Ransomware attack on China's biggest bank disrupts Treasury market trades, reports say
A financial services business of China's biggest bank says it was it by a ransomware attack that reportedly disrupted trading in the U.S. Treasury market
Your support helps us to tell the story
From reproductive rights to climate change to Big Tech, The Independent is on the ground when the story is developing. Whether it's investigating the financials of Elon Musk's pro-Trump PAC or producing our latest documentary, 'The A Word', which shines a light on the American women fighting for reproductive rights, we know how important it is to parse out the facts from the messaging.
At such a critical moment in US history, we need reporters on the ground. Your donation allows us to keep sending journalists to speak to both sides of the story.
The Independent is trusted by Americans across the entire political spectrum. And unlike many other quality news outlets, we choose not to lock Americans out of our reporting and analysis with paywalls. We believe quality journalism should be available to everyone, paid for by those who can afford it.
Your support makes all the difference.A financial services business of China’s biggest bank says it was it by a ransomware attack that reportedly disrupted trading in the U.S. Treasury market.
Industrial and Commercial Bank of China Financial Services handles trades and other services for financial institutions. A statement on its website seen Friday said the ransomware attack this week disrupted some of its systems but that it had disconnected parts of the affected systems to limit the impact from the attack.
The company, which is based in New York, said it was investigating and had reported the problem to law enforcement.
All Treasury trades executed Wednesday and repo financing trades on Thursday were cleared, it said. It said ICBC’s banking, email and other systems were not affected.
The company gave no further details but reports said the attack was by LockBit, a Russian-speaking ransomware syndicate that does not target former Soviet countries. It is one of the most efficient ransomware variants around, according to the cybersecurity firm Emsisoft. Active since September 2019, it has attacked thousands of organizations.