LockBit Ransomware Targets ICBC Financial Services and U.S. Bank

LockBit Ransomware Targets ICBC Financial Services and U.S. Bank

First seen 20 Aug 2026, 14:59 UTC Escudodigitalwww.resecurity.com 72% similarity 65.5

Article Content

Browse articles
ThreatCluster

On November 8, 2025, the LockBit ransomware group attacked ICBC Financial Services, disrupting U.S. Treasury trading operations. The attack exploited a vulnerability in Citrix NetScaler, leading to a $9 billion injection by ICBC to settle trades. The incident highlighted the vulnerability of the global financial system, particularly affecting repo transactions. On August 19, 2026, LockBit 5.0 claimed to have breached U.S. Bank, although this remains unverified. The attack's impact on U.S. Treasury bond auctions was significant, with poor demand attributed to the cyber event. LockBit's resurgence follows a previous crackdown in 2024, demonstrating the group's resilience and ongoing threat to financial institutions.

Key Points: • LockBit ransomware attacked ICBC Financial Services, disrupting U.S. Treasury operations. • The attack exploited a vulnerability in Citrix NetScaler, affecting critical financial transactions. • LockBit 5.0 claimed a new breach of U.S. Bank, though details remain unverified.

ThreatCluster AI How this analysis works

Timeline

2023-10-10
CVE-2023-4966 published
CVE-2023-4966 was published, related to vulnerabilities exploited by ransomware groups.
2023-10-18
CVE-2023-4966 added to CISA KEV
CISA added CVE-2023-4966 to its Known Exploited Vulnerabilities list due to active exploitation.
2023-10-27
CVE-2023-4967 published
CVE-2023-4967 was published, highlighting additional vulnerabilities relevant to ransomware attacks.
2025-11-08
LockBit attacks ICBC Financial Services
The ransomware attack disrupted U.S. Treasury trading operations, leading to a $9 billion settlement injection.
Resecurity
2026-08-19
LockBit 5.0 claims breach of U.S. Bank
The ransomware group claimed to have compromised U.S. Bank, but the attack remains unverified and lacks details on data exposure.
Escudodigital

Community

Browse all →