Company Details
us-bank
79,818
544,967
52211
usbank.com
0
U.S_1281064
In-progress

U.S. Bank Company CyberSecurity Posture
usbank.comAt U.S. Bank, we help millions of clients achieve their goals with a balance of best-in-class technology and human expertise tailored to individual needs. As the fifth-largest commercial bank in the United States, we’ve built a reputation for strength and stability across a diversified mix of businesses, including commercial and institutional banking, business banking, payments, wealth management and consumer banking. We’ve been named one of the World’s Most Ethical Companies® by the Ethisphere Institute and the most admired superregional bank by Fortune. In addition to thousands of branches serving consumers, U.S. Bank offers a complete suite of products, services and strategic partnerships for business. Within our Wealth, Corporate, Commercial and Institutional Banking division, we serve more than half a million clients across the country and around the world, ranging from wealthy individuals and families to the largest corporations, including 90% of Fortune 1000 companies. We’re also consistently recognized as a great place to work. We’re shaping our company culture with intention, focused on creating a workplace where it’s safe to speak up, share ideas and try new things. We’re proud to be recognized as a “Best for Vets” employer by the Military Times and included on Fair360’s (formerly DiversityInc.) list of Top 50 Companies for Diversity. U.S. Bank, NA. Member FDIC. Equal Housing Lender.
Company Details
us-bank
79,818
544,967
52211
usbank.com
0
U.S_1281064
In-progress
Between 750 and 799

U.S. Bank Global Score (TPRM)XXXX

Description: The California Office of the Attorney General reported that U.S. Bank experienced a data breach on September 23, 2022, affecting customer personal information, including names, addresses, social security numbers, dates of birth, and account details. The breach was reported on October 27, 2022, and it involved inadvertent sharing of a file by a vendor.
Description: On February 3, 2021, the California Office of the Attorney General reported a data breach involving U.S. Bank, N.A., which occurred on July 30, 2020. The breach involved the physical theft of a computer server containing personally identifiable information, including names and Social Security numbers of affected individuals. The number of individuals affected is currently unknown.
Description: The Maine Attorney General's Office reported that U.S. Bank, N.A. experienced a credential stuffing attack on March 31, 2021, affecting a total of 333 individuals, including 2 residents of Maine. The breach was discovered on the same date, and consumers were notified by telephone on April 2, 2021.


No incidents recorded for U.S. Bank in 2025.
No incidents recorded for U.S. Bank in 2025.
No incidents recorded for U.S. Bank in 2025.
U.S. Bank cyber incidents detection timeline including parent company and subsidiaries

At U.S. Bank, we help millions of clients achieve their goals with a balance of best-in-class technology and human expertise tailored to individual needs. As the fifth-largest commercial bank in the United States, we’ve built a reputation for strength and stability across a diversified mix of businesses, including commercial and institutional banking, business banking, payments, wealth management and consumer banking. We’ve been named one of the World’s Most Ethical Companies® by the Ethisphere Institute and the most admired superregional bank by Fortune. In addition to thousands of branches serving consumers, U.S. Bank offers a complete suite of products, services and strategic partnerships for business. Within our Wealth, Corporate, Commercial and Institutional Banking division, we serve more than half a million clients across the country and around the world, ranging from wealthy individuals and families to the largest corporations, including 90% of Fortune 1000 companies. We’re also consistently recognized as a great place to work. We’re shaping our company culture with intention, focused on creating a workplace where it’s safe to speak up, share ideas and try new things. We’re proud to be recognized as a “Best for Vets” employer by the Military Times and included on Fair360’s (formerly DiversityInc.) list of Top 50 Companies for Diversity. U.S. Bank, NA. Member FDIC. Equal Housing Lender.


We are a leading international banking group, with a presence in 54 of the world’s most dynamic markets. Our purpose is to drive commerce and prosperity through our unique diversity, and our heritage and values are expressed in our brand promise, here for good. If you’re interested joining Standar

Established in 1907, today, we are a family of over 141 million customers and 40000 staff members. With a 100% CBS network of 6000+ branches and 5400+ ATMs and BNAs, Indian Bank has a wide national footprint, besides foreign branches in Singapore and Colombo, along with arrangements with 640 Oversea
ICICI Bank is one of India’s leading private sector banks, offering a wide range of banking products and services to corporate, Small and Medium Enterprises (SME) and individual customers across the country. The Bank offers multi-channel touch points including branches, ATMs, mobile banking, interne

The dream started two decades ago by Mr. Sanjay Agarwal, a merit holder Chartered Accountant and a first generation entrepreneur, along with his proficient team. Together, the dexterous team embarked on a journey of excellence while enriching lives along the way. What started off as a dream to be

We are the leading financial group in the Spanish market, comprised of banking business, insurance activity and investments in international banks and leading companies in the services sector. CaixaBank is a financial group with a socially responsible, long-term universal banking model, based on qua

En Banamex una palabra nos ha definido durante nuestra historia: Estar. Estar es acompañar. Estar es avanzar juntos. Acompañar para forjar relaciones auténticas, duraderas, significativas, que nos den confianza y nos impulsen a alcanzar aquello que es importante para ti, para nosotros, para todos.

For over 200 years, BNP Paribas Fortis has helped drive the growth and prosperity of Belgium’s economy and communities. The mission of our 12,000 colleagues is clear: be the trusted financial partner for four million individual customers, businesses and organisations. We do this by offering advice a

Started as a universal bank on August 23, 2015, Bandhan Bank is one of India’s fastest-growing private sector banks. Bandhan Bank has always been committed to financial inclusion and aims to serve the underserved. Guided by the principle of ‘Aapka Bhala, Sabki Bhalai,’ the Bank is dedicated not only
UniCredit exists to empower communities to progress. To deliver for all our stakeholders across Europe and unlock the potential within each individual and community we serve. We are a pan-European bank: our 13 banks across the continent work together as one, leveraging the strength of the collectiv
.png)
A cybersecurity incident affecting multiple U.S. financial institutions, when Marquis Software Solutions notified affected customers of a...
Marquis said ransomware hackers stole reams of banking customer data, containing personal information and financial records,...
Big U.S. banks and mortgage lenders are scrambling to identify whether their customers' sensitive information — including customer and...
The Bank of America chief, speaking Tuesday at the American Bankers Association's annual convention, talked stablecoins, cybersecurity and...
Properly protecting confidential data from cyberattacks requires a strong, intelligence-driven and risk-based security program that is backed by executive...
Quantum Computing (QUBT) recently secured its first U.S. commercial sale for quantum cybersecurity solutions with a Top 5 U.S. Bank,...
While banks are paying more attention to the threat of email fraud, a new study by a Massachusetts cybersecurity firm shows many of them...
Quantum Computing Inc. Secures $332,000 Purchase Order from Top 5 U.S. Bank for Quantum Cybersecurity Testbed ... Quantum Computing Inc. (QCi) (...
("QCi" or the "Company") (Nasdaq: QUBT), an innovative, integrated photonics and quantum optics technology company, today announced that it has...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of U.S. Bank is https://www.usbank.com/index.html.
According to Rankiteo, U.S. Bank’s AI-generated cybersecurity score is 777, reflecting their Fair security posture.
According to Rankiteo, U.S. Bank currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, U.S. Bank is not certified under SOC 2 Type 1.
According to Rankiteo, U.S. Bank does not hold a SOC 2 Type 2 certification.
According to Rankiteo, U.S. Bank is not listed as GDPR compliant.
According to Rankiteo, U.S. Bank does not currently maintain PCI DSS compliance.
According to Rankiteo, U.S. Bank is not compliant with HIPAA regulations.
According to Rankiteo,U.S. Bank is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
U.S. Bank operates primarily in the Banking industry.
U.S. Bank employs approximately 79,818 people worldwide.
U.S. Bank presently has no subsidiaries across any sectors.
U.S. Bank’s official LinkedIn profile has approximately 544,967 followers.
U.S. Bank is classified under the NAICS code 52211, which corresponds to Commercial Banking.
Yes, U.S. Bank has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/u-s-bancorp.
Yes, U.S. Bank maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/us-bank.
As of December 11, 2025, Rankiteo reports that U.S. Bank has experienced 3 cybersecurity incidents.
U.S. Bank has an estimated 6,988 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Cyber Attack and Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an communication strategy with consumers were notified by telephone on april 2, 2021..
Title: U.S. Bank Credential Stuffing Attack
Description: U.S. Bank, N.A. experienced a credential stuffing attack affecting 333 individuals, including 2 residents of Maine.
Date Detected: 2021-03-31
Type: Credential Stuffing Attack
Attack Vector: Credential Stuffing
Title: Data Breach at U.S. Bank, N.A.
Description: Physical theft of a computer server containing personally identifiable information, including names and Social Security numbers.
Date Detected: 2021-02-03
Date Publicly Disclosed: 2021-02-03
Type: Data Breach
Attack Vector: Physical Theft
Title: U.S. Bank Data Breach
Description: The California Office of the Attorney General reported that U.S. Bank experienced a data breach on September 23, 2022, affecting customer personal information, including names, addresses, social security numbers, dates of birth, and account details. The breach was reported on October 27, 2022, and it involved inadvertent sharing of a file by a vendor.
Date Detected: 2022-09-23
Date Publicly Disclosed: 2022-10-27
Type: Data Breach
Attack Vector: Inadvertent sharing of a file by a vendor
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: Names, Social security numbers
Systems Affected: Computer Server

Data Compromised: Names, Addresses, Social security numbers, Dates of birth, Account details
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Names, Social Security Numbers, , Names, Addresses, Social Security Numbers, Dates Of Birth, Account Details and .

Entity Name: U.S. Bank, N.A.
Entity Type: Financial Institution
Industry: Banking
Customers Affected: 333

Entity Name: U.S. Bank, N.A.
Entity Type: Financial Institution
Industry: Banking

Entity Name: U.S. Bank
Entity Type: Financial Institution
Industry: Banking
Location: United States

Communication Strategy: Consumers were notified by telephone on April 2, 2021

Number of Records Exposed: 333

Type of Data Compromised: Names, Social security numbers
Sensitivity of Data: High

Type of Data Compromised: Names, Addresses, Social security numbers, Dates of birth, Account details
Sensitivity of Data: High

Source: Maine Attorney General's Office

Source: California Office of the Attorney General
Date Accessed: 2021-02-03

Source: California Office of the Attorney General
Date Accessed: 2022-10-27
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Maine Attorney General's Office, and Source: California Office of the Attorney GeneralDate Accessed: 2021-02-03, and Source: California Office of the Attorney GeneralDate Accessed: 2022-10-27.
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Consumers were notified by telephone on April 2 and 2021.
Most Recent Incident Detected: The most recent incident detected was on 2021-03-31.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2022-10-27.
Most Significant Data Compromised: The most significant data compromised in an incident were Names, Social Security numbers, , names, addresses, social security numbers, dates of birth, account details and .
Most Significant System Affected: The most significant system affected in an incident was Computer Server.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Social Security numbers, addresses, social security numbers, names, account details, Names and dates of birth.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 333.0.
Most Recent Source: The most recent source of information about an incident are California Office of the Attorney General and Maine Attorney General's Office.
.png)
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local configuration, this password could be the extension, voicemail, user manager, DPMA or EPM phone admin password. This issue is fixed in versions 16.0.96 and 17.0.10.
Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller using PDO::prepare() + execute() without semantic restrictions. This is consistent with the name (“write tool”), but in an LLM/agent context it becomes a high-risk capability: prompt injection or indirect prompt manipulation can cause execution of destructive queries such as DROP TABLE, TRUNCATE, DELETE, ALTER, or privilege-related statements (subject to DB permissions). Deployments that expose an agent with MySQLWriteTool enabled to untrusted input and/or run the tool with a DB user that has broad privileges are impacted. This issue is fixed in version 2.8.12.
Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which is vulnerable to Read-Only Bypass. MySQLSelectTool is intended to be a read-only SQL tool (e.g., for LLM agent querying, however, validation based on the first keyword (e.g., SELECT) and a forbidden-keyword list does not block file-writing constructs such as INTO OUTFILE / INTO DUMPFILE. As a result, an attacker who can influence the tool input (e.g., via prompt injection through a public agent endpoint) may write arbitrary files to the DB server if the MySQL/MariaDB account has the FILE privilege and server configuration permits writes to a useful location (e.g., a web-accessible directory). This issue is fixed in version 2.8.12.
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request’s response. This issue is fixed in version 20.0.1.
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and 4.12.1.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.