Protect.Computer
NEWS

LockBit Claims U.S. Bank Data Theft — Bank Blames Fourth Party

· 1 min read · Data hijack Got hacked
LockBit Claims U.S. Bank Data Theft — Bank Blames Fourth Party

LockBit ransomware listed U.S. Bancorp — the 7th largest bank in the United States — on its leak site Thursday morning, threatening to publish stolen data within two weeks. U.S. Bank’s parent company investigated the claim and traced it back not to a breach of its own systems, but to what it called a “fourth-party event”: a cyber incident at a contractor hired by one of U.S. Bancorp’s own third-party vendors. “At this time, there is no evidence that our systems, networks or data repositories were compromised,” a spokesperson told Recorded Future News. The bank said it has shared information with law enforcement and is monitoring the situation. LockBit did not release any data samples to back up its claim.

The distinction between a third-party and a fourth-party breach matters to customers: it means U.S. Bank’s own infrastructure was not touched, but data the bank shared with external partners may still have been exposed somewhere down the supply chain. The bank declined to name either the third or fourth party involved, so it is not yet possible to say what types of data may be at risk or how many people are affected. LockBit has struggled since a major law enforcement takedown in early 2024 and has had difficulty sustaining operations, but continues to list victims on a rebuilt site. U.S. Bancorp is the second major bank added to a ransomware leak site this week.

Sources

Related reading