ICBC Financial Services Hit by Ransomware Attack, Disrupting U.S. Treasury Market Operations

Published:

ICBC Financial Services (FS) fell victim to a ransomware attack on November 8, 2023 (U.S. Eastern Time), causing disruptions to key FS systems. The bank promptly disconnected and isolated affected systems to contain the incident. While ICBC FS is actively investigating the breach and working on recovery with its information security experts, it has successfully cleared U.S. Treasury and Repo financing trades.

The incident, reported to law enforcement, specifically impacted ICBC FS, and its business and email systems operate independently from the ICBC Group. Notably, the ICBC New York Branch, ICBC Head Office, and other affiliated institutions domestically and abroad remain unaffected.

The ransomware attack led to disruptions in the U.S. Treasury market, affecting equities clearing. Securities Industry and Financial Markets Association members were notified of the incident, causing ICBC’s clearing customers to experience connectivity issues with DTCC/NSCC.

Security expert Kevin Beaumont indicated that ICBC’s vulnerability was linked to an unpatched Citrix server, exposing the bank to the ‘Citrix Bleed’ exploit actively utilized by ransomware groups. ICBC, the world’s largest commercial bank by revenue, faces significant challenges as it works to restore systems and services following this cyberattack.

U.S. Treasury officials are closely monitoring the situation, acknowledging the potential implications of this cybersecurity issue on the broader financial sector. ICBC has not issued an official statement, but industry sources confirm the ransomware attack, emphasizing the urgency of addressing vulnerabilities in financial institutions.

Related articles

spot_img