If you hear that a bank has been hit by ransomware, you probably imagine hackers breaking into the bank's computer systems and stealing customer information. That isn’t how it always happens and lately, it seems it’s the rare case. This story is a little different.
The ransomware group LockBit recently added U.S. Bank to its leak site, claiming it had stolen data from the financial institution. The group gave the bank a deadline of September 3 to pay an undisclosed ransom or face having the allegedly stolen information published online.
But U.S. Bank says there is an important distinction; its own systems were not compromised.
After investigating the claim, U.S. Bank said the available evidence points to a cybersecurity incident involving a fourth-party provider—meaning they got the information from a company used by one of the bank's vendors. The incident occurred outside U.S. Bank's own environment and the bank says there is currently no evidence that its systems, networks, or data repositories were compromised.
Wait... What's a Fourth Party?
Here's the simple version.
Your bank uses a vendor. That vendor uses another company. That company gets hacked. That's a fourth-party incident.
Think of it as a digital chain. U.S. Bank may have carefully protected its own systems, but it cannot control every computer belonging to every company that does business with its vendors. And that is becoming a bigger cybersecurity problem.
So, Are U.S. Bank Customers at Risk?
This is a big question. It simply is not yet known. LockBit has not publicly provided details about how much data it claims to have stolen or exactly what the information contains. U.S. Bank has not confirmed that customer information was stolen at all, because according to it’s own investigation, it wasn’t. That's important.
At this point, customers should not assume their accounts have been compromised. But they should remain alert. If information is eventually released, criminals could potentially use it for phishing, identity theft or other scams.
And There's Another Problem
U.S. Bank has dealt with other vendor-related incidents involving customer information.
In one recent incident involving a third-party provider, the bank notified 537 Massachusetts customers that their names, mailing addresses, and credit-card numbers may have been exposed. Social Security numbers, online banking credentials, and account balances were reportedly not involved in that incident.
The lesson is bigger than U.S. Bank.
Your financial information can travel farther than you realize. You may trust your bank. Your bank may trust its vendor. And that vendor may trust another company. Unfortunately, cybercriminals only need one weak link.
What Should U.S. Bank Customers Do?
For now, there's no reason to panic or automatically close accounts because of the LockBit claim. Instead:
- Watch your banking and payment-card accounts for unusual activity.
- Be suspicious of unexpected calls, texts, or emails claiming to be from U.S. Bank.
- Never provide passwords or authentication codes to someone who contacts you unexpectedly.
- Don't click links in suspicious messages or from senders you don’t recognize.
- If you're concerned, contact U.S. Bank using the phone number on your card or another trusted source.
The U.S. Bank situation is still developing, and there is currently no evidence that the bank's own systems were breached. So, whether or not LockBit publishes information is TBD. But the incident demonstrates something consumers should understand: Sometimes your information can be exposed without anyone hacking your bank.
The digital supply chain has become enormous, and sometimes the weakest link isn't the company you trust. It's the company that works for the company you trust.