LockBit 5.0 claims US Bank and a healthcare TPA — a leak-site listing is half the attack
On August 29, 2026, LockBit 5.0 listed the healthcare administrator American Plan Administrators on its leak site, three weeks after targeting US Bank with a September 3 deadline. A claim is not a confirmed breach, but it is already real pressure: here is how to handle it.
February 20, 2024. Operation Cronos dismantles LockBit’s infrastructure and identifies its administrator, Dmitry Khoroshev, aka LockBitSupp. 2025. A LockBit 5.0 variant resurfaces. August 29, 2026. The group lists American Plan Administrators, a self-funded health plan administrator, on its leak site — three weeks after targeting US Bank with a September 3 deadline. The most-dismantled ransomware gang in history is not dead: it has learned that a public claim, even without evidence, does half the work of an attack.
LockBit is not dead, it changed tactics
In February 2024, Operation Cronos — led by the UK NCA, Europol and the FBI — seized LockBit’s servers, domains and decryption keys. In May 2024, authorities named Dmitry Yuryevich Khoroshev, alias LockBitSupp, as the alleged operator and sanctioned him. To most observers the case looked closed. It was not: the group re-emerged in 2025 as a LockBit 5.0 variant, and the Cronos investigation surfaced a chilling detail — victims who paid still had their data retained despite the promise of deletion.
That detail frames everything that follows. When LockBit (rebranded LockBit 5.0, sometimes written lockbit5) publishes a victim, it is no longer about encrypting a fleet and negotiating in private. It is about posting a name to a leak site and letting fear do the work. Exfiltration becomes the product, the threat of disclosure the leverage, and the target’s name the ammunition.
What the group is claiming right now
On August 20, 2026, US Bank was added to LockBit’s leak site with a 14-day clock: pay before September 3, 2026, or the stolen files go public. The group did not specify how many files it claims to hold or what kind of data is involved — and that silence is precisely what makes the claim effective. Lee Henderson, the bank’s vice-president of public affairs, told The Register that “at this time, there is no indication that our internal systems are impacted or evidence of unauthorized access to our network.”
On August 29, 2026, a second name appeared on the leak site: American Plan Administrators, a US third-party administrator (TPA) that runs self-funded health plans on behalf of employers. The sector is the same as the group’s earlier targets, and the exposure is not trivial: a health TPA concentrates regulated health data, so a compromise cascades downstream to every employer that delegates its plan to it.
The list of claimed victims in August 2026 is eclectic — a cardiology clinic in the US, a Czech technology firm, a Dutch consultancy, ADT. This is not surgical targeting: it is a broad spray designed to maximize headlines.
The trap of an evidence-free claim
Let it be said plainly: a leak-site listing is not a confirmed breach. OSINT aggregators such as Ransomware.live and CTIWatch say so themselves — a listed victim is only a “group claim,” not a verified compromise. An actor can list a name by mistake, for prestige, to pressure a rival, or to test a target it never actually touched.
That is exactly the trap. For a listed company, the choice is asymmetric: confirming too fast invites market and regulatory panic, denying too hard risks being contradicted by a later publication. US Bank chose the middle path — “we are examining” — which is the only tenable position until an internal investigation rules one way or the other. The problem is that the group’s calendar (September 3) is designed to make that position untenable.
The lesson for a CISO is a single rule: the response to a ransomware claim must be pre-written, not improvised. Verifying an exfiltration allegation is not about believing or denying — it is about running a protocol: search logs for exfiltration traces, query EDR detections, audit privileged access and service accounts, and hold the public line without ever vouching for something you have not verified.
Why these targets — and the third-party pattern
The choice of US Bank is notable, but it is not proof of a breach of the banking core. The bank has a history of exposure through third parties: an incident at Fidelity National Information Services led to notifying 537 Massachusetts customers about exposed names, addresses and card numbers, and a file mis-shared by a vendor in 2022 affected roughly 11,000 customers. The pattern repeats: large organizations are hit through their perimeter — the vendor, the TPA, the service provider — more often than through the front door.
American Plan Administrators illustrates the other side of the problem. A health TPA is a concentration point: it processes HIPAA-protected data on behalf of many employers, and its compromise propagates downstream to dozens of organizations that never had a direct relationship with the attacker. It is the same logic as a software supply chain attack, transposed to health data.
Verify a claim in 24 hours
The deadline a group imposes — two weeks, then publication — is not accidental: it is tuned to force a response under pressure. The only defense is to have rehearsed the scenario. Exfiltration verification follows four steps, in order.
- Freeze without breaking. Lock down privileged access and suspicious service accounts, revoke unexplained active sessions — without halting operations until an indicator is confirmed.
- Hunt the data exit. Look for anomalous outbound volume, DNS queries to newly-registered domains, transfers to external object storage, unusual connection windows.
- Cross-check the EDR. Compare detections against the date the group claims: a credible claim usually comes with dateable artifacts.
- Hold one line. A factual position, identical internally and externally, that neither confirms nor denies until the investigation rules.
The goal is not to win the public argument but to reduce the claim to a binary question: is there, or is there not, evidence of exfiltration? A team that can answer that within 24 hours has already neutralized most of the surprise. In parallel, monitor the leak site and breach-notification feeds: the moment the group publishes, the timeline resets and the containment playbook changes. Preparing that second-phase response now — legal hold, notification lists, credit monitoring for affected individuals — is what separates a breach handled from a breach endured.
Verdict
If you fall within the radius of a claim — employee, customer or partner of a listed organization — conclude nothing before official confirmation. A leak-site listing is a signal to monitor, not a fact to relay. Turn on breach monitoring and prepare for possible personal exposure: credit monitoring and heightened vigilance against targeted phishing.
If you run security for an organization, treat this sequence as a reminder: write your ransomware-claim response protocol now, exercise it, and map the third parties that concentrate sensitive data. The risk is not only being attacked — it is being named. In this game, being able to verify within 24 hours is worth more than any statement of innocence.
References
- US Bank investigates LockBit’s claims as ransomware crims set pay-or-leak deadline — The Register, August 20, 2026
- US Bank Investigating Data Breach Following LockBit Ransomware Claim — Cyber Security News, August 21, 2026
- New LockBit 5.0 ransomware variant — Cyber Security News, 2025
- apatpa.com — lockbit5 ransomware attack (August 29, 2026) — CTIWatch
- apatpa.com data breach — Lockbit5 ransomware leak (2026) — Darkfield
- Operation Cronos: LockBit disrupted — National Crime Agency