Skip to content
LockBit 5.0 targets U.S. Bank, one of the largest banks in the United States

LockBit 5.0 targets U.S. Bank, one of the largest banks in the United States

Escudodigital • August 20, 2026

The ransomware group claims to have breached the financial institution, but has yet to reveal what data it may have stolen, while the alleged attack remains unverified.

The ransomware group LockBit 5.0 claims to have compromised U.S. Bank , one of the major financial entities in the United States, in an attack that was reportedly detected on August 19. The claim has been picked up by threat services like Hackmanac and VenariX, although there is currently no public confirmation from U.S. Bank or U.S. authorities, and the incident remains pending verification.

The available information also does not yet allow for the determination of which systems may have been compromised, what information may have been stolen, or if systems were encrypted. Hackmanac classifies the alleged attack within the financial sector and does not specify any type of exposed data.

The possible attack comes at a time of renewed activity for LockBit 5.0 , the new version of one of the most significant ransomware operations in recent years. The organization survived the blow of Operation Cronos , the international police operation launched in February 2024 against its infrastructure, and subsequently rebuilt its activity under new versions.

🚨Cyber Alert ‼️ 🇺🇸United States - 𝗨𝗦 𝗕𝗮𝗻𝗸 LockBit 5.0 ransomware group claims to have breached US Bank. Threat actor: LockBit 5.0 Sector: Financial / Insurance Data exposure (claimed): Not specified Data type: Not specified Observed: Aug 19, 2026 Status: Pending… pic.twitter.com/vUh0xNvMVT

The financial sector is not new to LockBit. One of its most impactful attacks occurred in November 2023 against ICBC Financial Services , the U.S. subsidiary of the Chinese financial giant Industrial and Commercial Bank of China. The incident affected securities trading operations and forced the establishment of alternative mechanisms for certain transactions.

In 2026, LockBit 5.0 has also claimed attacks against other financial entities. In April, the group claimed to have compromised Bladex , a multilateral bank based in the United States, and threatened to publish sensitive information if negotiations were not initiated.

These episodes align with LockBit's traditional model, based on ransomware-as-a-service (RaaS). The group provides the infrastructure and malware while different affiliates carry out intrusions against victims.

The usual strategy combines information theft and system encryption, followed by double extortion: demanding a ransom to regain access to systems and threatening to publish the stolen data if the victim does not pay.

The possible intrusion against U.S. Bank also has added significance because it demonstrates the difficulties in definitively ending large ransomware operations.

In February 2024, international security forces managed to take control of a large part of LockBit's infrastructure, seize servers, identify affiliates, and obtain information their operations. Europol then described LockBit as the world's most prolific and damaging ransomware operation.

However, the group managed to rebuild and reappear with LockBit 5.0, a cross-platform variant capable of attacking Windows, Linux, and VMware ESXi systems.

The activity continues in 2026. Recent investigations place LockBit among the ransomware groups that remain active and capable of attacking organizations in various sectors.

The ransomware group LockBit 5.0 claims to have compromised U.S. Bank , one of the major financial entities in the United States, in an attack that was reportedly detected on August 19. The claim has been picked up by threat services like Hackmanac and VenariX, although there is currently no public confirmation from U.S. Bank or U.S. authorities, and the incident remains pending verification.

The available information also does not yet allow for the determination of which systems may have been compromised, what information may have been stolen, or if systems were encrypted. Hackmanac classifies the alleged attack within the financial sector and does not specify any type of exposed data.

The possible attack comes at a time of renewed activity for LockBit 5.0 , the new version of one of the most significant ransomware operations in recent years. The organization survived the blow of Operation Cronos , the international police operation launched in February 2024 against its infrastructure, and subsequently rebuilt its activity under new versions.

🚨Cyber Alert ‼️ 🇺🇸United States - 𝗨𝗦 𝗕𝗮𝗻𝗸 LockBit 5.0 ransomware group claims to have breached US Bank. Threat actor: LockBit 5.0 Sector: Financial / Insurance Data exposure (claimed): Not specified Data type: Not specified Observed: Aug 19, 2026 Status: Pending… pic.twitter.com/vUh0xNvMVT

The financial sector is not new to LockBit. One of its most impactful attacks occurred in November 2023 against ICBC Financial Services , the U.S. subsidiary of the Chinese financial giant Industrial and Commercial Bank of China. The incident affected securities trading operations and forced the establishment of alternative mechanisms for certain transactions.

In 2026, LockBit 5.0 has also claimed attacks against other financial entities. In April, the group claimed to have compromised Bladex , a multilateral bank based in the United States, and threatened to publish sensitive information if negotiations were not initiated.

These episodes align with LockBit's traditional model, based on ransomware-as-a-service (RaaS). The group provides the infrastructure and malware while different affiliates carry out intrusions against victims.

The usual strategy combines information theft and system encryption, followed by double extortion: demanding a ransom to regain access to systems and threatening to publish the stolen data if the victim does not pay.

The possible intrusion against U.S. Bank also has added significance because it demonstrates the difficulties in definitively ending large ransomware operations.

In February 2024, international security forces managed to take control of a large part of LockBit's infrastructure, seize servers, identify affiliates, and obtain information their operations. Europol then described LockBit as the world's most prolific and damaging ransomware operation.

However, the group managed to rebuild and reappear with LockBit 5.0, a cross-platform variant capable of attacking Windows, Linux, and VMware ESXi systems.

The activity continues in 2026. Recent investigations place LockBit among the ransomware groups that remain active and capable of attacking organizations in various sectors.

Become a premium member for free!

Extracted Entities