HomeSecurityICBC Bank paid to end ransomware attack

ICBC Bank paid to end ransomware attack

A hacker group says the Industrial and Commercial Bank of China (ICBC) has paid a ransom after a attack last week.

See also: LockBit ransomware gang leaked Boeing data

ICBC

Last week, the bank, which is China's largest, was disconnected from an platform for US Treasury bonds operated by BNY Mellon after a ransomware attack.

A spokesman for a hacking group using the Lockbit ransomware virus claims that ICBC has paid a ransom, Reuters reported on Monday (November 13). Reuters noted that it was unable to independently verify the group's claim

A Lockbit spokesperson told Reuters in a message sent via the online messaging app Tox: “Ransom paid, deal done.”

ICBC confirmed the attack in a statement on its financial services website last week, saying it disrupted some of its systems.

“As soon as the incident was discovered, ICBC FS disconnected and isolated the affected systems to contain the incident,” the bank said. “ICBC FS is conducting an extensive investigation and proceeding with recovery efforts with the support of its professional information security team.”

The attack comes at a time of increasing ransomware incidents worldwide, targeting both individuals and organizations. These attacks involve malicious actors breaking into computer systems and encrypting data, then demanding a ransom for the decryption key.

See also: FBI: Royal ransomware has compromised 350 companies

Some of the most prominent examples this year include the attack that disrupted MGM Resorts ' casino operations over the summer and an attack on cleaning products company Clorox , which appears to have affected the company's quarterly earnings.

ransomware

In response to these attacks, a 40-nation alliance led by the United States, the International Counter Ransomware Initiative, said it would pledge not to pay ransoms to cybercriminals. The alliance hopes to deprive hackers of their sources of revenue by improving the sharing of information about ransom-paying bank accounts.

“As long as there are flows of money to criminals, this is a problem that will continue to grow,” Anne Neuberger, the White House deputy national security adviser for cybersecurity and new technologies, told reporters on October 31.

The Federal Trade Commission (FTC) also works to combat ransomware and other cyberattacks, sometimes through "implementing a comprehensive data security enforcement program aimed at ensuring that companies take appropriate steps to protect the personal data they hold from such attacks."

The common methods used by hackers to carry out ransomware attacks on banks are multiple. One of the main ways is by sending malicious emails (phishing emails) that contain malicious attachments or malicious links. When the user opens the attachment or clicks on the link, the malicious code is executed and the ransomware attack begins.

See also: Industrial & Commercial Bank of China (ICBC): “Hit” by ransomware

Another method used is exploiting vulnerabilities in software. Hackers look for weaknesses in software used by banks and use specially designed malicious code to break into the system and carry out the ransomware attack.

Hackers also use the remote desktop protocol (RDP) technique to break into bank networks. Depending on the banks' failure to properly secure RDP connections and use weak password management, hackers can gain access to the networks and execute the ransomware attack.

Source: pymnts

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS