Fidelity National Information Services: US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline

Fidelity National Information Services: US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline

LockBit Claims Breach of US Bank, Threatens Data Leak by September 3

US Bank is investigating claims by the ransomware group LockBit that it breached the financial institution and exfiltrated data, which the cybercriminals threaten to leak on September 3 unless a ransom is paid. In a statement to The Register, US Bank VP of public affairs Lee Henderson acknowledged awareness of the claims but declined to confirm details, including whether the bank has engaged with the extortionists or the amount demanded.

The bank stated there is currently no evidence of unauthorized access to its internal systems or network, emphasizing its commitment to security and ongoing investigation. LockBit added US Bank to its leak site late Wednesday, giving a 14-day deadline for payment but did not disclose the volume or nature of the allegedly stolen data.

LockBit, one of the most prolific ransomware operations, was disrupted in February 2024 when law enforcement seized its infrastructure and exposed the identity of its leader, Russian national Dmitry Yuryevich Khoroshev. Despite the takedown, the group resurfaced in September 2025 with a new ransomware variant, LockBit 5.0.

This incident follows previous third-party breaches affecting US Bank customers. In May 2024, the bank discovered a vendor-related security lapse at Fidelity National Information Services, exposing the credit card details of 537 Massachusetts residents. A separate 2022 breach, involving a different vendor, compromised personal data including Social Security numbers of approximately 11,000 customers. US Bank has faced legal scrutiny over these incidents, with at least one law firm considering a class-action lawsuit.

Source: https://www.theregister.com/security/2026/08/20/us-bank-investigates-lockbits-claims-as-ransomware-crims-set-pay-or-leak-deadline/5290560

Fidelity National Information Services TPRM report: https://www.rankiteo.com/company/fidelity-bank

"id": "fid1787250317",
"linkid": "fidelity-bank",
"type": "Breach",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Banking',
                        'location': 'United States',
                        'name': 'US Bank',
                        'type': 'Financial Institution'}],
 'data_breach': {'data_exfiltration': True,
                 'personally_identifiable_information': True},
 'description': 'US Bank is investigating claims by the ransomware group '
                'LockBit that it breached the financial institution and '
                'exfiltrated data, which the cybercriminals threaten to leak '
                'on September 3 unless a ransom is paid.',
 'impact': {'brand_reputation_impact': True,
            'data_compromised': True,
            'identity_theft_risk': True,
            'legal_liabilities': True,
            'payment_information_risk': True},
 'investigation_status': 'Ongoing',
 'motivation': 'Extortion',
 'ransomware': {'data_exfiltration': True, 'ransomware_strain': 'LockBit 5.0'},
 'references': [{'source': 'The Register'}],
 'regulatory_compliance': {'legal_actions': 'Class-action lawsuit considered'},
 'response': {'communication_strategy': 'Public statement acknowledging '
                                        'awareness of claims',
              'incident_response_plan_activated': True},
 'threat_actor': 'LockBit',
 'title': 'LockBit Claims Breach of US Bank, Threatens Data Leak by September '
          '3',
 'type': 'Ransomware'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.