www.resecurity.com
LockBit Ransomware Targets ICBC Financial Services and U.S. Bank
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On November 8, 2025, the LockBit ransomware group attacked ICBC Financial Services, disrupting U.S. Treasury trading operations. The attack exploited a vulnerability in Citrix NetScaler, leading to a $9 billion injection by ICBC to settle trades. The incident highlighted the vulnerability of the global financial system, particularly affecting repo transactions. On August 19, 2026, LockBit 5.0 claimed to have breached U.S. Bank, although this remains unverified. The attack's impact on U.S. Treasury bond auctions was significant, with poor demand attributed to the cyber event. LockBit's resurgence follows a previous crackdown in 2024, demonstrating the group's resilience and ongoing threat to financial institutions.
Key Points: • LockBit ransomware attacked ICBC Financial Services, disrupting U.S. Treasury operations. • The attack exploited a vulnerability in Citrix NetScaler, affecting critical financial transactions. • LockBit 5.0 claimed a new breach of U.S. Bank, though details remain unverified.