates that the LockBit 5.0 operation added U.S. Bank, a major multinational financial institution, to its extortion leak site on 20 August 2026. The listing claims compromise of 18 employees, over 21,000 user accounts, and 56 third-party employee credentials, alongside enumeration of 109 external attack-surface assets.
The posted data largely consists of DNS, WHOIS, and SPF/TXT records for usbank.com, showing the bank's use of numerous third-party SaaS and security vendors (Proofpoint, DocuSign, Atlassian, MongoDB, Cisco Webex, OneTrust, and others). While this metadata does not itself constitute stolen data, its inclusion is typical of LockBit's practice of publishing reconnaissance details to substantiate an extortion claim and pressure the victim before or in lieu of releasing exfiltrated files.
No confirmation of the intrusion has been provided by U.S. Bank, and the claim remains unverified pending further disclosure. Given LockBit's history of high-impact attacks against large enterprises and the financial sector's sensitivity to credential and customer-data exposure, this listing warrants monitoring for follow-on data leaks or confirmation of compromise.
Mentioned in this report
Source reporting: https://www.ransomware.live/id/dXNiYW5rLmNvbUBsb2NrYml0NQ==
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free