ICBC's US broker-dealer hit by LockBit ransomware, disrupting Treasury trades

Organization
Industrial and Commercial Bank of China (ICBC)
Exploit
Ransomware
Industry
Financial Services

Systems at ICBC Financial Services, the US broker-dealer arm of the Industrial and Commercial Bank of China, were disrupted by ransomware on November 8, 2023. ICBC confirmed the attack, said it had disconnected and isolated the affected systems, launched an investigation with outside cybersecurity experts and informed authorities. It stated that head office systems and overseas units were not affected.

Reporting and researchers attributed the intrusion to the Russia-linked LockBit operation and to exploitation of Citrix Bleed, the critical NetScaler flaw tracked as CVE-2023-4966 that lets an attacker hijack authenticated sessions and bypass multifactor authentication. Security Affairs reported that ICBC was running a vulnerable Citrix NetScaler server, and noted Mandiant had seen the bug exploited as a zero-day since late August 2023, before Citrix published its October 10 bulletin.

The effect landed in the US Treasury market. ICBC Financial Services could not settle Treasury trades for other market participants, and some equity trades were affected as well. Hedge funds and asset managers rerouted transactions, and traders resorted to moving trade data physically, with couriers carrying USB drives across Manhattan. Reuters reported that the unsettled trades left the unit temporarily owing Bank of New York Mellon around $9 billion, and that ICBC injected capital into the subsidiary.

ICBC Financial Services said it cleared the Treasury trades executed on November 8 and the repo financing trades done on November 9. LockBit claimed the bank had paid a ransom, which ICBC did not confirm.

Sources