Ransomware attack on China’s ICBC disrupts Treasury market trades

A ransomware attack on the US unit of Industrial and Commercial Bank of China (ICBC) disrupted some trades in the US Treasury market on Thursday (Nov 9) but market sources said the impact seemed to be limited.

ICBC Financial Services said in a statement a ransomware attack resulted in disruption to certain systems and it was conducting an investigation and “progressing its recovery efforts”.

The bank said it had successfully cleared Treasury trades executed on Wednesday and repurchase agreements (repo) financing trades done on Thursday.

“In general, the event had a limited impact on the market,” said Scott Skrym, executive vice president for fixed income and repo at broker-dealer Curvature Securities.

In ransomware attacks, hackers encrypt an organisation’s systems and demand ransom payments in exchange for unlocking them. It was not immediately clear who was behind the attack.

Bloomberg reported later on Thursday that a prolific criminal gang known as Lockbit, which has ties to Russia, is suspected to have orchestrated the hack, citing people familiar with the situation.

While ransomware attacks have been soaring across a range of sectors in recent years, they have rarely disrupted a major financial market. Thursday’s incident is likely to raise questions over market participants’ cyber security controls and potentially draw regulatory scrutiny.

Some market participants said trades going through ICBC, China’s largest commercial lender by assets, were not settled due to the attack and this affected market liquidity. It was not clear whether this contributed to the weak outcome of a 30-year bond auction on Thursday.

“There could have been maybe some technical issues with some participants not being able to access the market fully on the day,” said Michael Gladchun, associate portfolio manager, core plus fixed income, at Loomis Sayles.

The Financial Times reported earlier on Thursday that the US Securities Industry and Financial Markets Association (SIFMA) told members that ICBC had been hit by ransomware that disrupted the US Treasury market by preventing it from settling trades on behalf of other market players.

“We are aware of the cybersecurity issue and are in regular contact with key financial sector participants, in addition to federal regulators. We continue to monitor the situation,” a Treasury spokesperson said in response to a question about the FT report. SIFMA declined to comment.

The Treasury market appeared to be functioning normally on Thursday, according to LSEG data.

According to the data platform Statista, globally organisations detected 493.33 million ransomware attack attempts last year. Lockbit was the most prolific ransomware operator throughout 2022, according to the Financial Services Information Sharing and Analysis Center.