Â鶹´«Ã½

Skip to main content

China's biggest lender ICBC hit by ransomware attack

Bank tellers sit in a branch office of the Industrial and Commercial Bank of China in Hong Kong on March 27, 2013. (AP Photo/Kin Cheung, File) Bank tellers sit in a branch office of the Industrial and Commercial Bank of China in Hong Kong on March 27, 2013. (AP Photo/Kin Cheung, File)
Share

The Industrial and Commercial Bank of China's (ICBC) U.S. arm was hit by a ransomware attack that disrupted trades in the U.S. Treasury market on Thursday, the latest in a string of victims ransom-demanding hackers have claimed this year.

ICBC Financial Services, the U.S. unit of China's largest commercial lender by assets, said it was investigating the attack that disrupted some of its systems, and making progress toward recovering from it.

China's foreign ministry said on Friday the lender is striving to minimize risk impact and losses after the attack.

"ICBC has been closely monitoring the matter and has done its best in emergency response and supervisory communication," ministry spokesperson Wang Wenbin told a regular news conference.

Wang added businesses remained normal at ICBC head office and other branches and subsidiaries across the globe.

Hackers lock up a victim organization's systems in such attacks and demand ransom for unlocking it, often also stealing sensitive data for extortion.

Several ransomware experts and analysts said an aggressive cybercrime gang named Lockbit was believed to be behind the hack, although the gang's dark web site where it typically posts names of its victims did not mention ICBC as a victim as of Thursday evening. Lockbit did not respond to a request for comment sent via a contact address posted on its site.

"We don't often see a bank this large get hit with this disruptive of a ransomware attack," said Allan Liska, a ransomware expert at the cybersecurity firm Recorded Future.

Liska, who also believes Lockbit was behind the hack, said ransomware gangs may not name and shame their victims when they are negotiating with them.

"This attack continues a trend of increasing brazenness by ransomware groups," he said. "With no fear of repercussions, ransomware groups feel no target is off limits."

U.S. authorities have struggled to curb a rash of cybercrime, chiefly ransomware attacks, which hit hundreds of companies in nearly every industry each year. Just last week U.S. officials said they were working on curtailing the funding routes of ransomware gangs by improving information-sharing on such criminals across a 40-country alliance.

The ICBC did not comment on whether Lockbit was behind the hack. It is common for targets to refrain from publicly disclosing the names of cybercrime gangs.

Since Lockbit was discovered in 2020, the group has hit 1,700 U.S. organizations, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). Last month it threatened Boeing with a leak of sensitive data.

A CISA spokesperson referred questions about the ICBC hack to the U.S. Treasury Department.

While market sources said the impact of the hack appeared limited, it signalled how vulnerable systems at large organizations such as the bank continue to be. Thursday's incident is likely to raise questions over market participants' cybersecurity controls and draw regulatory scrutiny.

TRADES CLEARED

ICBC said it had successfully cleared Treasury trades executed on Wednesday and repurchase agreements (repo) financing trades done on Thursday.

"In general, the event had a limited impact on the market," said Scott Skrym, executive vice-president for fixed income and repo at broker-dealer Curvature Securities.

Some market participants said trades going through ICBC were not settled due to the attack and affected market liquidity. It was not clear whether this contributed to the weak outcome of a 30-year bond auction on Thursday.

"There could have been maybe some technical issues with some participants not being able to access the market fully on the day," said Michael Gladchun, associate portfolio manager, core plus fixed income, at Loomis Sayles.

The Financial Times reported earlier on Thursday that the U.S. Securities Industry and Financial Markets Association (SIFMA) told members that ICBC had been hit by ransomware that disrupted the U.S. Treasury market by preventing it from settling trades on behalf of other market players.

"We are aware of the cybersecurity issue and are in regular contact with key financial sector participants, in addition to federal regulators. We continue to monitor the situation," a Treasury spokesperson said in a response to a question about the FT report. SIFMA declined to comment.

The Treasury market appeared to be functioning normally on Thursday, according to LSEG data.

(Reporting by Urvi Dugar in Bengaluru and Pete Schroder in Washington; Additional reporting by Gertrude Chavez, Davide Barbuscia, Carolina Mandl, Paritosh Bansal and Joe Cash; Editing by Stephen Coates and Tomasz Janowski)

CTVNews.ca Top Stories

A Manitoba man convicted of murder 50 years ago has been acquitted. Clarence Woodhouse was found guilty in 1974 of fatally beating and stabbing a restaurant worker in downtown Winnipeg.

A health official has confirmed a child in Ontario has died after they came in contact with a rabid bat.

More sexual assault charges have been filed against billionaire Frank Stronach with the Canadian businessman now facing a total of 18 charges.

An Ontario family was planning a religious trip to Saudi Arabia that included 10 people, but when they were checking in for their flights, the family discovered some of their tickets were fake.

Local Spotlight

The grave of a previously unknown Canadian soldier has been identified as a man from Hayfield, Man. who fought in the First World War.

Moving into the second week of October, the eastern half of Canada can expect some brisker fall air to break down from the north

What does New Westminster's təməsew̓txʷ Aquatic and Community Centre have in common with a historic 68,000-seat stadium in Beijing, an NFL stadium and the aquatics venue for the Paris Olympics? They've all been named among the world's most beautiful sports venues for 2024.

The last living member of the legendary Vancouver Asahi baseball team, Kaye Kaminishi, died on Saturday, Sept. 28, surrounded by family. He was 102 years old.

New data from Greater Vancouver and the Fraser Valley shows a surge in supply and drop in demand in the region's historically hot real estate market.

On Saturday night at her parents’ home in Delaware, Ont. the Olympic bronze medallist in pole vault welcomed everyone who played a role in getting her to the podium in Paris.

A tale about a taxicab hauling gold and sinking through the ice on Larder Lake, Ont., in December 1937 has captivated a man from that town for decades.

When a group of B.C. filmmakers set out on a small fishing boat near Powell River last week, they hoped to capture some video for a documentary on humpback whales. What happened next blew their minds.

A pizza chain in Edmonton claims to have the world's largest deliverable pizza.

Stay Connected