US Bank is investigating LockBit’s claim that it stole data and may publish it. Here’s what customers should know, what remains unconfirmed, and how to protect their information online today.
Table of Contents
What Happened?
LockBit added US Bank to its leak site on August 19 and gave the bank 14 days to pay. The group says it will publish the stolen information on September 3 if no payment is made.
However, US Bank says it has found no evidence that criminals entered its internal network.
The bank also has not confirmed that LockBit stole any information. It has not shared details about a ransom demand or possible contact with the group.
LockBit is a ransomware group that steals information and demands money from victims. In some attacks, criminals threaten to publish stolen files if payment is refused.
If stolen data is eventually confirmed, it could create problems long after the investigation ends. Criminals often reuse personal information in phishing emails, fake calls, or identity theft attempts.
Your information may also have been leaked through other companies without you realizing it. Regular monitoring can help you find those problems sooner.
Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.
Who Could Be Affected and What Data Was Taken?
US Bank has not said whether any customers or employees were affected by the current LockBit incident.
LockBit also has not publicly revealed how many files it claims to have stolen or what those files contain.
That means there is currently no confirmed list of customer information connected to the LockBit claim.
A separate US Bank incident affected 537 Massachusetts customers earlier in 2026. That incident involved a third-party vendor and was not connected to the current LockBit claim.
In that earlier case, names, mailing addresses, and credit card numbers may have been stolen. Social Security numbers, banking login details, and balances were reportedly not affected.
US Bank also experienced a separate vendor-related incident in 2022 that affected around 11,000 customers.
Futureproof keeps your data safer with simple guidance to set a strong password, turn on 2-step verification, and lock down your account.
Check my safetyHow LockBit May Have Targeted US Bank
US Bank has not publicly explained how LockBit may have obtained the information it claims to possess.
The bank says it currently has no evidence of unauthorized access to its internal network. Because of that, the exact source of the claimed data remains unclear.
LockBit is known for ransomware attacks, but US Bank has not confirmed that ransomware entered its systems.
Without more information, it would be premature to say whether criminals used stolen passwords, malicious software, or another method.

At Futureproof, Kevin explains digital safety in simple words, with clear tips and zero fluff. He holds a degree in information technology and studies fraud trends to keep his tips up-to-date.
In his free time, Kevin plays with his cat, enjoys board-game nights, and hunts for New York’s best cinnamon rolls.
