On Tuesday, the LockBit ransomware gang published a large cache of files allegedly stolen from the US Federal Reserve system. The Russian-affiliated group released 21 separate links containing directories, torrents, and compressed archive files, with a significant portion belonging to Evolve Bank and Trust, a US financial institution recently criticized by the Federal Reserve for unsafe banking practices.
Breakdown in Negotiations with LockBit Leads to the Release of Sensitive Federal Reserve Data
LockBit had previously warned the Federal Reserve via their dark web victim blog, threatening to publish the stolen data by June 25th if their ransom demands were not met. Claiming to possess 33 terabytes of sensitive banking information, the gang blamed the release on unsuccessful negotiations and an unsatisfactory ransom offer from the US central bank.
Extensive Scope of the Alleged Breach Involving Evolve Bank and Trust Data
The stolen data allegedly includes information on:
- ROMs and firmware
- Source codes
- Property files
- Employee and customer databases
- Financial information
- Future product plans
- Technical specification sheets
Additionally, the breach reportedly involves a comprehensive database of AMD employees, containing personal information such as user IDs, job functions, email addresses, and business phone numbers. LockBit is selling this data exclusively for XMR (Monero) cryptocurrency, offering to use a middleman for transactions.
Official Statements and Potential Repercussions for the Federal Reserve and Evolve Bank
Neither the US Federal Reserve Board of Governors nor Evolve Bank has confirmed the authenticity of the breach. However, Evolve Bank was recently served a cease-and-desist order for deficiencies in their anti-money laundering, risk management, and consumer compliance programs. Evolve Bank, headquartered in Memphis, Tennessee, partners with fintech platforms such as Mastercard, Visa, Affirm, Melio, Stripe, and Airwallex.
Expert Opinions on the Legitimacy of LockBit’s Claims and Potential Impact
Josh Jacobson, Director of Professional Services at HackerOne, emphasized the significant global implications of a breach affecting the Federal Reserve, noting the potential residual impacts and the importance of maintaining trust. Despite these concerns, some experts, including Aviral Verma, Lead Security Analyst at Securin, suspect that LockBit’s claims may be exaggerated or a bluff to regain notoriety following recent law enforcement actions against them.
LockBit’s Continued Threat and Evolution in the Cybersecurity Landscape Despite Setbacks
LockBit, operating since late 2019, has been involved in over 1,400 attacks globally, affecting various sectors. Despite suffering setbacks from Operation Cronos, led by the FBI and Interpol, the group continues to operate and target high-profile entities. LockBit’s latest ransomware variant, LockBit 3.0, is considered the most evasive yet, responsible for major attacks on organizations like The Boeing Company, Allen & Overy, and Deutsche Telekom.
Ransomware Trends and Ongoing Law Enforcement Efforts to Combat the Growing Threats
According to the Cybernews ransomware monitoring tool Ransomlooker, LockBit has been behind nearly 50% of all publicly acknowledged ransomware attacks since 2022. The FBI’s recovery of 7,000 decryption keys earlier this month highlights ongoing efforts to combat ransomware and assist victims in data recovery.
Conclusion: The Persistent and Evolving Threat of Ransomware Attacks on Critical Infrastructure
The LockBit ransomware gang’s alleged breach of the US Federal Reserve underscores the persistent and evolving threat posed by ransomware groups. As the cybersecurity community and stakeholders await further confirmation and details, this incident emphasizes the critical need for strong cybersecurity measures and constant vigilance.
Stay tuned for updates on this developing story as more information becomes available.

Discover more from Open Security Labs
Subscribe to get the latest posts sent to your email.







