U.S. Bancorp Attributes LockBit Listing to Fourth Party Outside Its Own Systems
LockBit posted U.S. Bank on its leak site August 19 with an early-September pay-or-publish deadline, but U.S. Bancorp stated on August 21 that available evidence points to an incident at a fourth-party vendor rather than a compromise of its own systems, networks, or data repositories. No ransom amount, file count, data sample, or affected population has been disclosed, and no SEC filing or regulatory notice related to the claim appeared in public records through August 22. LockBit's post-Operation Cronos track record includes recycled and misattributed victim listings, meaning the claim requires independent corroboration before its scope or validity can be assessed.