Ransomware

Ransomware Attack on China’s Biggest Bank Disrupts Treasury Market Trades, Reports Say

A ransomware attack on China’s biggest bank, the Industrial and Commercial Bank of China Financial Services, disrupts Treasury market trades.

ICBC Cyberattack impacts treasury market

A financial services business of China’s biggest bank says it was it by a ransomware attack that reportedly disrupted trading in the U.S. Treasury market.

Industrial and Commercial Bank of China Financial Services handles trades and other services for financial institutions.

A statement on its website seen Friday said the ransomware attack this week disrupted some of its systems but that it had disconnected parts of the affected systems to limit the impact from the attack.

The company, which is based in New York, said it was investigating and had reported the problem to law enforcement.

All Treasury trades executed Wednesday and repo financing trades on Thursday were cleared, it said. It said ICBC’s banking, email and other systems were not affected.

The company gave no further details but reports said the attack was by LockBit, a Russian-speaking ransomware syndicate that does not target former Soviet countries. It is one of the most efficient ransomware variants around, according to the cybersecurity firm Emsisoft. Active since September 2019, it has attacked thousands of organizations.

Advertisement. Scroll to continue reading.

Related: SysAid Zero-Day Vulnerability Exploited by Ransomware Group

Related: FBI Highlights Emerging Initial Access Methods Used by Ransomware Groups 

Related: Key Learnings from “Big Game” Ransomware Campaigns

Related: Authorities Shut Down RagnarLocker Ransomware Infrastructure

Related Content

Artificial Intelligence

The current GPT-5.6-Sol has been assigned a ‘high’ cybersecurity threshold, but Astra could reach the maximum ‘critical’ threshold. 

Application Security

The startup analyzes subtle telemetry signals to detect attacks that traditional security tools cannot see inside accelerator-powered AI infrastructure.

Vulnerabilities

Remote, unauthenticated attackers could exploit the bugs to cause a denial-of-service (DoS) condition.

Artificial Intelligence

An AI agent executes instructions that an attacker has planted in the log or alert that records a blocked request word for word.

ICS/OT

Hackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states.

Vulnerabilities

The security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances.

ICS/OT

CERT.PL said this appears to be the first instance of a private APN being used as an attack vector.

Vulnerabilities

The critical-severity flaw allows unauthenticated, remote attackers to execute arbitrary commands.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version