The LockBit ransomware group posted 3.1 million Bank of America customer records on its leak site on July 17 2026. The dataset contains account numbers partial Social Security numbers and transaction histories from May 2026. Bank of America confirmed the intrusion occurred between May 12 and June 4 when its security team isolated affected systems.
The bank notified affected customers on July 18 and offered two years of credit monitoring. The FBI issued an alert on July 19 warning other financial institutions of similar tactics used in the attack. LockBit demanded 45 million dollars in ransom which the bank refused to pay.
Bank of America invested 2.8 billion dollars in cybersecurity during 2025 and employs 1,200 security staff. The incident follows similar claims against JPMorgan Chase in April 2026 that were later attributed to a different group. Regulators including the OCC opened an investigation on July 20.
Why this matters
The breach highlights persistent vulnerabilities in legacy banking infrastructure despite record security spending. It will likely accelerate adoption of zero-trust architectures across the financial sector within 18 months. Customers may face increased fraud attempts as the data circulates on dark web markets.
Industry analysts expect similar incidents to prompt stricter federal breach notification timelines by early 2027.