-
#IAmJaneDoe: online support campaign in US university rape case
-
Trainer Scott gets perfect Arc boost with top notch double
-
Brazil shine on Selecao's first visit to India
-
Ex-PM says Putin cannot admit 'mistake' over Ukraine
-
Zverev sets up Djokovic quarter-final at China Open, Rybakina out
-
Houthis say Saudi Arabia launches dozens of strikes on Yemen capital
-
Happier at home, Bordeaux hammer Lyon in Top 14
-
Qatar and Abu Dhabi F1 Grand Prix to go ahead - F1 boss
-
Lula, Bolsonaro in final push for votes ahead of knife-edge election
-
South Korea lift gloom with smash-and-grab Games football gold
-
Boisterous fashion week barnstorms 'sleepy' Nigerian capital
-
Ireland news conference before Israel game cut short amid tensions
-
UAE investigators say flydubai co-pilot was planning 'terrorist act'
-
Protests over housing flare in Spain after relief measures rejected
-
Rahul smacks century in India v Windies ODI
-
Zverev thrashes Shang to set up Djokovic quarter-final at China Open
-
Daryz seeks to join exclusive club of dual Arc winners
-
Turkey football ref chief jailed pending trial for graft
-
Russia warns diplomats to leave Kyiv over new strikes threat
-
North Korea says test of intermediate-range strategic missile included use of AI
-
Olympic champ Zheng rebukes rowdy home crowd at China Open
-
Rampant Sayers leads Hong Kong to third men's rugby gold in a row
-
World No.1 Sinner pulls out of Shanghai Masters to delay return
-
Ethiopia's Tigray rebels abandon regional capital as govt advances
-
Red Bull's Verstappen grabs pole position for Bahrain GP
-
Bulgaria's Tsar Samuel returns 'home' after 1,000 years
-
India beat Pakistan in blockbuster as golfer Kim wins 'crazy' gold
-
'Glad it's over': Kim powers to Games gold and military exemption
-
India beat arch-rivals Pakistan to win Asian Games cricket gold
-
After 11 World Cups, football finally comes home for one Indian fan
-
Ethiopia's Tigray rebels abandon regional capital as govt advances: journalist
-
Marc Marquez wins sprint at Japan MotoGP, Martin grabs pole
-
Tom Kim powers to Games gold and exemption from military service
-
Alcaraz fends off Arnaldi to reach Japan Open quarters
-
Split loyalties for Indian football fans at Brazil friendly
-
Antonelli tops times in final practice at Bahrain GP
-
India-Pakistan blockbuster brings cricket fever to Japan baseball field
-
Gauff digs deep to beat Osorio in China Open second round
-
Wong waiting on Rafa after winning Asian Games tennis gold
-
Fresh protests to hit Spain after housing measures defeated
-
With Russia next door and rising costs, Latvia goes to the polls
-
'He's here with me': Japan cycle queen dedicates gold to late brother
-
Penalty hero rues empty seats as Games hosts Japan win football gold
-
Japan Olympic chief says 'lot more' athletes at Games than expected
-
North Korea fires ballistic missile after Seoul's apology demand
-
Asian carmakers besting US rivals at home, China poised to strike
-
US regulator finds Boeing 737 MAX software bug 'not a safety concern'
-
Widgets & Web Offers All-Inclusive Investor Relations Websites for Public Companies, IPOs and SPACs
-
Ohtani 'managing' injuries as Dodgers launch MLB post-season
-
Adams named new US captain to 2030 World Cup
US arm of China mega-lender ICBC hit by ransomware attack
The US arm of China's largest bank said it was hit by a ransomware attack, forcing clients to reroute trades and disrupting the US Treasury market.
Ransomware attacks typically access vulnerable computer systems and encrypt or steal data, before sending a ransom note demanding payment in exchange for decrypting the data or not releasing it publicly.
The Industrial and Commercial Bank of China Financial Services (ICBC FS) said Thursday it "experienced a ransomware attack that resulted in disruption to certain (financial services) systems."
"Immediately upon discovering the incident, ICBC FS disconnected and isolated impacted systems to contain the incident," the New York-based bank said, adding that it was investigating the attack and working on recovery.
ICBC FS said it had successfully cleared US Treasury trades executed Wednesday and repurchasing (repo) financing trades Thursday.
Slack demand for $24 billion in 30-year US Treasury bonds that were auctioned Thursday came as a surprise to some analysts.
This sale "attracted very poor demand, one of the weakest I can remember," Karl Haeling of the bank LBBW told AFP.
But demand at this sale "might not have been as bad as advertised," said Patrick O'Hare of Briefing.com.
"That's because subsequent reports have indicated that the US financial services division of China's Industrial and Commercial Bank was hit by a ransomware cyberattack yesterday that disrupted trades in the Treasury market."
Richard Flax, chief investment officer at Moneyfarm, put it this way: "Finally, a large Chinese bank suffered a cyber-attack that impacted its ability to trade in US Treasuries. Some commentators argue that that, rather than weak demand, was behind the relatively poor US government bond auction."
Bloomberg reported that some trades handled by ICBC FS on Thursday were transported across Manhattan on a USB stick as messengers manually relayed required settlement details.
China's foreign ministry said Friday that "the business systems and office systems of the head office of ICBC and other domestic and foreign branches and subsidiaries within the group are normal."
"As far as we know, ICBC has paid close attention to this matter, and has done a good job in emergency handling and supervision and communication, striving to minimize the impact of risks and losses," foreign ministry spokesman Wang Wenbin said at a regular news briefing.
"At present, the business systems and office systems of the head office of ICBC and other domestic and foreign branches and subsidiaries within the group are normal."
US media reported that the hack was executed using software created by Lockbit, the Russian-speaking hacking group known for scrambling files on a host's computer and flashing up messages demanding cryptocurrency payment to resolve the issue.
US aircraft manufacturer Boeing was hit with an attack from Lockbit last week.
Last year, LockBit was "the most deployed ransomware variant across the world and continues to be prolific in 2023," according to the US Cybersecurity and Infrastructure Security Agency.
The US Justice Department said in May that LockBit ransomware had been used in more than 1,400 attacks globally.
LockBit has targeted critical infrastructure and large industrial groups, with ransom demands ranging from €5 million to €70 million.
The group attacked Britain's Royal Mail in early January and a Canadian children's hospital in December.
G.Haefliger--VB