World's biggest bank hit by ransomware, forced to trade via USB stick (2024)

The US trading arm of the Industrial and Commercial Bank of China (ICBC) has been hit by a ransomware attack that reportedly forced it to handle trades via messengers carrying USB thumb drives across Manhattan.

A notice on the ICBC Financial Services website confirmed that its systems were disrupted on November 8 2023, and that it is "conducting a thorough investigation" into the security incident, and has informed relevant authorities.

World's biggest bank hit by ransomware, forced to trade via USB stick (2)

ICBC, the world's biggest bank, is believed to have been attacked by the Russia-linked LockBit ransomware gang that has numbered the likes of IT giant Accenture, the German autoparts firm Continental, and the UK's Royal Mail, amongst its many past victims.

According to the company, the affected systems are isolated from ICBC's head office, and overseas units are not impacted.

Security researcher Kevin Beaumont posted on Mastodon that ICBC Financial Services had not patched its Citrix NetScaler Gateway appliance against the critical Citrix Bleed vulnerability (CVE-2023-4966), which Citrix issued a fix for last month.

The vulnerability is considered particularly serious because of how it can be exploited to allow hackers to easily bypass authentication - opening avenues for ransomware groups to break into corporate systems.

The same Citrix Bleed vulnerability has been actively exploited for weeks in attacks against unpatched government networks and corporations.

World's biggest bank hit by ransomware, forced to trade via USB stick (2024)

FAQs

World's biggest bank hit by ransomware, forced to trade via USB stick? ›

The US unit of the Industrial & Commercial Bank of China (ICBC) was hit by a cyberattack, causing disruption to US Treasury trades. ICBC had to send settlement details to parties via a messenger carrying a USB stick after the hacked systems were disconnected.

What is the world's largest bank hit by ransomware? ›

ICBC, the world's largest lender by assets, said Thursday its financial services arm experienced a ransomware attack “that resulted in disruption to certain” systems. Security expert have said ransomware from the hacking group LockBit was used to carry out the cyberattack on ICBC.

What was the largest ransomware attack? ›

However, many users hadn't updated their systems, leaving their computers vulnerable to cyber attacks. One of the costliest and most famous ransomware attacks in history, WannaCry cost an estimated $4 billion.

Which bank got hacked? ›

The Bank of America has not yet revealed how many users were affected by the data breach. However, a letter filed with the Attorney General of Maine disclosed that 57,028 individuals were impacted. This cybersecurity incident emphasizes the importance of securing customer data.

Did Bank of America have a data breach? ›

In the case of the Bank of America data breach, LockBit found Infosys McCamish Systems (IMS), a Indian tech services giant, to serve this purpose. The first sign of the breach was the “unavailability of certain applications and systems in IMS.” LockBit claims that over 2,000 systems were encrypted during the breach.

Which world's biggest bank forced to trade via USB stick? ›

The US unit of the Industrial & Commercial Bank of China (ICBC) was hit by a cyberattack, causing disruption to US Treasury trades.

Can I get my money back if my bank account has been hacked? ›

Am I going to get my money back? Your bank should refund any money stolen from you as a result of fraud and identity theft. They should do this as soon as possible - ideally by the end of the next working day after you report the problem.

What bank is the most secure from hackers? ›

JPMorgan Chase, the financial institution that owns Chase Bank, topped our experts' list because it's designated as the world's most systemically important bank on the 2023 G-SIB list. This designation means it has the highest loss absorbency requirements of any bank, providing more protection against financial crisis.

Which bank has the largest data breach? ›

The 10 Biggest Data Breaches in the Finance Sector
  • Equifax Data Breach. ...
  • Heartland Payment Systems Data Breach. ...
  • Capital One Data Breach. Date: March 2019. ...
  • JPMorgan Chase Data Breach. Date: October 2014. ...
  • Experian. Date: August 2020. ...
  • Block. Date: Apr 2022. ...
  • Desjardins Group. Date: June 2019. ...
  • Westpac Banking Corporation. Date: June 2013.

Can hackers see my bank account? ›

If a hacker uncovers the one password, that can make it easier for them to access your other accounts. This can potentially include bank accounts with your sensitive financial or payment information. Jeremiah Grossman, cybersecurity expert and CEO of an IT startup, agrees.

What top US banks are under investigation? ›

Attorney General Paxton joined a multistate investigation into Bank of America Corporation, Wells Fargo & Company, Morgan Stanley & Co. LLC, JPMorgan Chase & Co., The Goldman Sachs Group, Inc., and Citigroup Inc. for potential violations of consumer protection laws.

Where can I check if my data has been breached? ›

Use Avast Hack Check to see what accounts have been compromised. If you find any, change their passwords immediately — use our password generator for the best results.

Which Bank crashed in us? ›

The largest bank failures in U.S. history were Washington Mutual, First Republic Bank and Silicon Valley Bank.

Which country is most affected by ransomware? ›

In 2022, the number of ransomware attacks in the United States amounted to around 217.5 million, making it the most targeted country worldwide.

What is the world's largest data breach and hack? ›

In January 2024, a data breach dubbed the "mother of all breaches" was uncovered. Over 26 billion records, including some from Twitter, Adobe, Canva, LinkedIn, and Dropbox, were found in the database. No organization immediately claimed responsibility.

Which industry has the most ransomware attacks? ›

In 2023, the U.S. Internet Crime Complaint Center (IC3) received approximately 250 complaints indicating ransomware attacks in healthcare organizations. The second most victimized industry sector was critical manufacturing. Government facilities ranked third, with 156 complaints.

What is the largest hack in the US? ›

26 Biggest Data Breaches in US History
  1. 1. Yahoo! Date: 2013-2016. ...
  2. Microsoft. Date: January 2021. ...
  3. Real Estate Wealth Network. Date: December 2023. ...
  4. First American Financial Corp. Date: May 2019. ...
  5. 5. Facebook. Date: April 2021. ...
  6. LinkedIn. Date: April 2021. ...
  7. JPMorgan Chase. Date: June 2014. ...
  8. Home Depot. Date: April 2014.
Feb 20, 2024

Top Articles
Latest Posts
Article information

Author: Rob Wisoky

Last Updated:

Views: 6581

Rating: 4.8 / 5 (68 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Rob Wisoky

Birthday: 1994-09-30

Address: 5789 Michel Vista, West Domenic, OR 80464-9452

Phone: +97313824072371

Job: Education Orchestrator

Hobby: Lockpicking, Crocheting, Baton twirling, Video gaming, Jogging, Whittling, Model building

Introduction: My name is Rob Wisoky, I am a smiling, helpful, encouraging, zealous, energetic, faithful, fantastic person who loves writing and wants to share my knowledge and understanding with you.