Experts say LockBit is behind the Industrial and Commercial Bank of China hack, a “ransomware as a service” group that hacked the UK's Royal Mail, among others
- LockBit is what's known as a ‘ransomware as a service’ group — It is one of the most prolific ransomware attackers in world
That cross-sector record matters because LockBit is described here as ransomware-as-a-service: a model in which a prolific operator’s reach can extend beyond any one victim or industry.
First-order effects
ICBC must treat the alleged LockBit involvement as a live incident-response and recovery issue, while the attribution further associates LockBit with a major financial institution.
Financial-sector operators and their technology providers have a clearer reason to prioritize ransomware resilience and continuity planning against the same threat group, particularly after the prior ION-related market disruption.
LockBit’s ransomware-as-a-service positioning means the risk is not confined to a single set of operators; defenders must account for a broader ecosystem of actors using a shared criminal platform.
Third-order effects
If attacks continue to affect institutions with wide operational dependencies, ransomware will increasingly be treated as a systemic continuity risk rather than solely an individual-company security problem.
The LockBit pattern also underscores the durability of the service-model threat: later coverage found that even a major law-enforcement blow can be followed by groups attempting to regroup.
The trend: Ransomware-as-a-service is turning cyber extortion into a cross-sector operational-risk problem, with attacks on infrastructure and financial intermediaries carrying effects beyond the initial victim.
The U.S. subsidiary of China's largest bank, ICBCFS, was attacked by the Russian ransomware LockBit, causing chaos in the U.S. Treasury market. LockBit generally only accepts payments in cryptocurrencies such as Bitcoin, Monero or Zcash. It encrypts files on the victim's computer…
The cyberattack forced #ICBC's US unit to send the required settlement details to those parties by a messenger carrying a USB stick as the state-owned lender raced to limit the damage.-Bloomberg #Lockbit
The big whoopsie has hit. Earlier this morning nerds began informing us that equity traders were unable to place trades (or clear previous ones) through ICBC (Industrial and Commercial Bank of China). An emergency notice was sent out stating: “ICBC is currently unable to...
🚨Just in: Worlds biggest bank forced to trade via UBS stick after hack. Chinas ICBC was hit by a cyberattack and was unable to clear U.S Treasury trades. This forced the bank to send the required settlement details via messenger carrying a thumb drive. Nuts!
Oh boy. Lots of people going to wonder how ICBC can be that disruptive to an auction, or if there's more to this. “The attack prevented ICBC from settling Treasury trades on behalf of other market participants, according to traders and banks.” https://www.ft.com/...
The irony of the Industrial and Commercial Bank of China #ICBC getting hit with a ransomware attack...when they're linked to the crypto ecosystem via #Tether $USDT fraud commercial paper...is honestly too rich. Now the US Treasury market is at risk. 🚩 Crypto is a #NatSec risk. [i…
ICBC, the worlds largest bank by market capitalization was just hit by a cyber attack that halted trading in billions of treasury bond products. The next generation of bond market builders should take this as a lesson to work on deploying more decentralized infra. DeFi infra has.…
The world's largest lender, based in China, experienced a cyber attack that ended up impacting fresh Treasury issuance, enough to spark hiccups in one of the most safe and liquid markets on the globe 😳😳😳 https://giftarticle.ft.com/...