18.1 C
Athens
Παρασκευή, 17 Μαΐου, 2024

China’s biggest lender ICBC hit by ransomware attack

Περισσότερα Νέα

- Advertisement -

The Industrial and Commercial Bank of China’s (ICBC) U.S. arm was hit by a ransomware attack that disrupted trades in the U.S. Treasury on Thursday, the latest in a string of victims ransom-demanding hackers have claimed this year.

ICBC Financial Services, the U.S. unit of China’s largest commercial lender by assets, said it was investigating the attack that disrupted some of its systems, and making progress toward recovering from it.

Hackers lock up a victim organization’s systems in such attacks and demand ransom for unlocking it, often also stealing sensitive data for extortion.

Several ransomware experts and analysts said an aggressive cybercrime gang named Lockbit was believed to be behind the hack, although the gang’s dark web site where it typically posts names of its victims did not mention ICBC as a victim as of Thursday evening. Lockbit did not respond to a request for comment sent via a contact address posted on its site.

“We don’t often see a bank this large get hit with this disruptive of a ransomware attack,” said Allan Liska, a ransomware expert at the cybersecurity firm Recorded Future.

- Advertisement -

Liska, who also believes Lockbit was behind the hack, said ransomware gangs may not name and shame their victims when they are negotiating with them on the ransom demand.

“This attack continues a trend of increasing brazenness by ransomware groups,” he said. “With no fear of repercussions, ransomware groups feel no target is off limits.”

U.S. authorities have struggled to curb a rash of cybercrime, chiefly ransomware actors, who hit hundreds of companies in nearly every industry annually. Just last week, U.S. officials said they were working on curtailing the funding routes of ransomware gangs by improving information-sharing on such criminals across a 40-country alliance.

The ICBC did not comment on whether Lockbit was behind the hack. It is common for victim organizations to refrain from publicly disclosing the names of cybercrime gangs.

Since Lockbit was discovered in 2020, the group has hit 1,700 U.S. organizations, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). Last month, it threatened Boeing with a leak of sensitive data it said it had found by breaching the company.

A CISA spokesperson referred questions about the ICBC hack to the U.S. Treasury Department.

While market sources said the impact of the hack appeared limited, it signaled how vulnerable systems at large organizations such as the bank continue to be to cybercriminals. Thursday’s incident is likely to raise questions over market participants’ cybersecurity controls and draw regulatory scrutiny.

ICBC said it had successfully cleared Treasury trades executed on Wednesday and repurchase agreements (repo) financing trades done on Thursday.

“In general, the event had a limited impact on the market,” said Scott Skrym, executive vice president for fixed income and repo at broker-dealer Curvature Securities.

Some market participants said trades going through ICBC were not settled due to the attack and affected market liquidity. It was not clear whether this contributed to the weak outcome of a 30-year bond auction on Thursday.

“There could have been maybe some technical issues with some participants not being able to access the market fully on the day,” said Michael Gladchun, associate portfolio manager, core plus fixed income, at Loomis Sayles.

The Financial Times reported earlier on Thursday that the U.S. Securities Industry and Financial Markets Association (SIFMA) told members that ICBC had been hit by ransomware that disrupted the U.S. Treasury market by preventing it from settling trades on behalf of other market players.

“We are aware of the cybersecurity issue and are in regular contact with key financial sector participants, in addition to federal regulators. We continue to monitor the situation,” a Treasury spokesperson said in a response to a question about the FT report. SIFMA declined to comment.

The Treasury market appeared to be functioning normally on Thursday, according to LSEG data.

english.pardafas.com

- Advertisement -

ΑΠΑΝΤΗΣΤΕ

εισάγετε το σχόλιό σας!
παρακαλώ εισάγετε το όνομά σας εδώ

The reCAPTCHA verification period has expired. Please reload the page.

Ροή ειδήσεων

ΣΧΕΤΙΚΑ ΑΡΘΡΑ

World Uyghur Congress (WUC) Amplifies Calls for Unified Action Against Chinese Repression

The 20th anniversary of the World Uyghur Congress in Munich served as a powerful rallying cry against the Chinese government’s escalating atrocities targeting the...

BRI is China’s Trojan Horse in Europe’s Backyard: Report

In an ever-shifting global landscape, where economic prowess meets geopolitical ambition, the allure of China’s Belt and Road Initiative (BRI) has cast its shadow...

Pakistan’s Gwadar port shows China’s Belt and Road can fail

In November 2016, Gwadar port symbolized stability, peace and prosperity for Pakistan — at least according to then-Prime Minister Nawaz Sharif. "This day is the dawn of...

Chinese society is rapidly militarising

The reports in China’s state media speak about ‘advancing national defence education in the new era’, teaching students to be ‘disciplined’, and ‘promoting the...

ΔΗΜΟΦΙΛΗ ΑΡΘΡΑ

Θανάσης Μπάφας: Πέθανε ο στρατηγός των Ειδικών Δυνάμεων-Συμμετείχε σε πολλές και επικίνδυνες αποστολές όπως στο Ερμπίλ

Πέθανε ο απόστρατος αξιωματικός, στρατιωτικός αναλυτής και στρατιωτικός συντάκτης Θανάσης Μπάφας, σκορπώντας θλίψη στις Ένοπλες Δυνάμεις. Ο εκλιπών το τελευταίο διάστημα νοσηλευόταν αρχικά στο 401...

Τουρκία: Μαφιόζοι, δικαστές και αστυνομικοί εμπλέκονται σε σχέδιο συνωμοσίας εις βάρος της κυβέρνησης Ερντογάν

Στα 12 ανέρχονται τα στελέχη της Αστυνομίας στην Τουρκία που απομακρύνθηκαν από τα καθήκοντά τους για εμπλοκή στο καταγγελλόμενο σχέδιο συνωμοσίας εις βάρος της...

«Ήρθε η ώρα η Ελλάδα να καταγγείλλει τη Συμφωνία των Πρεσπών» – Πώς μπορεί να γίνει αυτό νομικά

Να ενεργοποιηθεί άμεσα η καταγγελία της Συμφωνίας των Πρεσπών, με σκοπό την ακύρωσή της, λόγω της αμετανόητης και προσβλητικής ανυπόστατης πράξεως της Προέδρου Δημοκρατίας...