Desk live·
ForensicPost
Ransomware/Verification/File 24-0623

LockBit Claimed 33TB From the Federal Reserve; the Data Was Evolve Bank's

LockBit announced thirty-three terabytes from the US central bank. The data was a Tennessee bank’s. The group did not know which organisation it had broken into.

Constructed geometry · not a chart of case data
JurisdictionUSAMemphis, Tennesseethe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetEvolve Bank & Trust
ActorLockBit
S. Rosler13 min readConfidence: high3 sources reviewed

In June 2024 LockBit announced that it had breached the United States Federal Reserve and taken 33 terabytes of banking information. The claim was covered widely and briefly.

The data was not the Federal Reserve’s. It came from Evolve Bank & Trust, a Tennessee institution providing banking services to financial technology companies, and Evolve subsequently confirmed the intrusion.

The Corpus Has Recorded Many Wrong Attacker Figures And Never This

Volume claims are routinely inflated — the corpus documented a twenty-to-one gap at 24-0812 and a hundred-to-one one at 24-1001. Those are exaggerations of a real thing.

This is different in kind. The group was wrong about the identity of its victim. It had the data, it could read the data, and it still named the wrong institution.

What That Implies About The Rest Of The Claims

The most charitable reading is that the intrusion and the extortion are done by different people, and the person writing the leak-site post has not examined the material carefully. That is consistent with what the corpus recorded at 25-0525 about tiered affiliate programmes and at 25-0225 about the division of labour inside these operations.

Either way it establishes something narrow and useful: an attacker asserting a victim identity is asserting something it may not have checked. This desk grades attacker claims low as a matter of routine, and this is the file that explains why the routine covers more than the numbers.

The Claim Did Work Regardless

A Federal Reserve breach is a far bigger story than a Memphis bank breach, and the announcement travelled on that basis. By the time it was corrected the attention had moved.

The corpus filed at 24-0813 that early wrong statements are rarely punished because nobody re-reads them. That was a victim organisation getting it wrong; the same asymmetry works for an attacker, and there the incentive to overstate is deliberate rather than accidental.

How we reported this

Compiled from contemporaneous reporting, listed below. Graded high: the misattribution is established by the victim’s own confirmation that the data was its own. The 33TB figure is the group’s claim and is not treated as established for any organisation. This desk offers no assessment of why the wrong name was used beyond noting the reading that is consistent with what leaked operational material shows about division of labour. Corrections: corrections@forensicpost.com.

Sources
  1. Evolve data breach dispels LockBit’s Federal Reserve ransom leakCybernews
  2. Evolve Bank & Trust confirms data was stolen in cyberattackInsurance Journal
  3. Evolve Bank and Trust confirms a LockBit data breach, fintech startups impactedCPO Magazine
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary