LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › ICBC (London) Listed by hunters Ransomware Group

HIGH severityUnverified claimHow we verify

ICBC (London) Listed by hunters Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 11, 2024
ICBC (London) Listed by hunters Ransomware Group

Reported September 11, 2024.

HIGH
Severity
September 11, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

ICBC (London) was listed by the Hunters ransomware group on 11 September 2024, with internal files reported exfiltrated in the attack; the date of the intrusion itself has not been established. Individuals should verify whether their information was exposed and follow any guidance issued by the bank.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On 11 September 2024, the ransomware group known as hunters listed ICBC (London) on its leak site, claiming to have exfiltrated internal files from the organisation. Public detail remains limited: the number of people affected is unknown, and the listing itself is an unverified claim by the group. What is reported is that data was taken from systems in the United Kingdom, with no indication that systems were encrypted.

For customers, staff and counterparties of a major banking entity, even an unconfirmed claim of internal-file theft raises practical questions about what may have left the organisation’s control and how to respond. This article sets out only what is known from the public record and places it in context.

What happened

According to the available report dated 11 September 2024, ICBC (London) was named by the hunters ransomware group. The group’s listing asserts that internal files were exfiltrated. The same report states that data was taken (exfiltrated: yes) while encryption of systems did not occur (encrypted data: no). No further technical detail—such as the initial access method, the precise date of intrusion, the volume of material removed, or confirmation by the organisation—has been disclosed in the public summary.

The incident is therefore characterised solely by the group’s claim of a ransomware-related data theft that stopped short of locking systems. Whether the claim is accurate, partial or false has not been independently verified in the material provided. Scale, in terms of individuals or records affected, remains unknown.

Who is hunters?

Hunters is a ransomware operation that has appeared in public reporting as a group that conducts double-extortion style attacks: it claims to steal data and then threatens to publish it unless a ransom is paid. Like other such actors, it maintains a leak site on which it lists alleged victims and, in some cases, samples or larger dumps of stolen material. Its typical tactics, drawn from established public accounts of its activity, include targeting organisations that hold commercially or personally sensitive information, exfiltrating files, and using the threat of disclosure as leverage.

In this instance the group has listed ICBC (London) and asserted that internal files were taken. That listing is a claim made by the group; it does not constitute independent confirmation that the organisation was compromised or that the stated data left its systems. No additional statements attributed specifically to hunters about this victim—beyond the fact of the listing and the reported summary of exfiltration without encryption—appear in the available facts.

Who is ICBC (London)?

ICBC (London) is the London-based presence of the Industrial and Commercial Bank of China, one of the world’s largest banking groups by assets. As a regulated financial institution operating in the United Kingdom, it provides corporate and institutional banking services, trade finance, treasury and related products. Organisations of this type routinely hold customer and counterparty records, transaction data, internal operational documents, employee information and communications that support regulatory compliance and day-to-day banking.

A breach claim against such an entity is consequential because financial institutions sit at the centre of payment flows, credit decisions and cross-border commerce. Even limited internal files can contain commercially sensitive material or personal data that, if misused, could affect clients, staff or market counterparties. The United Kingdom location places the organisation under UK data-protection and financial-services oversight, adding a further layer of regulatory interest should the claim be substantiated.

What data was at risk

The only data type named in the public report is “internal files exfiltrated in ransomware attack.” No inventory of those files, no count of records, and no confirmation of specific categories such as customer account details, identity documents or employee records have been disclosed. The report simply records that exfiltration occurred and encryption did not.

Financial institutions of this kind typically maintain a wide range of internal material—policy documents, operational logs, client correspondence, risk assessments and staff records. Whether any of those categories formed part of the claimed theft is unconfirmed. Readers should therefore treat the precise contents as unknown; the public record does not establish what, if anything, left the organisation’s control beyond the group’s general assertion of internal files.

Why it matters

For individuals whose data might have been among the claimed files, the practical risks include possible misuse of personal or financial information for fraud, phishing or identity-related crime. Even without encryption of systems, the removal of internal material can expose contact details, account identifiers or other attributes that criminals later combine with other sources. For the organisation itself, an unverified claim still creates operational and reputational pressure: it must investigate, notify regulators where required, and communicate with affected parties while the facts remain incomplete.

Because the number of people affected is unknown and the exact data types are not itemised, the scale of any real-world impact cannot yet be measured. The absence of encryption may have limited immediate service disruption, yet the exfiltration claim alone is sufficient to warrant caution among customers and staff who interact with ICBC (London).

What to do if you're exposed

If you hold accounts, work with, or have supplied personal information to ICBC (London), treat the situation as a prompt for ordinary hygiene rather than panic. Concrete first steps include:

Public detail on this incident remains limited. Any further confirmation, regulatory notices or official statements from the organisation should be followed as they appear. Until then, the measured response is vigilance, not assumption of confirmed compromise.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyICBC (London) security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See ICBC (London)’s full breach history →

More recent breaches

Development Bank of Jamaica Listed by hunters Ransomware GroupDecember 18, 2024A&O IT Group Listed by hunters Ransomware GroupNovember 15, 2024Ace Laboratories Limited Listed by hunters Ransomware GroupNovember 8, 2024Banco Sucredito Regional S.A.U. Listed by hunters Ransomware GroupOctober 25, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the ICBC (London) Listed by hunters Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by hunters — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram