News: 1675409410

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

LockBit claims responsibility for ION ransomware attack but US/UK hounds are sniffing

(2023/02/03)


UK regulators are investigating a cyberattack against financial technology firm ION, while the LockBit ransomware gang has threatened to publish the stolen data on February 4 if the software provider doesn't pay up.

According to a statement posted on ION Market's website, its ION Cleared Derivatives division "experienced a cybersecurity event" on January 31.

"The incident is contained to a specific environment, all the affected servers are disconnected, and remediation of services is ongoing," the notice [1]said . "Further updates will be posted when available."

[2]

LockBit, a ransomware group with [3]ties to Russia , has since said it pulled off the data heist, and promised to publish "all available data," according to a screenshot posted by Emsisoft threat analyst Brett Callow.

[4]#LockBit has listed [5]#ION . The [6]#RoyalMail has not been listed. The reason for that is not known. [7]pic.twitter.com/7p5nZNttjm — Brett Callow (@BrettCallow) [8]February 2, 2023

This is the crime gang that may or may not have also [9]attacked Royal Mail last month. Despite claiming one of its affiliates compromised the postal service, Royal Mail hasn't been listed on LockBit's leak site, as Callow [10]noted .

While the ION security alert didn't provide any additional details, but according to media reports the attack affected 42 of ION's customers, which likely included ABN Amro Clearing and Intesa Sanpaolo, Italy's biggest bank, [11]Reuters reported .

[12]

[13]

Meanwhile, some European and US banks and brokers had to pull the pens and paper out of storage. ION's software automates trading processes, and [14]Bloomberg reported the outage forced these banks and brokers to manually process derivative trades.

The attack prompted the Futures Industry Association (FIA) to weigh in on the security snafu, which it [15]said has affected ION clients "across global markets."

[16]

The industry association, which represents futures dealers, investors and exchanges, said it was working with its member organizations, "including clearing firms and exchanges, as well as market regulators and others, to assess the extent of the impact on trading, processing, and clearing."

[17]Royal Mail, cops probe 'cyber incident' that's knackered international mail

[18]LockBit: Sorry about the SickKids ransomware, not sorry about the rest

[19]LockBit 3.0 malware forced NHS tech supplier to shut down hosted sites

[20]LockBit threatens to leak confidential info stolen from California's beancounters

Additionally, a spokesperson for the UK's Financial Conduct Authority told The Register that the FCA is "aware of this incident and we will continue to work with our counterparts and the firms affected."

The FCA regulates British banks and financial services companies. While ION, as a third-party software provider, isn't an FCA-regulated business, it does provide services to several firms that do fall under the agency's purview.

As such, the FCA is working with its counterparts to help affected financial services firms.

US downplays risk

The US Treasury Department also confirmed the ransomware attack against ION, but said it didn't post a "systematic risk" to industry.

"The issue is currently isolated to a small number of smaller and mid-size firms and does not pose a systemic risk to the financial sector," Deputy Assistant Secretary of the Treasury for Office of Cybersecurity and Critical Infrastructure Protection Todd Conklin told The Register .

"We remain connected with key financial sector partners, and will advise of any changes to this assessment," Conklin added.

[21]

However, these types of supply-chain, or "island-hopping" attacks, are becoming more prevalent in the financial sector, Tom Kellermann, senior VP of cyber strategy at Contrast Security, told The Register .

"Shared service providers are being increasingly targeted by cybercrime cartels to manifest island hopping," he said. "Cyberattacks in the financial sector are no longer merely about conducting a heist but rather to hijack the digital transformation of the victim so as to launch attacks against their customer base." ®

Get our [22]Tech Resources



[1] https://iongroup.com/press-release/markets/cleared-derivatives-cyber-event/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y9zpUAKUh8ZqG4OYAYHIVAAAANY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.theregister.com/2022/11/12/in_brief_security/

[4] https://twitter.com/hashtag/LockBit?src=hash&ref_src=twsrc%5Etfw

[5] https://twitter.com/hashtag/ION?src=hash&ref_src=twsrc%5Etfw

[6] https://twitter.com/hashtag/RoyalMail?src=hash&ref_src=twsrc%5Etfw

[7] https://t.co/7p5nZNttjm

[8] https://twitter.com/BrettCallow/status/1621188538120417280?ref_src=twsrc%5Etfw

[9] https://www.theregister.com/2023/01/11/royal_mail_uk_cyber_incident/

[10] https://twitter.com/BrettCallow/status/1621188538120417280

[11] https://www.reuters.com/technology/ransomware-attack-data-firm-ion-could-take-days-fix-sources-2023-02-02/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y9zpUAKUh8ZqG4OYAYHIVAAAANY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y9zpUAKUh8ZqG4OYAYHIVAAAANY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://www.bloomberg.com/news/articles/2023-02-01/ion-signals-to-firms-cyberattack-may-take-2-3-days-to-resolve

[15] https://www.fia.org/resources/fia-comments-ion-group-cyber-incident

[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y9zpUAKUh8ZqG4OYAYHIVAAAANY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[17] https://www.theregister.com/2023/01/11/royal_mail_uk_cyber_incident/

[18] https://www.theregister.com/2023/01/04/lockbit_sickkids_ransomware/

[19] https://www.theregister.com/2022/10/14/nhs_software_hosting_provider_advanced_ransomware_lockbit/

[20] https://www.theregister.com/2022/12/13/california_finance_department_lockbit/

[21] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y9zpUAKUh8ZqG4OYAYHIVAAAANY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[22] https://whitepapers.theregister.com/



"The issue is currently isolated to a small number of smaller and mid-size firms"

Pascal Monett

So it's not a problem until "the issue" starts targetting Big Money, at which point the battlecruisers will be sent out to deal with it.

But, until then, the small fry can get stiffed.

If I could drop dead right now, I'd be the happiest man alive!
-- Samuel Goldwyn