LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp) — Threadlinqs Intelligence
As of 2026-08-21, LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp) is a high-severity ransomware threat attributed to LockBit (LockBitSupp (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 33 indicators of compromise.
Threat ID: TL-2026-2094 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: LockBit (LockBitSupp · Russia · FINANCIAL
LockBit 5.0 ransomware group claimed to have breached US Bank (U.S. Bancorp, the fifth-largest U.S. commercial bank) and exfiltrated sensitive data, adding the bank to its Tor-based data-leak site on
On August 19, 2026, the LockBit ransomware group operating its LockBit 5.0 variant added US Bank (U.S. Bancorp, NYSE: USB) to its Tor-based data-leak site, claiming a breach and exfiltration of sensitive data. The group imposed a 14-day extortion deadline of September 3, 2026, threatening to publish the allegedly stolen data if the ransom demand — the amount of which has not been disclosed — is not met. The incident was first reported by GBHackers on August 21, 2026, and covered by The Register on August 20, 2026. US Bank Vice President of Public Affairs Lee Henderson stated that the bank is aware of the claims and is investigating, but that 'at this time, there is no indication that our internal systems have been impacted, and there is no evidence of unauthorized access to our network.' No details regarding the volume, type, or nature of the allegedly exfiltrated data have been provided by LockBit.
US Bank is the fifth-largest commercial bank in the United States, headquartered in Minneapolis, Minnesota, with $692 billion in total assets (as of December 31, 2025), approximately 15 million clients ($13 million consumer, $1.4 million business), 2,075 branches across 26 states, and 70,000 employees. The bank operates four major business lines: Wealth, Corporate, Commercial and Institutional Banking; Consumer and Business Banking; Payment Services (including Elavon merchant processing); and Treasury and Corporate Support. The scale and systemic importance of US Bank makes it a high-value target for ransomware extortion, and any confirmed compromise would have far-reaching implications across the U.S. financial services sector, including potential downstream impacts on merchant processing, payment systems, and customer trust.
This is not the first extortion claim against US Bank. In March 2025, the Babuk2 ransomware group falsely claimed to have breached US Bank and 25 other companies, but cybersecurity researchers assessed the claim as bogus, determining the data was recycled from the Cl0p gang's MOVEit mass-exploitation campaign from 2023. Separately, in May 2026, US Bank began notifying 537 Massachusetts customers that their name, mailing address, and credit card number may have been exposed through a third-party service provider supporting the bank's vendor Fidelity National Information Services (FIS). That incident was not a direct breach of US Bank systems and did not involve Social Security numbers, online banking credentials, or account balances. The temporal proximity of the LockBit extortion claim to the FIS vendor incident raises the possibility of opportunistic extortion by LockBit based on publicly disclosed vendor exposure, a known tactic in the ransomware ecosystem.
LockBit 5.0 (internally codenamed 'ChuongDong') was announced in early September 2025 on the Russian-language cybercrime forum RAMP to mark the group's sixth anniversary, recruiting new affiliates. Check Point Research identified at least a dozen organizations hit by LockBit-branded ransomware within the first month of the 5.0 launch, spanning Western Europe, the Americas, and Asia. LockBit 5.0 is a multi-platform ransomware variant targeting Windows, Linux, and VMware ESXi environments. The Windows variant uses heavy obfuscation and packing, decrypting a PE binary in memory and loading it via DLL reflection techniques that significantly complicate static analysis. The variant incorporates multiple anti-analysis and evasion mechanisms: it patches the EtwEventWrite API with a 0xC3 (RET) instruction to disable Windows Event Tracing for Windows (ETW), terminates 63 security-related services by comparing CRC32-hashed service names against a hardcoded list, and clears event logs post-encryption using the EvtClearLog API. Encrypted files are appended with randomized 16-character hexadecimal file extensions, and the original file size is embedded in the encrypted file footer. The encryptor employs a hybrid encryption scheme using AES (per-file randomly gener
Weaknesses (CWE)
CWE-788, CWE-287, CWE-862, CWE-94, CWE-269, CWE-330, CWE-22
Target sectors: financial-services, banking
Target regions: North America
Timeline
- Operation Cronos: FBI, UK NCA, and international partners seize LockBit's public-facing websites, dark web infrastructure, and control servers; obtain decryption keys enabling hundreds of victims to recover encrypted data; seize StealBit platform; freeze over 200 cryptocurrency accounts. DOJ unseals indictments of Artur Sungatov and Ivan Kondratyev (Bassterlord).
- DOJ unseals indictment of Dmitry Yuryevich Khoroshev (aka LockBitSupp, putinkrab) as the alleged creator and administrator of LockBit ransomware. Treasury Department imposes sanctions. Khoroshev remains at large.
- Evolve Bank & Trust data breach: LockBit affiliate breaches the Arkansas-based bank via a phishing link, exfiltrating data on 7.6 million individuals including names, SSNs, and bank account numbers. LockBit mistakenly claims to have hacked the U.S. Federal Reserve.
- Babuk2 ransomware group falsely claims to have breached US Bank and 25 other organizations. Cybersecurity researchers assess the claim as bogus — the data is recycled from the Cl0p gang's MOVEit mass-exploitation campaign from 2023.
- LockBit's dark web affiliate panels are hacked and defaced with a taunting message ('Don't do crime CRIME IS BAD xoxo from Prague'). MySQL database dump from ~April 29, 2025 leaks 4,442 negotiation messages (Dec 2024–Apr 2025), 59,975 Bitcoin addresses, 75 admin/affiliate accounts with plaintext passwords, and build configurations.
- LockBit officially announces its return on the Russian-language cybercrime forum RAMP, unveiling LockBit 5.0 (internally codenamed 'ChuongDong') to mark the group's sixth anniversary, and begins recruiting new affiliates with a $500 BTC deposit requirement.
- Trend Micro publishes technical analysis of LockBit 5.0 confirming multi-platform support (Windows, Linux, ESXi), DLL reflection loading, ETW patching, 63 security service terminations, randomized 16-character hex file extensions, AES/RSA hybrid encryption, and Russian language geolocation checks.
- Check Point Research identifies at least a dozen organizations hit by LockBit-branded ransomware in September 2025, half infected with LockBit 5.0 and half with LockBit 3.0 (LockBit Black). Victims span Western Europe, the Americas, and Asia with ~65% targeting U.S. organizations.
- U.S. Bank is notified that a third-party service provider supporting its vendor Fidelity National Information Services (FIS) experienced a security incident. On May 19, 2026, US Bank confirms that certain customer credit-card data was impacted.
- US Bank begins mailing notification letters to 537 Massachusetts customers whose name, mailing address, and credit card number may have been exposed through the FIS vendor incident. Social Security numbers, online banking credentials, and account balances were not involved. Bank offers 12 months of complimentary credit monitoring.
- LockBit 5.0 ransomware group adds US Bank to its Tor-based data-leak site, claiming a breach and exfiltration of sensitive data, imposing a 14-day extortion deadline of September 3, 2026. No data volume, file types, or specific exfiltration details are disclosed.
- The Register publishes coverage of the LockBit extortion claim against US Bank. US Bank VP of Public Affairs Lee Henderson states the bank is aware of the claims and investigating but finds no evidence of unauthorized internal system access.
Related threats
- Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demands
- Q1 2026 Ransomware Landscape: Qilin Dominance, LockBit 5.0 Comeback, and FortiGate (CVE-2024-55591) / Oracle EBS (CVE-2025-61882) Mass Exploitation
- 2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)
- INC Ransom Affiliate Network Targeting Pacific Critical Infrastructure (AU/NZ/Tonga Joint Advisory)
- Black Basta Ransomware: Internal Chat Leaks Expose $100M+ RaaS Operation — Conti Successor Unmasked
- The Gentlemen Ransomware Operationalizes SystemBC SOCKS5 Botnet of 1,570+ Corporate Hosts for Double-Extortion Operations
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 33 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, CVE-2023-4966, CVE-2023-0669, CVE-2023-27350, CVE-2021-44228, CVE-2021-22986, CVE-2020-1472, CVE-2019-0708, CVE-2018-13379, T1190, T1566, T1133, T1078, T1059, T1569, T1053, T1543, T1548, T1685