US Bank said that data-theft claims made by the LockBit ransomware group stem from a fourth-party incident that happened outside its own environment, at a contractor working for one of its third-party vendors. The bank stated there is no evidence its own systems, networks, or data repositories were compromised, while LockBit set a deadline to leak the data unless paid. The "fourth-party" framing is the notable part: exposure reached the bank's customers through a vendor's vendor, two steps removed from its own controls. It follows earlier third-party incidents affecting US Bank customer data and underscores how far organizations' real attack surface extends beyond their direct suppliers.