U.S. Bancorp Confirms Third-Party Breach After LockBit Ransomware Claims
Financial giant **U.S. Bancorp** has confirmed that recent claims of data theft by the **LockBit** ransomware gang stem from a breach involving a contractor for a third-party vendor, not its own internal systems. The bank assures customers and stakeholders that its core networks and data repositories remain uncompromised, with investigations ongoing and law enforcement notified.
On Thursday morning, the notorious **LockBit** ransomware gang added **U.S. Bancorp** to its list of victims, threatening to leak sensitive data within two weeks. This claim prompted an immediate investigation by the seventh-largest bank in the United States.
**U.S. Bancorp** has since clarified that while a cyber incident did occur, it was isolated to a "fourth-party event" outside of their direct environment. A spokesperson for **U.S. Bancorp** stated, "At this time, there is no evidence that our systems, networks or data repositories were compromised."
### The Supply Chain Vulnerability
The bank declined to name the specific third-party contractor or the fourth-party entity involved in the breach. This incident highlights the growing risks associated with complex supply chains and the ripple effect of cyberattacks on vendors and their downstream partners.
**U.S. Bancorp** has provided relevant information to law enforcement and continues to monitor the situation, emphasizing vigilance against potential data exposure.
### LockBit's Resurgence Attempts
**LockBit** was once considered one of the most prolific and destructive ransomware groups globally. However, an international law enforcement operation in early 2024 significantly disrupted its infrastructure and activities. Despite these setbacks, the group has repeatedly attempted to revive its operations, often facing technical difficulties and increased scrutiny.
Prior to the takedown, the U.S. Treasury Department reported that **LockBit** extorted approximately $252.4 million from 353 successful attacks between 2022 and 2024. The group's source code has also been leaked, enabling other cybercriminals to leverage **LockBit**'s tools, even against organizations in Russia, where its alleged leaders are based.
This incident with **U.S. Bancorp** marks the second bank to appear on a ransomware leak site this week, following a separate attack on Cameroon's **CrΓ©dit Communautaire d'Afrique Bank**.