Company Details
us-bank
79,818
544,967
52211
usbank.com
0
U.S_1281064
In-progress

U.S. Bank Company CyberSecurity Posture
usbank.comAt U.S. Bank, we help millions of clients achieve their goals with a balance of best-in-class technology and human expertise tailored to individual needs. As the fifth-largest commercial bank in the United States, we’ve built a reputation for strength and stability across a diversified mix of businesses, including commercial and institutional banking, business banking, payments, wealth management and consumer banking. We’ve been named one of the World’s Most Ethical Companies® by the Ethisphere Institute and the most admired superregional bank by Fortune. In addition to thousands of branches serving consumers, U.S. Bank offers a complete suite of products, services and strategic partnerships for business. Within our Wealth, Corporate, Commercial and Institutional Banking division, we serve more than half a million clients across the country and around the world, ranging from wealthy individuals and families to the largest corporations, including 90% of Fortune 1000 companies. We’re also consistently recognized as a great place to work. We’re shaping our company culture with intention, focused on creating a workplace where it’s safe to speak up, share ideas and try new things. We’re proud to be recognized as a “Best for Vets” employer by the Military Times and included on Fair360’s (formerly DiversityInc.) list of Top 50 Companies for Diversity. U.S. Bank, NA. Member FDIC. Equal Housing Lender.
Company Details
us-bank
79,818
544,967
52211
usbank.com
0
U.S_1281064
In-progress
Between 750 and 799

U.S. Bank Global Score (TPRM)XXXX

Description: The California Office of the Attorney General reported that U.S. Bank experienced a data breach on September 23, 2022, affecting customer personal information, including names, addresses, social security numbers, dates of birth, and account details. The breach was reported on October 27, 2022, and it involved inadvertent sharing of a file by a vendor.
Description: On February 3, 2021, the California Office of the Attorney General reported a data breach involving U.S. Bank, N.A., which occurred on July 30, 2020. The breach involved the physical theft of a computer server containing personally identifiable information, including names and Social Security numbers of affected individuals. The number of individuals affected is currently unknown.
Description: The Maine Attorney General's Office reported that U.S. Bank, N.A. experienced a credential stuffing attack on March 31, 2021, affecting a total of 333 individuals, including 2 residents of Maine. The breach was discovered on the same date, and consumers were notified by telephone on April 2, 2021.


No incidents recorded for U.S. Bank in 2025.
No incidents recorded for U.S. Bank in 2025.
No incidents recorded for U.S. Bank in 2025.
U.S. Bank cyber incidents detection timeline including parent company and subsidiaries

At U.S. Bank, we help millions of clients achieve their goals with a balance of best-in-class technology and human expertise tailored to individual needs. As the fifth-largest commercial bank in the United States, we’ve built a reputation for strength and stability across a diversified mix of businesses, including commercial and institutional banking, business banking, payments, wealth management and consumer banking. We’ve been named one of the World’s Most Ethical Companies® by the Ethisphere Institute and the most admired superregional bank by Fortune. In addition to thousands of branches serving consumers, U.S. Bank offers a complete suite of products, services and strategic partnerships for business. Within our Wealth, Corporate, Commercial and Institutional Banking division, we serve more than half a million clients across the country and around the world, ranging from wealthy individuals and families to the largest corporations, including 90% of Fortune 1000 companies. We’re also consistently recognized as a great place to work. We’re shaping our company culture with intention, focused on creating a workplace where it’s safe to speak up, share ideas and try new things. We’re proud to be recognized as a “Best for Vets” employer by the Military Times and included on Fair360’s (formerly DiversityInc.) list of Top 50 Companies for Diversity. U.S. Bank, NA. Member FDIC. Equal Housing Lender.


Somos un grupo financiero latinoamericano que apoya los sueños de las personas y busca establecer con ellas relaciones duraderas, basadas en la confianza, la cercanía, el respeto, la inclusión y la calidez. Escuchar, pensar en el otro y ser sensible a sus necesidades, nos ha llevado hacia una man

Founded in 1908, Bank of Communications Co., Ltd. ("the Bank") is one of the oldest banks in China as well as one of the note-issuing banks in modern China. The Bank was listed on the Hong Kong Stock Exchange in June 2005 and on the Shanghai Stock Exchange in May 2007. The Bank currently has 18

Welcome to the official LinkedIn page of Central Bank of India. Central Bank of India offers a wide range of products and services for every segment. Please join us to know more about our best products & services, attractive offers and the latest updates. We invite & value your active participatio
HDFC Bank is India's largest private sector bank, offering a comprehensive range of financial products and services to our customer base of over 92 million. Our extensive distribution network of 8,919 branches and 21,031 ATMs across 3,836 cities and towns as of August 2024, reaches every corner of t
Credit Suisse Group AG has been acquired by UBS Group AG. UBS is the world’s largest and only truly global wealth manager. We operate through four business divisions: Global Wealth Management, Personal & Corporate Banking, Asset Management, and the Investment Bank. Our global reach and the breadth

Desjardins Group is the largest cooperative financial group in North America and the fifth largest cooperative financial group in the world, with assets of $435.8 billion as at March 31, 2024. It was named one of Canada's Best Employers by Forbes magazine and by Mediacorp. To meet the diverse needs

Equitas Small Finance Bank is an active member of the communities where we live and work, and a strong philanthropic partner enabling individuals, families, businesses, and entire communities in their financial aspirations with seamless banking services. We take the responsibility to be good neighbo

Bank Rakyat Indonesia (BRI) adalah salah satu bank milik pemerintah yang terbesar di Indonesia. BRI didirikan di Purwokerto, Jawa Tengah oleh Raden Bei Aria Wirjaatmadja pada 16 Desember 1895. Lebih dari 128 tahun memberi pelayanan terbaik bagi seluruh lapisan masyarakat, BRI turut andil dalam upa
Bank of China, include BOC Hong Kong, BOC International, BOCG Insurance and other financial institutions, providing a comprehensive range of high-quality financial services to individual and corporate customers as well as financial institutions worldwide. Over the past century, Bank of China pla
.png)
Major U.S. banks are assessing their exposure to a cybersecurity incident at real estate financial technology company SitusAMC, which disclosed Saturday...
Big U.S. banks and mortgage lenders are scrambling to identify whether their customers' sensitive information — including customer and...
The Bank of America chief, speaking Tuesday at the American Bankers Association's annual convention, talked stablecoins, cybersecurity and...
Venture capital and private equity firm Insight Partners is notifying 12,657 people that their data was stolen in a ransomware attack,...
Properly protecting confidential data from cyberattacks requires a strong, intelligence-driven and risk-based security program that is backed by executive...
Quantum Computing (QUBT) recently secured its first U.S. commercial sale for quantum cybersecurity solutions with a Top 5 U.S. Bank,...
While banks are paying more attention to the threat of email fraud, a new study by a Massachusetts cybersecurity firm shows many of them...
Quantum Computing Inc. Secures $332,000 Purchase Order from Top 5 U.S. Bank for Quantum Cybersecurity Testbed ... Quantum Computing Inc. (QCi) (...
("QCi" or the "Company") (Nasdaq: QUBT), an innovative, integrated photonics and quantum optics technology company, today announced that it has...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of U.S. Bank is https://www.usbank.com/index.html.
According to Rankiteo, U.S. Bank’s AI-generated cybersecurity score is 790, reflecting their Fair security posture.
According to Rankiteo, U.S. Bank currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, U.S. Bank is not certified under SOC 2 Type 1.
According to Rankiteo, U.S. Bank does not hold a SOC 2 Type 2 certification.
According to Rankiteo, U.S. Bank is not listed as GDPR compliant.
According to Rankiteo, U.S. Bank does not currently maintain PCI DSS compliance.
According to Rankiteo, U.S. Bank is not compliant with HIPAA regulations.
According to Rankiteo,U.S. Bank is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
U.S. Bank operates primarily in the Banking industry.
U.S. Bank employs approximately 79,818 people worldwide.
U.S. Bank presently has no subsidiaries across any sectors.
U.S. Bank’s official LinkedIn profile has approximately 544,967 followers.
U.S. Bank is classified under the NAICS code 52211, which corresponds to Commercial Banking.
Yes, U.S. Bank has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/u-s-bancorp.
Yes, U.S. Bank maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/us-bank.
As of December 23, 2025, Rankiteo reports that U.S. Bank has experienced 3 cybersecurity incidents.
U.S. Bank has an estimated 7,108 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Cyber Attack and Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an communication strategy with consumers were notified by telephone on april 2, 2021..
Title: U.S. Bank Credential Stuffing Attack
Description: U.S. Bank, N.A. experienced a credential stuffing attack affecting 333 individuals, including 2 residents of Maine.
Date Detected: 2021-03-31
Type: Credential Stuffing Attack
Attack Vector: Credential Stuffing
Title: Data Breach at U.S. Bank, N.A.
Description: Physical theft of a computer server containing personally identifiable information, including names and Social Security numbers.
Date Detected: 2021-02-03
Date Publicly Disclosed: 2021-02-03
Type: Data Breach
Attack Vector: Physical Theft
Title: U.S. Bank Data Breach
Description: The California Office of the Attorney General reported that U.S. Bank experienced a data breach on September 23, 2022, affecting customer personal information, including names, addresses, social security numbers, dates of birth, and account details. The breach was reported on October 27, 2022, and it involved inadvertent sharing of a file by a vendor.
Date Detected: 2022-09-23
Date Publicly Disclosed: 2022-10-27
Type: Data Breach
Attack Vector: Inadvertent sharing of a file by a vendor
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: Names, Social security numbers
Systems Affected: Computer Server

Data Compromised: Names, Addresses, Social security numbers, Dates of birth, Account details
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Names, Social Security Numbers, , Names, Addresses, Social Security Numbers, Dates Of Birth, Account Details and .

Entity Name: U.S. Bank, N.A.
Entity Type: Financial Institution
Industry: Banking
Customers Affected: 333

Entity Name: U.S. Bank, N.A.
Entity Type: Financial Institution
Industry: Banking

Entity Name: U.S. Bank
Entity Type: Financial Institution
Industry: Banking
Location: United States

Communication Strategy: Consumers were notified by telephone on April 2, 2021

Number of Records Exposed: 333

Type of Data Compromised: Names, Social security numbers
Sensitivity of Data: High

Type of Data Compromised: Names, Addresses, Social security numbers, Dates of birth, Account details
Sensitivity of Data: High

Source: Maine Attorney General's Office

Source: California Office of the Attorney General
Date Accessed: 2021-02-03

Source: California Office of the Attorney General
Date Accessed: 2022-10-27
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Maine Attorney General's Office, and Source: California Office of the Attorney GeneralDate Accessed: 2021-02-03, and Source: California Office of the Attorney GeneralDate Accessed: 2022-10-27.
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Consumers were notified by telephone on April 2 and 2021.
Most Recent Incident Detected: The most recent incident detected was on 2021-03-31.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2022-10-27.
Most Significant Data Compromised: The most significant data compromised in an incident were Names, Social Security numbers, , names, addresses, social security numbers, dates of birth, account details and .
Most Significant System Affected: The most significant system affected in an incident was Computer Server.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Names, account details, addresses, social security numbers, Social Security numbers, names and dates of birth.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 333.0.
Most Recent Source: The most recent source of information about an incident are California Office of the Attorney General and Maine Attorney General's Office.
.png)
A vulnerability has been found in SeaCMS up to 13.3. The affected element is an unknown function of the file js/player/dmplayer/dmku/class/mysqli.class.php. Such manipulation of the argument page/limit leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyDevs TempTool allows Stored XSS.This issue affects TempTool: from n/a through 1.3.1.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tormorten WP Microdata allows Stored XSS.This issue affects WP Microdata: from n/a through 1.0.
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in HappyDevs TempTool allows Retrieve Embedded Sensitive Data.This issue affects TempTool: from n/a through 1.3.1.
A vulnerability has been found in Tenda FH1201 1.2.0.14(408). Affected is the function sprintf of the file /goform/SetIpBind. Such manipulation of the argument page leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.