-
LockBit 5.0 added US Bank to its dark web leak site and gave it about 14 days to pay.
-
US Bank says it found no proof of a break in, but it is still checking the claim closely.
-
Cybersecurity trackers gave different leak dates, and one flagged a separate suspicious server tied to over 20 banks.

A hacking group called LockBit 5.0 says it broke into US Bank and stole company data. The gang posted the bank’s name on its dark web leak site late Wednesday.
It gave the bank close to 14 days to pay up before it leaked the files. US Bank has not confirmed that a break in took place. The bank says it is looking into the matter with care.
LockBit Sets a Countdown for US Bank
The Register reported that LockBit listed US Bank on its leak page late Wednesday night. The gang set a deadline of September 3 for its extortion demand. If US Bank does not pay, LockBit says it will release the data it claims to hold.
The leak post did not say how much data the group took. It also gave no details about what kind of files were grabbed. Because there is no public proof yet, the claim cannot be confirmed.
Cybersecurity watchers on X also picked up the story. One tracking account on X listed US Bank as a fresh LockBit target too. The security analyst’s account pointed to a September 4 cutoff instead, a day later than The Register’s report. This small gap between the two dates is a reminder to treat each date as a claim for now, not a fact.
The Bank Responds, Finds No Sign of a Break In
US Bank spoke to The Register through Lee Henderson, its vice president of public affairs. Henderson said the bank knows about the claims and is looking into a possible cyber incident.
The bank chose not to answer harder questions. It would not say if it had spoken with the hackers. It also would not say how much money LockBit wants.
Henderson added that nothing so far points to trouble inside the bank’s own systems. The bank has not found proof that someone broke into its network without permission. Still, the bank says it will keep watching the claims closely. It also said it is taking steps to lower any risk from cyber threats.
Even without solid proof, a claim like this can hurt a company’s name. Customers and partners may grow uneasy while the bank works through its review. Banks handle money and personal records every day, so any hint of a breach draws fast attention from regulators, customers, and the media alike.
A Separate Server Raises New Questions
A cybersecurity researcher who goes by CRK shared new findings on X. CRK said researchers had been watching a suspicious server for close to two months. That server appeared able to send harmful payloads toward more than 20 financial companies.
CRK was careful to note that this activity has not been tied to ransomware yet. There is also no public evidence linking that server to the alleged US Bank case. The two stories are separate for now.
This claim lands as LockBit works under its newer 5.0 setup. Police in several countries dealt the group a hard blow back in February 2024. That operation seized servers, took down key parts of LockBit’s setup, and grabbed decryption keys. Officers later named the person they believe ran the operation. Even with all that pressure, LockBit came back with its 5.0 version in 2025.
Leak threats like this one remain a favorite tool for the group. Stealing files and threatening to post them costs less effort than locking up every computer with encryption. Even before hackers prove they stole anything, the mere threat can rattle a company and its customers.
Right now, the true state of the alleged US Bank case stays unclear. The bank says its systems show no sign of a break-in. LockBit still insists it holds stolen files. Until LockBit shows real proof, or the bank confirms an actual breach, this should be treated as an unverified claim.
The September deadline could bring real answers soon, especially if LockBit posts files it says belong to US Bank. Until that date arrives, customers and security teams alike will be watching closely while the bank finishes its review.
A similar pattern of unverified bank breach claims has emerged in India. In June 2026, a threat actor reposted and distributed an alleged Federal Bank customer dataset, claiming it contained approximately 637,895 records with highly sensitive personally identifiable information including PAN numbers, Aadhaar/UID identifiers, passport numbers, and driving license details. However, cybersecurity researchers have not independently verified the authenticity of the dataset or whether it directly originated from Federal Bank systems.
For now, the safest move for anyone connected to US Bank is to stay alert, watch official updates, and avoid drawing conclusions before facts are confirmed.