/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Experts say LockBit is behind the Industrial and Commercial Bank of China hack, a “ransomware as a service” group that hacked the UK's Royal Mail, among others

- LockBit is what's known as a ‘ransomware as a service’ group  — It is one of the most prolific ransomware attackers in world

Bloomberg

Context & Ripple Effects

The alleged ICBC breach places LockBit in a run of incidents spanning essential services and financial-market infrastructure. Earlier coverage tied the group to Royal Mail disruptions that stopped overseas deliveries and to an attack on ION Trading that upended derivatives trading globally.

That cross-sector record matters because LockBit is described here as ransomware-as-a-service: a model in which a prolific operator’s reach can extend beyond any one victim or industry.

First-order effects

  • ICBC must treat the alleged LockBit involvement as a live incident-response and recovery issue, while the attribution further associates LockBit with a major financial institution.
  • The allegation adds to LockBit’s documented pattern of targeting organizations whose outages can disrupt downstream services, following the Royal Mail attack that halted international shipping.

Second-order effects

  • Financial-sector operators and their technology providers have a clearer reason to prioritize ransomware resilience and continuity planning against the same threat group, particularly after the prior ION-related market disruption.
  • LockBit’s ransomware-as-a-service positioning means the risk is not confined to a single set of operators; defenders must account for a broader ecosystem of actors using a shared criminal platform.

Third-order effects

  • If attacks continue to affect institutions with wide operational dependencies, ransomware will increasingly be treated as a systemic continuity risk rather than solely an individual-company security problem.
  • The LockBit pattern also underscores the durability of the service-model threat: later coverage found that even a major law-enforcement blow can be followed by groups attempting to regroup.

The trend: Ransomware-as-a-service is turning cyber extortion into a cross-sector operational-risk problem, with attacks on infrastructure and financial intermediaries carrying effects beyond the initial victim.

Discussion

  • @hongpong @hongpong on x
    https://www.ft.com/... hackers affect liquidity of US treasuries, major Chinese bank hit, lockbit!🧐 [image]
  • @wublockchain Wu Blockchain on x
    The U.S. subsidiary of China's largest bank, ICBCFS, was attacked by the Russian ransomware LockBit, causing chaos in the U.S. Treasury market. LockBit generally only accepts payments in cryptocurrencies such as Bitcoin, Monero or Zcash. It encrypts files on the victim's computer…
  • @sino_market @sino_market on x
    The cyberattack forced #ICBC's US unit to send the required settlement details to those parties by a messenger carrying a USB stick as the state-owned lender raced to limit the damage.-Bloomberg #Lockbit
  • @vxunderground @vxunderground on x
    The big whoopsie has hit. Earlier this morning nerds began informing us that equity traders were unable to place trades (or clear previous ones) through ICBC (Industrial and Commercial Bank of China). An emergency notice was sent out stating: “ICBC is currently unable to...
  • @grdecter @grdecter on x
    🚨Just in: Worlds biggest bank forced to trade via UBS stick after hack. Chinas ICBC was hit by a cyberattack and was unable to clear U.S Treasury trades. This forced the bank to send the required settlement details via messenger carrying a thumb drive. Nuts!
  • @joemosch Joe Moschella on x
    Oh boy. Lots of people going to wonder how ICBC can be that disruptive to an auction, or if there's more to this. “The attack prevented ICBC from settling Treasury trades on behalf of other market participants, according to traders and banks.” https://www.ft.com/...
  • @parrotcapital @parrotcapital on x
    The irony of the Industrial and Commercial Bank of China #ICBC getting hit with a ransomware attack...when they're linked to the crypto ecosystem via #Tether $USDT fraud commercial paper...is honestly too rich. Now the US Treasury market is at risk. 🚩 Crypto is a #NatSec risk. [i…
  • @bond_dog_51 Brent Xu on x
    ICBC, the worlds largest bank by market capitalization was just hit by a cyber attack that halted trading in billions of treasury bond products. The next generation of bond market builders should take this as a lesson to work on deploying more decentralized infra. DeFi infra has.…
  • @sonalibasak Sonali Basak on x
    The world's largest lender, based in China, experienced a cyber attack that ended up impacting fresh Treasury issuance, enough to spark hiccups in one of the most safe and liquid markets on the globe 😳😳😳 https://giftarticle.ft.com/...
  • @lisaabramowicz1 Lisa Abramowicz on x
    Shortly after the “outright bad” auction, this comes out in the FT: https://www.ft.com/...