Security

Cyber-crime

Hunters International cyber-gang extorts Chinese mega-bank's London HQ

Allegedly swiped more than 5.2M files and threatens to publish the lot


Ransomware gang Hunters International reportedly claims to have stolen more than 5.2 million files belonging to the London branch of the Industrial and Commercial Bank of China (ICBC), a Chinese state-owned bank and financial service corporation, and set a deadline of September 13 to release all the data unless demands are met.

The newish ransomware-as-a-service operation, first spotted last October, allegedly swiped 6.6 TB of the bank's data after breaking into its network, and threatened to publish all of it unless ICBC pays up.

The Register has not confirmed that the stolen info is legitimate, and ICBC did not immediately respond to our inquiries. We will update this story if and when we hear back.

If the claims turn out to be true, this could be very bad news for customers and their financial data.

Banks are particularly attractive targets for ransomware gangs, and all types of financially motivated criminals, because they are responsible for vast amounts of highly sensitive financial data. This, at least in the extortionists' minds, makes them more likely to pay steep ransom demands to prevent that info from being publicly exposed, angering customers, and tanking the bank's reputation — and possibly revenue.

ICBC is the world's largest bank by assets, boasting $6.3 trillion as of mid-2024, with an annual revenue of $113 billion.

Hunters International, despite being relatively new to the ransomware scene, has quickly risen up through the ranks and claimed to have breached more than 134 organizations so far this year. These victims span the globe, with the notable exception of Russia. 

This is not uncommon for cybercriminals, which often operate out of that country and, in general, are given safe harbor — or even outright rescued from foreign custody — so long as they don't target Russian organizations for their financial scams and extortion attempts. ®

Send us news
7 Comments

Ransomware's ripple effect felt across ERs as patient care suffers

389 US healthcare orgs infected this year alone

Would banning ransomware insurance stop the scourge?

White House official makes case for ending extortion reimbursements

Akira ransomware is encrypting victims again following pure extortion fling

Crooks revert to old ways for greater efficiency

Senator accuses sloppy domain registrars of aiding Russian disinfo campaigns

Also, Change Healthcare sets a record, cybercrime cop suspect indicted, a new Mallox decryptor, and more

Brazen crims selling stolen credit cards on Meta's Threads

The platform 'continues to take action' against illegal posts, we're told

Perfctl malware strikes again as crypto-crooks target Docker Remote API servers

Attacks on unprotected servers reach 'critical level'

Gang gobbles 15K credentials from cloud and email providers' garbage Git configs

Emeraldwhale looked sharp – until it made a common S3 bucket mistake

Microsoft says more ransomware stopped before reaching encryption

Volume of attacks still surging though, according to Digital Defense Report

Uncle Sam outs a Russian accused of developing Redline infostealing malware

Or: why using the same iCloud account for malware development and gaming is a bad idea

Feds investigate China's Salt Typhoon amid campaign phone hacks

'They're taunting us,' investigator says and it looks like it's working

JPMorgan Chase sues scammers following viral 'infinite money glitch'

ATMs paid customers thousands ... and now the bank wants its money back

Wanted. Top infosec pros willing to defend Britain on shabby salaries

GCHQ job ads seek top talent with bottom-end pay packets