U.S. Bank is investigating a LockBit leak-site listing, not a confirmed theft of bank systems. The Register (updated August 21, 2026) reported that LockBit added the bank late Wednesday, August 19, with a 14-day pay-or-leak clock toward September 3, 2026. The leak post did not say how many files were taken or what they contained.
Lee Henderson, VP of public affairs, told The Register the investigation points to a fourth-party event outside our environment, with no evidence that U.S. Bank systems, networks, or data repositories were compromised. The bank said it gave relevant information to law enforcement. The Record reported the same line: a contractor in a third-party chain; the bank declined to name those vendors; LockBit did not publish samples. Do not write “U.S. Bank was breached” from this listing alone.
This is not a duplicate of our national banks MFA scorecard or major U.S. banks email-security listicle. Those posts grade login methods and public domain posture. They do not cover this LockBit claim. It is also not the same story as ExfilSquad’s unverified name-dump.
Customers should still treat unexpected “your files leaked — sign in here” mail as hostile. Type usbank.com / onlinebanking.usbank.com yourself.

Snapshot
| Field | Detail |
|---|---|
| Organization | U.S. Bank / U.S. Bancorp |
| Domains | usbank.com (brand) · onlinebanking.usbank.com (login) · usbancorp.com |
| Trigger | LockBit leak-site listing (~Aug 19–20, 2026) |
| Bank position | Fourth-party, outside its environment; no evidence of a bank-systems hit |
| Confirmed dump | No — no file count, no public samples as of Aug 24 |
| Deadline claimed | September 3, 2026 (attacker clock) |
What the listing claims vs what the bank has said
GalaxyWarden logged an unconfirmed usbank.com listing by Lockbit5 on August 20, 2026. The attacker write-up described a password field and did not list SSN, date of birth, or driver’s license among the fields it described. Treat that as attacker marketing, not a validated file inventory.
| Source | What it establishes |
|---|---|
| LockBit leak site | A listing and a countdown — not proof of bank-held files |
| U.S. Bank (Henderson) | Fourth-party event outside the bank; no evidence of systems/network/repo compromise |
| GalaxyWarden | Tracker record of the claim; unverified |
| SEC Item 1.05 | No matching 8-K found for this listing as of Aug 24 |
LockBit 5.0 reappeared in September 2025 after the 2024 law-enforcement takedown (LockBitSupp / Dmitry Yuryevich Khoroshev remains at large). A listing after a revival is still a claim.
This is not the May–June FIS notices, and not the 2022 mishare
Keep three events on three lines. The bank has not named the fourth-party chain for this LockBit listing. Do not assume it is FIS.
| When | What | Scope | vs this listing |
|---|---|---|---|
| May–June 2026 | FIS vendor notices (names, addresses, card numbers) | 537 MA customers | Separate |
| 2022 | Vendor mishare of closed card accounts | ~11,000 customers | Separate |
| Aug 19–21, 2026 | LockBit listing + fourth-party statement | Unverified; no samples | This post |
The Register also noted a law firm considering a class action over the FIS notices (names, mailing addresses, and card numbers; SSNs / online-banking credentials / balances reportedly not accessed). The 2022 mishare included SSNs and dates of birth on closed accounts. CourtListener RECAP as of August 24, 2026 found no docket that matches this LockBit listing (see below).

What customers should do
- Type usbank.com or onlinebanking.usbank.com — do not click a mail button that says “view leaked files” or “confirm your account after LockBit.”
- Enroll a passkey in online banking if the Login preferences card is available. Passkeys are not yet on the Mobile App. A password is still allowed.
- Treat SMS one-time codes as weak. They remain the documented two-step method. Lock the mobile number (carrier PIN / port freeze).
- Watch for lookalikes such as
usbanklogin.com(phishing-host pattern) and hyphen traps likeus-bancorp.com. - Nobody legitimate will ask you to pay a ransomware crew, or to “verify” a leak on a page they emailed you.
MFA: passkeys yes; YubiKey and Google Authenticator are not documented
U.S. Bank documents two-step verification as a one-time passcode to your mobile number (KB0069343). It can be toggled, but the bank says it cannot be completely stopped. The Passkey page covers online banking passkeys (rolled out gradually; not on the Mobile App). Two-step can still run with a passkey. Password login remains available.
Docs rechecked August 24, 2026: YubiKey / FIDO security keys and Google Authenticator / open TOTP are not documented. Directory grade stays Fail. Passkeys do not promote Fail→Pass/Strong while SMS OTP remains the documented second factor. Same rule as the national banks MFA scorecard.
| Method | On U.S. Bank docs | Grade impact |
|---|---|---|
| OTP to mobile (SMS) | Documented two-step | Fail (SIM-swap path) |
| Passkeys | Yes — web, not Mobile App | Tracked; does not promote |
| YubiKey / FIDO key | Not documented | No Strong path |
| Google Authenticator / open TOTP | Not documented | No Pass path |
CISA still recommends phishing-resistant MFA (More than a Password). That is guidance, not a claim that U.S. Bank already offers a consumer YubiKey.
Recommended MFA tools
| Product | Best for | Get it |
|---|---|---|
| YubiKey 5C NFC | USB-C laptops + NFC phones | Amazon |
| YubiKey 5 NFC | USB-A desktops + NFC phones | Amazon |
| YubiKey 5 / 5C NFC case | Keychain protection for the key | Amazon |
| Proton Pass | Passkeys + authenticator-style TOTP vault | Proton Pass |
We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Independent cybersecurity audits
We audited brand, login, parent, ticker-style, and the prior FIS vendor host on August 24, 2026. 100% is the ideal. None reach it. These scores are public email / transport / website posture. They do not prove or disprove the LockBit claim.
| Organization | Domain | Overall | vs 100% |
|---|---|---|---|
| U.S. Bank | usbank.com | 68% | −32 |
| U.S. Bancorp | usbancorp.com | 62% | −38 |
| USB short host | usb.com | 63% | −37 |
| Online banking | onlinebanking.usbank.com | 34% | −66 |
| FIS (prior vendor) | fisglobal.com | 87% | −13 |
| Domain | Identity | Transport | Website |
|---|---|---|---|
| usbank.com | 90% | 15% | 37% |
| usbancorp.com | 75% | 15% | 37% |
| usb.com | 75% | 15% | 40% |
| onlinebanking.usbank.com | 0% | 45% | 40% |
| fisglobal.com | 90% | 40% | 95% |
How to read this: usbank.com is Above Average (68%) with a familiar 15% transport gap (MTA-STS / related). Identity 0% on onlinebanking.usbank.com is a no-MX login-host pattern — not a reason to follow a lookalike. usb.com had no MX/web IPs in the blacklist probe; treat it as a short host we still scored, not as the customer login. fisglobal.com is here because of the separate May–June notices — not because the bank named FIS as this LockBit fourth party.
Audit links: usbank.com · usbancorp.com · usb.com · onlinebanking.usbank.com · fisglobal.com

Website stack note
Passive website-tech probes on August 24, 2026:
| Domain | Stack signal |
|---|---|
| usbank.com / usbancorp.com | Stack undetected; DigiCert TLS (into 2027) |
| onlinebanking.usbank.com | Stack undetected; DigiCert TLS; HTTP→HTTPS redirect not confirmed on the probe |
| usb.com | Stack undetected; HTTP→HTTPS redirect not confirmed |
| fisglobal.com | ASP.NET; Sectigo TLS (into 2027) |
Point-in-time only. An undetected CMS or a vendor ASP.NET flag is not proof of this leak-site claim.
Blacklist, lookalikes, CourtListener
Email blacklist checks (public DoH, August 24, 2026): usbank.com, usbancorp.com, and onlinebanking.usbank.com were clear. usb.com returned no_ips (no MX/web addresses in the probe). fisglobal.com showed UCEPROTECT L2/L3 on shared Proofpoint MX IPs — low-signal provider noise. Do not lead as “FIS is blacklisted.”
DNS lookalike scan of usbank.com (BEC profile, registered signals): 77 to review, 4 likely owned pointing at the brand (usbank.biz / .info / .net / .org CNAME to U.S. Bank hosts), 0 BEC staging. usbancorp.com: 9 to review, 0 likely owned, 1 BEC staging.
| Lookalike | Technique | Note |
|---|---|---|
| usbanklogin.com | phishing-host | Registered (NS, A, MX) — type the official login yourself |
| us-bancorp.com | hyphenation | BEC staging (NS, MX) on the parent-brand scan |
| usbank.biz / .info / .net / .org | tld-swap | Likely owned (CNAME to U.S. Bank) |
| iusbank.com / usbankk.com | insertion / duplication | Registered — investigate, not proof of LockBit |
Monitor lookalikes with Cybersquat Domain Monitoring. A listing week is when fake “leak portal” and “secure your account” hosts get registered.
CourtListener RECAP (August 24, 2026): LockBit + U.S. Bank / Bancorp filed after 2026-08-01 — 0 dockets. Party “U.S. Bank National Association” with LockBit / ransomware / data-breach keywords after that date — 0. Texas Southern / Western and District of Minnesota keyword scan after 2026-08-01 — 0 matching this listing. A case_name “Data Breach” net hit In Re Instructure (D. Utah) — unrelated. No federal docket matches this LockBit claim as of this writing.
Related coverage
- National banks MFA — SMS vs YubiKey & authenticator apps
- Major U.S. banks email security
- Minnesota banks email security
- MFA support directory
- ExfilSquad unverified claims
- Ransomware threat landscape — public victim trackers
- Beazley Q2 2026 — stolen credentials still start most ransomware
Run a free audit at audit.emailmenow.com or contact EmailMeNow for DMARC / MTA-STS and MFA baselines aimed at the 100% ideal.
Sources: The Register, Aug 20–21, 2026 · The Record / Recorded Future News · GalaxyWarden — usbank.com Lockbit5 listing · GalaxyWarden — Lockbit5 tracker · U.S. Bank two-step verification · Passkeys. Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches August 24, 2026. Domain scores: audit.emailmenow.com only.