Desk live·
ForensicPost
Ransomware/Finance/File 23-1108

ICBC’s US Unit Could Not Clear Treasury Trades After LockBit Attack

A ransomware attack on the American arm of the world’s largest bank stopped it connecting to the clearing system for US Treasury and repo trades. Reporting describes trading data moving by USB stick, and a nine-billion-dollar debt to the settlement bank that had to be covered by the parent.

Constructed geometry · not a chart of case data
JurisdictionUSANew Yorkthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetICBC Financial Services
ActorLockBit
S. Rosler11 min readConfidence: high2 sources reviewed

ICBC Financial Services, the US subsidiary of Industrial and Commercial Bank of China, was hit by ransomware on 8 November 2023. Staff were temporarily unable to reach corporate email or connect systems to the clearing infrastructure used to settle US Treasury and repo trades.

ICBC stated that Treasury trades executed on the Wednesday and repo financing trades done on the Thursday were successfully cleared. Reporting nonetheless described the firm being unable to settle trades on behalf of other market participants.

The Harm Landed On Counterparties

This is the corpus’s clearest instance of an availability failure travelling outward through a market rather than stopping at the affected organisation.

Reporting placed the firm as owing its settlement bank around nine billion dollars for unsettled trades, requiring a capital injection from the parent, and put the resulting rise in Treasury repo fails at $62.2 billion. Those are not costs to ICBC — they are the incident arriving at institutions that had no relationship with the compromised systems.

The Fallback Was A USB Stick

Reporting describes ICBC Financial Services proposing to send trading data to its settlement bank on a USB stick so that trades could be settled.

The corpus argues at 25-1224b and 24-1125 that manual fallback is a wasting asset — it works, it is slower, and it exists only where somebody kept a non-digital path alive. Physically couriering settlement data between two of the largest financial institutions on earth is that argument in its most concentrated form.

The Payment Claim Is The Operators’ Own

LockBit told a news agency that ICBC had paid. The agency reported that it could not independently verify the claim, and this desk does not record it.

An extortion group has an obvious interest in being believed about payment, both to pressure future targets and to advertise that paying works. The corpus treats a claimed payment exactly as it treats a claimed volume.

How we reported this

Built on contemporaneous reporting of the attack and its market effects. ICBC’s statement that the specified trades cleared is the firm’s own. The nine-billion-dollar settlement debt, the capital injection, the $62.2 billion figure for repo fails and the USB stick proposal are from that reporting rather than from any filing this desk has read, and are stated as reported. The claim that a ransom was paid comes from LockBit and was not independently verified by the agency that reported it; it is not in the record. Graded high on the disruption and the clearing failure; the market figures carry the reporting’s own qualification. Corrections: corrections@forensicpost.com.

Sources
  1. China’s ICBC, the world’s biggest bank, hit by cyberattack that reportedly disrupted Treasury marketsCNBC
  2. The ICBC ransomware hack and impact on US repo marketsFinadium
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary