-
US actor Jared Leto denies latest accusations of sexual assault
-
Campari - king of the spritz - hopes to conquer American heartland
-
Danube drops to 'historic lows' as fresh heatwave hits
-
Mancini wants Italy back to trophy-winning ways
-
US Federal Reserve holds rates steady as inflation hawks call for hike
-
Torrey Pines added to new PGA Tour top-level series from 2028
-
Eala beats defending champ Fernandez in Washington
-
Air France-KLM and Lufthansa bid for Portugal's TAP airline
-
US man accused of destroying evidence by wiping phone at airport
-
Korda seeks 'control' as she chases history at women's British Open
-
BTS pulls out of Grammys after Asian pop category introduction
-
Profits soar at Airbus as it delivers more planes
-
Judge orders Amy Winehouse's father to pay nearly £1mn to her friends
-
US-Saudi strikes in Iraq kill 20, including Iranians
-
Crisis-hit Cuba opens pharmacies, gas stations to private firms
-
Brazil court scrutinizes Jair Bolsonaro deepfake endorsing son
-
Pro-Kremlin TV commentator ordered to leave France, under house arrest
-
OpenAI says rogue AI agent attack hit other companies
-
'I started crying': Battle to tame fresh blaze near French seaside
-
Irish singer, musician Glen Hansard killed in motorbike crash at 56
-
Former top US Covid expert Fauci declines to answer hostile Senate questioning
-
Ukraine appeals against Russian return to Olympics
-
Neymar says his time playing for Brazil 'is over'
-
Rheinmetall shares surge after armsmaker reports record profit
-
F1 boss says season to finish in Europe if Gulf races cancelled
-
Israel army hit Gaza mosque, says used for Hamas 'weapons storage'
-
Spanish wildfire evacuees go home as France hit by new heat alert
-
Trump says US to hit Iran hard
-
French DJ Kavinsky, famed for 'Nightcall', found dead in Paris
-
UBS second-quarter net profit up 17% to $2.8 billion
-
How an AFP beach snap became emblem of Europe's wildfire summer
-
FIFA hit by furious backlash over plans to sell stake in competitions
-
More than half of England 'officially in drought': UK govt
-
TRX Spot and Perpetuals Listing Launches on Backpack, Expanding Access to the TRON Ecosystem
-
MEXC Integrates World-Check to Fortify Institutional Grade Compliance Architecture
-
Tel on target as Tottenham held to 1-1 draw by Sydney FC
-
Tech stocks plunge further but London market hits record high
-
UN chief to convene new talks on divided Cyprus
-
Spain's three worst wildfires since 1961 happened in last two years
-
'No home': Spanish pensioner returns to charred ruins after wildfire
-
FIFA proposal 'an outright attack on football', says DFB vice-president
-
Nepal's tiger numbers climb 20 percent to estimated 429: survey
-
Principal reaction to FIFA's private investor plan
-
Germany's Merz under fire over chaotic reshuffle
-
Ireland's Harrington named as vice-captain for 2027 Ryder Cup
-
US, Saudi strike Iraq alliance in expanding war
-
Spain returns wildfire evacuees as France braces for worsening weather
-
FIFA's plans to sell $4.2bn stake in its tournaments widely criticised
-
Neuer 'very likely' to retire at end of season
-
Russia seeks arrest of Telegram chief Durov
US arm of China mega-lender ICBC hit by ransomware attack
The US arm of China's largest bank said it was hit by a ransomware attack, forcing clients to reroute trades and disrupting the US Treasury market.
Ransomware attacks typically access vulnerable computer systems and encrypt or steal data, before sending a ransom note demanding payment in exchange for decrypting the data or not releasing it publicly.
The Industrial and Commercial Bank of China Financial Services (ICBC FS) said Thursday it "experienced a ransomware attack that resulted in disruption to certain (financial services) systems."
"Immediately upon discovering the incident, ICBC FS disconnected and isolated impacted systems to contain the incident," the New York-based bank said, adding that it was investigating the attack and working on recovery.
ICBC FS said it had successfully cleared US Treasury trades executed Wednesday and repurchasing (repo) financing trades Thursday.
Slack demand for $24 billion in 30-year US Treasury bonds that were auctioned Thursday came as a surprise to some analysts.
This sale "attracted very poor demand, one of the weakest I can remember," Karl Haeling of the bank LBBW told AFP.
But demand at this sale "might not have been as bad as advertised," said Patrick O'Hare of Briefing.com.
"That's because subsequent reports have indicated that the US financial services division of China's Industrial and Commercial Bank was hit by a ransomware cyberattack yesterday that disrupted trades in the Treasury market."
Richard Flax, chief investment officer at Moneyfarm, put it this way: "Finally, a large Chinese bank suffered a cyber-attack that impacted its ability to trade in US Treasuries. Some commentators argue that that, rather than weak demand, was behind the relatively poor US government bond auction."
Bloomberg reported that some trades handled by ICBC FS on Thursday were transported across Manhattan on a USB stick as messengers manually relayed required settlement details.
China's foreign ministry said Friday that "the business systems and office systems of the head office of ICBC and other domestic and foreign branches and subsidiaries within the group are normal."
"As far as we know, ICBC has paid close attention to this matter, and has done a good job in emergency handling and supervision and communication, striving to minimize the impact of risks and losses," foreign ministry spokesman Wang Wenbin said at a regular news briefing.
"At present, the business systems and office systems of the head office of ICBC and other domestic and foreign branches and subsidiaries within the group are normal."
US media reported that the hack was executed using software created by Lockbit, the Russian-speaking hacking group known for scrambling files on a host's computer and flashing up messages demanding cryptocurrency payment to resolve the issue.
US aircraft manufacturer Boeing was hit with an attack from Lockbit last week.
Last year, LockBit was "the most deployed ransomware variant across the world and continues to be prolific in 2023," according to the US Cybersecurity and Infrastructure Security Agency.
The US Justice Department said in May that LockBit ransomware had been used in more than 1,400 attacks globally.
LockBit has targeted critical infrastructure and large industrial groups, with ransom demands ranging from €5 million to €70 million.
The group attacked Britain's Royal Mail in early January and a Canadian children's hospital in December.
I.Meyer--BTB