Ransomware attack on China's ICBC disrupts Treasury market trades | Inquirer Business

Ransomware attack on China’s ICBC disrupts Treasury market trades

/ 07:46 AM November 10, 2023

People walk past a branch of Industrial and Commercial Bank of China

People walk past a branch of Industrial and Commercial Bank of China (ICBC) in Beijing, China April 1, 2019. REUTERS/Florence Lo/File photo

A ransomware attack on Industrial and Commercial Bank of China (ICBC) disrupted some trades in the U.S. Treasury market on Thursday but market sources said the impact seemed to be limited.

ICBC Financial Services said in a statement a ransomware attack resulted in disruption to certain systems and it was conducting an investigation and “progressing its recovery efforts.”

Article continues after this advertisement

The bank said it had successfully cleared Treasury trades executed on Wednesday and repurchase agreements (repo) financing trades done on Thursday.

FEATURED STORIES

“In general, the event had a limited impact on the market,” said Scott Skrym, executive vice president for fixed income and repo at broker-dealer Curvature Securities.

In ransomware attacks, hackers encrypt an organization’s systems and demand ransom payments in exchange for unlocking them. It was not immediately clear who was behind the attack.

Article continues after this advertisement

While ransomware attacks have been soaring across a range of sectors in recent years, they have rarely disrupted a major financial market. Thursday’s incident is likely to raise questions over market participants’ cyber security controls and potentially draw regulatory scrutiny.

Article continues after this advertisement

Some market participants said trades going through ICBC, China’s largest commercial lender by assets, were not settled due to the attack and this affected market liquidity. It was not clear whether this contributed to the weak outcome of a 30-year bond auction on Thursday.

Article continues after this advertisement

“There could have been maybe some technical issues with some participants not being able to access the market fully on the day,” said Michael Gladchun, associate portfolio manager, core plus fixed income, at Loomis Sayles.

The Financial Times reported earlier on Thursday that the U.S. Securities Industry and Financial Markets Association (SIFMA) told members that ICBC had been hit by ransomware that disrupted the U.S. Treasury market by preventing it from settling trades on behalf of other market players.

Article continues after this advertisement

“We are aware of the cybersecurity issue and are in regular contact with key financial sector participants, in addition to federal regulators. We continue to monitor the situation,” a Treasury spokesperson said in a response to a question about the FT report. SIFMA declined to comment.

The Treasury market appeared to be functioning normally on Thursday, according to LSEG data.

READ: 50% of firms with cyberdefenses still victimized

Your subscription could not be saved. Please try again.
Your subscription has been successful.

Subscribe to our daily newsletter

By providing an email address. I agree to the Terms of Use and acknowledge that I have read the Privacy Policy.

According to the data platform Statista, globally organizations detected 493.33 million ransomware attack attempts last year. Cyber criminal group Lockbit was the most prolific ransomware operator throughout 2022, according to the Financial Services Information Sharing and Analysis Center.

TAGS: China, icbc, ransomware

Your subscription could not be saved. Please try again.
Your subscription has been successful.

Subscribe to our newsletter!

By providing an email address. I agree to the Terms of Use and acknowledge that I have read the Privacy Policy.

© Copyright 1997-2024 INQUIRER.net | All Rights Reserved

This is an information message

We use cookies to enhance your experience. By continuing, you agree to our use of cookies. Learn more here.