Ransomware

Ransomware Attack on China’s Biggest Bank Disrupts Treasury Market Trades, Reports Say

A ransomware attack on China’s biggest bank, the Industrial and Commercial Bank of China Financial Services, disrupts Treasury market trades.

ICBC Cyberattack impacts treasury market

A financial services business of China’s biggest bank says it was it by a ransomware attack that reportedly disrupted trading in the U.S. Treasury market.

Industrial and Commercial Bank of China Financial Services handles trades and other services for financial institutions.

A statement on its website seen Friday said the ransomware attack this week disrupted some of its systems but that it had disconnected parts of the affected systems to limit the impact from the attack.

The company, which is based in New York, said it was investigating and had reported the problem to law enforcement.

All Treasury trades executed Wednesday and repo financing trades on Thursday were cleared, it said. It said ICBC’s banking, email and other systems were not affected.

The company gave no further details but reports said the attack was by LockBit, a Russian-speaking ransomware syndicate that does not target former Soviet countries. It is one of the most efficient ransomware variants around, according to the cybersecurity firm Emsisoft. Active since September 2019, it has attacked thousands of organizations.

Related: SysAid Zero-Day Vulnerability Exploited by Ransomware Group

Related: FBI Highlights Emerging Initial Access Methods Used by Ransomware Groups 

Advertisement. Scroll to continue reading.

Related: Key Learnings from “Big Game” Ransomware Campaigns

Related: Authorities Shut Down RagnarLocker Ransomware Infrastructure

Related Content

Artificial Intelligence

Jan Leike, who ran OpenAI’s “Super Alignment” team, believes there should be more focus on preparing for the next generation of AI models, including...

Artificial Intelligence

Slack reveals it has been training AI/ML models on customer data, including messages, files and usage information. It's opt-in by default.

Cybercrime

Noteworthy stories that might have slipped under the radar: FBI is targeting Scattered Spider, Australia’s MediSecure hacked, new Wi-Fi attack.

Vulnerabilities

CISA has added two vulnerabilities in discontinued D-Link products to its KEV catalog, including a decade-old flaw.

Application Security

A critical vulnerability tracked as CVE-2024-34359 and dubbed Llama Drama can allow hackers to target AI product developers.

Malware & Threats

The Antidot Android banking trojan snoops on users and steals their credentials, contacts, and SMS messages.

Malware & Threats

The Black Basta group abuses remote connection tool Quick Assist in vishing attacks leading to ransomware deployment.

Tracking & Law Enforcement

The US government has announced charges, seizures, arrests and rewards as part of an effort to disrupt a scheme that generates revenue for North...

Copyright © 2024 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version