US Bank claimed by hackers, posted on the dark web
Instead of a data sample, the attackers gave a deadline.

Image by Cybernews.
- LockBit claims it breached US Bank and set a September 4 deadline to leak data.
- The gang has not shared a data sample, so the exposed information remains unknown.
- US Bank is reportedly aware of the claim and is investigating the alleged breach.
- Researchers say exposed employee or customer data could enable fraud, identity theft, or attacks on bank systems.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
One of America’s largest financial institutions, US Bank, has been claimed by the notorious LockBit hacker gang. The cybercrooks gave the bank until early September before leaking the data.
LockBit claimed the bank earlier this week, uploading US Bank onto its dark web forum used to showcase the gang’s latest victims. At the same time, the attackers put a countdown clock on the post, indicating that the time runs out on September 4th.
LockBit and other ransomware gangs typically use deadlines as a scare tactic, threatening to leak victims' data if they don’t pay up.
However, the attacker did not include a data sample, making it impossible to know what types of details LockBit may have accessed. We have reached out to US Bank for comment and will update this article once we receive a reply.
Reportedly, US Bank is aware of hackers’ claims and is investigating the alleged data breach.
While it’s currently impossible to know what information attackers may have gotten their hands on, our researchers believe the US Bank data breach, if confirmed, may take several turns.
“The damage really depends on what type of data was exposed. They could either have infrastructure, employee information, or details that are related to customers,” our researchers said.
If employee data was exposed, attackers could use it to target the bank itself by obtaining access to sensitive systems and moving laterally within them. Eventually, that could lead to customer data getting exposed.
“Another possibility is that attackers accessed highly sensitive personal and financial operation data, which can be used for identity theft, financial fraud, and is also very monetizable on the dark web,” our team explained.
We asked the US Bank whether its customers should take any precautions, and we will update the article once we receive a reply.
Last year, the US Bank already had issues with exposed data. In June 2025, the bank contacted an unknown number of individuals about an unauthorized party accessing their personal details.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
At the time, “a technical configuration error” led to unauthorized parties accessing account numbers and personally identifiable information (PII).
Meanwhile, US Bank’s alleged attackers, LockBit, were once at the top of the ransomware food chain. However, in February 2024, authorities seized LockBit’s servers, domain infrastructure, and decryption keys, outing the gang’s leader at the same time.
However, the gang returned in September 2025 with a new fifth iteration of the malicious software used to target organizations and businesses.