```html ```
top of page

LockBit Named US Bank and Started a 14-Day Clock. Here Is How to Price That Claim — and What Our Own LockBit Shelf Looks Like.

  • Writer: Patrick Duggan
    Patrick Duggan
  • 41 minutes ago
  • 7 min read

Late Wednesday night the ransomware crew LockBit added US Bank to its leak site and started a fourteen-day clock. Pay, or the data goes public on September 3. The bank's response, from VP of public affairs Lee Henderson, was the careful kind: aware of claims regarding a potential cybersecurity incident, no indication internal systems are impacted, no evidence of unauthorized access to the network.


Two statements, flatly opposed, and a fortnight of silence budgeted in between. This post is not about who is right. It is about how you should price a claim like this one before the deadline resolves it — and, because we ask other people to show their work, what our own LockBit coverage actually looks like underneath the confident-sounding parts.



What the Listing Contains, and What It Does Not


A leak-site post is a marketing asset. It is written to move a victim toward payment, and its contents are chosen accordingly. So read it the way you would read any other advertisement: by what it declines to say.


This one declines to say a great deal. There is no stated file volume. There is no sample tree, no directory listing, no redacted screenshot of a document that only an insider could hold. There is a name, a countdown, and an implication.


That absence is not proof of a bluff. Crews routinely withhold samples during a negotiation window precisely because publishing proof reduces the victim's incentive to pay quietly. But it does mean the claim currently sits at the very bottom of the evidence ladder, and every hour it stays there without a sample is information.



The Ladder


We grade extortion claims on five rungs. It costs nothing, it takes about four minutes, and it stops a newsroom headline from becoming an incident-response mobilisation.




Rung one — named, nothing else. A name on a wall. Costs the crew nothing and is the rung where fabrications live.


Rung two — a sample or file tree. Now there is something falsifiable. Check whether the tree's shape matches the named organisation or a supplier, a subsidiary, or a reseller who merely holds their records.


Rung three — insider-only artifacts. Internal hostnames, an org chart, a system that is not internet-facing. Hard to synthesise, and the first rung that genuinely moves our confidence.


Rung four — independent corroboration. Someone unrelated to the crew and unrelated to the victim confirms something. A regulator filing. A partner's breach notice. Credentials appearing in a market with matching domains.


Rung five — the victim confirms. Rare, slow, and usually arrives with lawyers.


The US Bank claim is on rung one. So was every fabrication we have ever caught.





Why We Are Careful About This Particular Crew


We have written this beat enough times to have earned the caution.


In May we documented a breach-monitoring service still listing Capgemini as a February victim of the 0APT crew — a listing a rival crew had already proven fake by leaking the access logs. In July, KryBit posted Ford and the sample turned out to be twenty-five login credentials from the Mexican subsidiary. Two ransomware gangs both claimed Coca-Cola's Fairlife with wildly different numbers. And in June we wrote up LockBit 5.0 posting three fresh victims after the 2024 takedown that was supposed to have ended them.


There is also a specific precedent worth having in your head this fortnight. In 2024 LockBit claimed it had breached the US Federal Reserve. The claim moved markets' worth of attention. When the data landed, it came from a single bank — Evolve Bank and Trust — not the Fed. The pattern is name-the-giant, deliver-the-adjacent. It is not a certainty here. It is a prior, and it is a strong one.



Now Ours: What Our LockBit Shelf Actually Holds


Here is the part that is uncomfortable to publish, which is why it is the part worth publishing.


We went and audited our own LockBit coverage this morning rather than assuming it. A loose text search across our indicator index returns six hundred and sixty-four records that match something LockBit-shaped, which sounds like plenty. But most of those are keyword noise from third-party feeds — a domain with "lockbit" in the string, no attribution attached. The records genuinely attributed to LockBit number seventeen, and even that is a floor rather than a total, because the count reaches our page ceiling.


That gap between 664 and 17 is worth sitting with for a second, because it is the number a careless vendor would have quoted you.


Then the date. The newest attributed LockBit indicator we hold arrived on June 26. The oldest arrived on June 6. Our entire LockBit shelf is a single three-week window that closed fifty-six days ago — eight weeks in which a crew currently running a countdown against a top-five American bank contributed nothing new to it at all.


And then the part that actually matters. All seventeen came from ThreatFox. Not one is first-party — nothing from our own scanning, our own hunting, or our own edge telemetry, ever. All seventeen are domains; there is not a single IP or file hash among them. And all seventeen carry a confidence of 70, which sits below the threshold of 80 that governs what reaches our blocking artifacts, so the number of LockBit indicators a customer can actually block from our feed today is zero.


ThreatFox is free, public, and universally consumed. Anyone pulling it had identical coverage on the same day. Whatever value we added there was distribution, not detection, and we should say so in those words rather than let a count imply otherwise.




We could have written a post today that said LockBit is in our feed. It would have been true. It would also have been the kind of true that gets a defender hurt.



The Bug Underneath the Bug


The reason we did not know this until a human asked is worth more than the finding.


We run a weekly audit whose entire job is to catch exactly this — actors we write about whose indicators never made it into the feed. It has been running for weeks and reporting healthy.


It graded on volume. An actor with three or more attributed indicators was green, permanently, with no expiry. There was no time axis anywhere in it. Seventeen indicators that stopped arriving in June look identical to seventeen indicators that arrived this morning, and the audit had no way to tell those apart. A high count with no recent arrivals is not coverage. It is a memoir.


It also could not see LockBit at all. The audit built its roster from our threat-actor profile index, and LockBit — the most prolific ransomware brand of the era, a crew we have written about repeatedly — had no profile. Not stale. Absent. An actor that is missing from the denominator does not show up as a gap; it does not show up at all, which reads exactly like health.


And a third one, found while proving the first two. The audit resolved every failed lookup to zero. When a sweep exhausted our own search rate limit partway through, every actor after that point was recorded as having no indicators. A dry run this morning reported ninety-eight of one hundred and two tracked actors as gaps. Almost none of them were. A failed measurement had been rendered as a confident zero, which is the most expensive value a monitoring system can produce.


All three are fixed as of today. The audit now grades on recency as well as volume — an actor over the count threshold with nothing new inside forty-five days is graded stale, which is its own state and its own worklist entry, ranked by age rather than by count. Branded ransomware crews are unioned into the roster whether or not a profile exists for them. And a lookup that fails now raises, gets counted separately as unaudited, and can never again be laundered into a zero.


We ran it across the whole roster after the change, and the before-and-after is the argument for doing this to yourself regularly.


Before: two actors fed, ninety-eight gaps, zero stale — a report that was almost entirely fiction, generated by a rate limit nobody could see.


After: one hundred and fourteen actors audited, zero failed lookups, eighteen fed, six thin, seventy-five with no attributed indicators, and fourteen graded stale — every one of them previously reporting as healthy or not reporting at all. Cl0p, one hundred and forty days since its last indicator. Black Basta, ninety indicators, one hundred and thirty-seven days. Medusa, one hundred and thirty-seven. TeamPCP — an actor we run a standing watch on — three hundred and sixty-five indicators and eighty-five days of silence. RansomHub sixty-two. LockBit fifty-six. Of those fourteen, twelve have no first-party record of any kind, ever.


None of that was visible yesterday. Not because the data was missing — it was sitting in the index the whole time — but because nothing we had built was asking the question in a form that could return an uncomfortable answer.



What to Actually Do Before September 3


If you are at the named institution, you already have people on this and none of it is news to you.


If you are one of the thousands of organisations that merely bank there, or supply them, or hold their paper, the useful posture is narrow. Do not mobilise on a rung-one claim. Do watch for the sample drop, because that is the moment the claim becomes gradeable and the moment the scope becomes visible — and the scope of these things is very often a supplier rather than the named brand. Treat any inbound communication referencing the incident as hostile until proven otherwise; the recovery-firm impersonation racket in this ecosystem is real and it moves fast when a big name is in the headlines.


And if you consume anybody's threat feed — ours included — ask the vendor a question that almost nobody asks. Not how many indicators do you have for this actor. When did the last one arrive, and was it yours.


We just had to answer that about ourselves, and the answer was worse than the count implied. That is exactly why it is the right question.




Was this useful, or did we miss something? Rate this post below — we read every one, and the low scores are the ones that change what we build.




Every indicator in this post is in the feed. Free.

1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.



Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=lockbit-named-us-bank-and-started-a-14-day-clock-here-is-how-to-price-that-claim-and-what-our-own



Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page