Back to news
Cybersecurity Alert
August 24, 2026 by EmailMeNow IT Consulting

U.S. Bank Is Investigating a LockBit Claim — Bank Says Fourth-Party, Not Its Systems

U.S. Bank is investigating a LockBit leak-site claim. The bank says a fourth-party event outside its environment; no evidence its systems were hit. Audits (ideal 100%): usbank.com 68%. MFA: Fail (SMS OTP; no YubiKey/TOTP).

Source: The Register · GalaxyWarden · The Record

NewsBankingRansomwareData BreachMFAPhishingBECCybersecurity
Bank building silhouette at dusk with an unverified leak-site countdown overlay

U.S. Bank is investigating a LockBit leak-site listing, not a confirmed theft of bank systems. The Register (updated August 21, 2026) reported that LockBit added the bank late Wednesday, August 19, with a 14-day pay-or-leak clock toward September 3, 2026. The leak post did not say how many files were taken or what they contained.

Lee Henderson, VP of public affairs, told The Register the investigation points to a fourth-party event outside our environment, with no evidence that U.S. Bank systems, networks, or data repositories were compromised. The bank said it gave relevant information to law enforcement. The Record reported the same line: a contractor in a third-party chain; the bank declined to name those vendors; LockBit did not publish samples. Do not write “U.S. Bank was breached” from this listing alone.

This is not a duplicate of our national banks MFA scorecard or major U.S. banks email-security listicle. Those posts grade login methods and public domain posture. They do not cover this LockBit claim. It is also not the same story as ExfilSquad’s unverified name-dump.

Customers should still treat unexpected “your files leaked — sign in here” mail as hostile. Type usbank.com / onlinebanking.usbank.com yourself.

Bank building silhouette at dusk with an unverified leak-site countdown overlay

Snapshot

FieldDetail
OrganizationU.S. Bank / U.S. Bancorp
Domainsusbank.com (brand) · onlinebanking.usbank.com (login) · usbancorp.com
TriggerLockBit leak-site listing (~Aug 19–20, 2026)
Bank positionFourth-party, outside its environment; no evidence of a bank-systems hit
Confirmed dumpNo — no file count, no public samples as of Aug 24
Deadline claimedSeptember 3, 2026 (attacker clock)

What the listing claims vs what the bank has said

GalaxyWarden logged an unconfirmed usbank.com listing by Lockbit5 on August 20, 2026. The attacker write-up described a password field and did not list SSN, date of birth, or driver’s license among the fields it described. Treat that as attacker marketing, not a validated file inventory.

SourceWhat it establishes
LockBit leak siteA listing and a countdown — not proof of bank-held files
U.S. Bank (Henderson)Fourth-party event outside the bank; no evidence of systems/network/repo compromise
GalaxyWardenTracker record of the claim; unverified
SEC Item 1.05No matching 8-K found for this listing as of Aug 24

LockBit 5.0 reappeared in September 2025 after the 2024 law-enforcement takedown (LockBitSupp / Dmitry Yuryevich Khoroshev remains at large). A listing after a revival is still a claim.

This is not the May–June FIS notices, and not the 2022 mishare

Keep three events on three lines. The bank has not named the fourth-party chain for this LockBit listing. Do not assume it is FIS.

WhenWhatScopevs this listing
May–June 2026FIS vendor notices (names, addresses, card numbers)537 MA customersSeparate
2022Vendor mishare of closed card accounts~11,000 customersSeparate
Aug 19–21, 2026LockBit listing + fourth-party statementUnverified; no samplesThis post

The Register also noted a law firm considering a class action over the FIS notices (names, mailing addresses, and card numbers; SSNs / online-banking credentials / balances reportedly not accessed). The 2022 mishare included SSNs and dates of birth on closed accounts. CourtListener RECAP as of August 24, 2026 found no docket that matches this LockBit listing (see below).

Phishing inbox lure for a fake bank file-leak notice beside a note to type the official URL

What customers should do

  1. Type usbank.com or onlinebanking.usbank.com — do not click a mail button that says “view leaked files” or “confirm your account after LockBit.”
  2. Enroll a passkey in online banking if the Login preferences card is available. Passkeys are not yet on the Mobile App. A password is still allowed.
  3. Treat SMS one-time codes as weak. They remain the documented two-step method. Lock the mobile number (carrier PIN / port freeze).
  4. Watch for lookalikes such as usbanklogin.com (phishing-host pattern) and hyphen traps like us-bancorp.com.
  5. Nobody legitimate will ask you to pay a ransomware crew, or to “verify” a leak on a page they emailed you.

MFA: passkeys yes; YubiKey and Google Authenticator are not documented

U.S. Bank documents two-step verification as a one-time passcode to your mobile number (KB0069343). It can be toggled, but the bank says it cannot be completely stopped. The Passkey page covers online banking passkeys (rolled out gradually; not on the Mobile App). Two-step can still run with a passkey. Password login remains available.

Docs rechecked August 24, 2026: YubiKey / FIDO security keys and Google Authenticator / open TOTP are not documented. Directory grade stays Fail. Passkeys do not promote Fail→Pass/Strong while SMS OTP remains the documented second factor. Same rule as the national banks MFA scorecard.

MethodOn U.S. Bank docsGrade impact
OTP to mobile (SMS)Documented two-stepFail (SIM-swap path)
PasskeysYes — web, not Mobile AppTracked; does not promote
YubiKey / FIDO keyNot documentedNo Strong path
Google Authenticator / open TOTPNot documentedNo Pass path

CISA still recommends phishing-resistant MFA (More than a Password). That is guidance, not a claim that U.S. Bank already offers a consumer YubiKey.

ProductBest forGet it
YubiKey 5C NFCUSB-C laptops + NFC phonesAmazon
YubiKey 5 NFCUSB-A desktops + NFC phonesAmazon
YubiKey 5 / 5C NFC caseKeychain protection for the keyAmazon
Proton PassPasskeys + authenticator-style TOTP vaultProton Pass

We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Hardware security key beside authenticator dots, contrasted with a weak SMS code

Independent cybersecurity audits

We audited brand, login, parent, ticker-style, and the prior FIS vendor host on August 24, 2026. 100% is the ideal. None reach it. These scores are public email / transport / website posture. They do not prove or disprove the LockBit claim.

OrganizationDomainOverallvs 100%
U.S. Bankusbank.com68%−32
U.S. Bancorpusbancorp.com62%−38
USB short hostusb.com63%−37
Online bankingonlinebanking.usbank.com34%−66
FIS (prior vendor)fisglobal.com87%−13
DomainIdentityTransportWebsite
usbank.com90%15%37%
usbancorp.com75%15%37%
usb.com75%15%40%
onlinebanking.usbank.com0%45%40%
fisglobal.com90%40%95%

How to read this: usbank.com is Above Average (68%) with a familiar 15% transport gap (MTA-STS / related). Identity 0% on onlinebanking.usbank.com is a no-MX login-host pattern — not a reason to follow a lookalike. usb.com had no MX/web IPs in the blacklist probe; treat it as a short host we still scored, not as the customer login. fisglobal.com is here because of the separate May–June notices — not because the bank named FIS as this LockBit fourth party.

Audit links: usbank.com · usbancorp.com · usb.com · onlinebanking.usbank.com · fisglobal.com

Four shield icons with short progress bars that stop before a 100 percent target line

Website stack note

Passive website-tech probes on August 24, 2026:

DomainStack signal
usbank.com / usbancorp.comStack undetected; DigiCert TLS (into 2027)
onlinebanking.usbank.comStack undetected; DigiCert TLS; HTTP→HTTPS redirect not confirmed on the probe
usb.comStack undetected; HTTP→HTTPS redirect not confirmed
fisglobal.comASP.NET; Sectigo TLS (into 2027)

Point-in-time only. An undetected CMS or a vendor ASP.NET flag is not proof of this leak-site claim.

Blacklist, lookalikes, CourtListener

Email blacklist checks (public DoH, August 24, 2026): usbank.com, usbancorp.com, and onlinebanking.usbank.com were clear. usb.com returned no_ips (no MX/web addresses in the probe). fisglobal.com showed UCEPROTECT L2/L3 on shared Proofpoint MX IPs — low-signal provider noise. Do not lead as “FIS is blacklisted.”

DNS lookalike scan of usbank.com (BEC profile, registered signals): 77 to review, 4 likely owned pointing at the brand (usbank.biz / .info / .net / .org CNAME to U.S. Bank hosts), 0 BEC staging. usbancorp.com: 9 to review, 0 likely owned, 1 BEC staging.

LookalikeTechniqueNote
usbanklogin.comphishing-hostRegistered (NS, A, MX) — type the official login yourself
us-bancorp.comhyphenationBEC staging (NS, MX) on the parent-brand scan
usbank.biz / .info / .net / .orgtld-swapLikely owned (CNAME to U.S. Bank)
iusbank.com / usbankk.cominsertion / duplicationRegistered — investigate, not proof of LockBit

Monitor lookalikes with Cybersquat Domain Monitoring. A listing week is when fake “leak portal” and “secure your account” hosts get registered.

CourtListener RECAP (August 24, 2026): LockBit + U.S. Bank / Bancorp filed after 2026-08-010 dockets. Party “U.S. Bank National Association” with LockBit / ransomware / data-breach keywords after that date — 0. Texas Southern / Western and District of Minnesota keyword scan after 2026-08-010 matching this listing. A case_name “Data Breach” net hit In Re Instructure (D. Utah) — unrelated. No federal docket matches this LockBit claim as of this writing.


Run a free audit at audit.emailmenow.com or contact EmailMeNow for DMARC / MTA-STS and MFA baselines aimed at the 100% ideal.


Sources: The Register, Aug 20–21, 2026 · The Record / Recorded Future News · GalaxyWarden — usbank.com Lockbit5 listing · GalaxyWarden — Lockbit5 tracker · U.S. Bank two-step verification · Passkeys. Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches August 24, 2026. Domain scores: audit.emailmenow.com only.