2026 U.S. Bank — LockBit leak-site claim; Sep 4 deadline, no sample (unverified)
Data compromised
Unknown — LockBit post cited by Cybernews/The Register did not include a data sample; employee vs customer scope not established
Technical writeup
Unverified ransomware leak-site claim with partial bank investigation context — August 2026 (Cybernews; The Register; The Record). LockBit listed U.S. Bank / U.S. Bancorp on its leak site with a countdown to approximately September 4, 2026 and did not publish a data sample. U.S. Bancorp told The Record it investigated the claims and traced them to a potential cyber incident involving a fourth-party event outside its environment, stating no evidence its own systems, networks, or data repositories were compromised; it notified law enforcement. The bank did not name the third/fourth parties or confirm customer data theft at indexing. recordsAffected 0 — no actor or company census.
Root cause
Unverified LockBit leak-site listing claiming U.S. Bank compromise with September 4, 2026 leak deadline; no data sample published; bank reportedly investigating