EquiLend tells employees data was stolen in January ransomware attack
- Organization
- EquiLend
- Exploit
- Ransomware
- Industry
- Financial Services
EquiLend, a securities lending technology firm whose Next Generation Trading platform processes about $113.5 billion of transactions a day for more than 120 firms across over 40 markets, pulled systems offline in late January 2024 after detecting unauthorized access. EquiLend said it identified the issue that placed portions of its systems offline on January 22, 2024, and announced the outage publicly on January 24. The company said it had launched an investigation and brought in outside cybersecurity specialists, and warned that restoration would take several days. Staff reverted to manual processes while the platform was down.
Client-facing services were restored by February 5, 2024, but EquiLend gave no detail on the scope of the intrusion at the time. In mid-March the company notified the Massachusetts Office of Consumer Affairs and Business Regulation and began sending letters to affected people.
The notification said the attackers took employee personal information including names, dates of birth and Social Security numbers, along with EquiLend payroll data. The company said it had not identified evidence that client transaction data was accessed or exfiltrated, and no evidence that the stolen information had been used to commit identity theft or fraud. Affected individuals were offered two years of identity theft protection at no cost.
The LockBit ransomware group claimed the attack, according to Bloomberg reporting cited by SecurityWeek. LockBit's infrastructure was disrupted by an international law enforcement operation in February 2024, weeks after the EquiLend incident.