U.S. Bancorp, the seventh largest bank in the United States, is pushing back on claims by the LockBit ransomware gang that it stole data from the company, saying its investigation traced the incident to a breach several steps removed from its own infrastructure.

A company spokesperson told Recorded Future News that U.S. Bancorp identified the source as “a potential cyber incident related to a fourth party event that occurred outside” of its environment. The bank said there is currently no evidence that its own systems, networks, or data repositories were compromised.

“We have provided relevant information to law enforcement and continue to support their investigation,” the spokesperson said. U.S. Bancorp declined to identify either the third party or the fourth party allegedly at the root of the breach, and said it will continue monitoring LockBit’s claims for signs of data exposure.

LockBit’s claim and lack of proof

The claims surfaced Thursday morning when LockBit added U.S. Bancorp to its victim leak site and threatened to publish stolen data within two weeks. The gang has not released any sample files to substantiate the claim, and U.S. Bancorp initially told reporters it had found no indication of unauthorized network access.

The incident highlights the growing risk posed by fourth-party exposure, where a breach at a vendor’s own supplier or contractor can implicate a much larger organization by association, even when the primary target’s core systems remain untouched.

LockBit’s uneven comeback

LockBit remains one of the most prolific ransomware brands in recent history despite a coordinated international law enforcement takedown in 2024. The U.S. Treasury Department said in December that LockBit generated $252.4 million in ransom payments across 353 successful attacks between 2022 and 2024.

Since the takedown, the group has struggled to rebuild its operation amid continued law enforcement pressure. Leaked versions of LockBit’s ransomware builder have also allowed unaffiliated criminals to launch attacks using its code, including against organizations inside Russia, where LockBit’s alleged leadership is based.

U.S. Bancorp is the second bank to appear on a ransomware leak site this week, following Cameroon’s Credit Communautaire d’Afrique Bank, which was listed by a different group after reporting operational issues roughly two weeks earlier.