The Industrial and Commercial Bank of China, the world's biggest lender, was hit by a cyber attack that caused disruption in US Treasury markets and forced traders to conduct transactions using USB sticks.
The attack, which was first reported by the Financial Times, was launched against Beijing-based ICBC's financial services unit and is suspected to have been carried out by underground organisation LockBit, one of the active ransomware groups globally, Bloomberg reported, citing sources.
ICBC Financial Services confirmed the attack on its website, saying it had “resulted in disruption to certain FS [financial services] systems”.
While the attack was discovered late on Thursday, the bank it was able to “successfully” clear US Treasury trades executed on Wednesday and repo financing trades the following day, it said in a notice on its website. Time magazine reported that traders used USB sticks to carry out those trades.
“ICBC FS's business and email systems operate independently of the Industrial and Commercial Bank of China Group,” it said.
“The systems of the ICBC head office and other domestic and overseas affiliated institutions were not affected by this incident, nor was the ICBC New York branch.”
The company “immediately” took action when the cyber attack was discovered, having “disconnected and isolated impacted systems to contain the incident” and reporting the incident to law enforcement while co-ordinating with cyber security experts.
ICBC did not specify the scope of the damage and which data has been potentially compromised.
A “thorough investigation” is under way, and the bank is “progressing its recovery efforts with the support of its professional team of information security experts”.
Cyber attacks continue to become more sophisticated and advanced, especially in today's digital age in which hackers focus on unsuspecting users who are immersed in technology more than ever, and can cause financial and reputational damages.
In particular, ransomware – a type of malicious software that takes over a system and demands a payment for it to be restored – continues to grow, compared with 10 years ago, cyber security services company Group-IB had previously said.
More than 72 per cent of businesses globally have been affected by ransomware attacks as of 2023, growing steadily over the past six years, data from Statista shows.
LockBit is the group responsible for similar cyber attacks on other major organisations in the past year, including US plane maker Boeing, the UK's Royal Mail and Ion Trading.
It has been labelled as “the most active ransomware group” and its software has been the most dominant strain of ransomware from July 2022 to June 2023, the latest data from US cyber security company Flashpoint shows.
During that period, LockBit accounted for about 28 per cent of all ransomware attacks, with the number of victims at 1,046 – about four times more than the victims of the next biggest group, BlackCat, Washington-based Flashpoint said.
“LockBit has established itself as a prolific ransomware group that maintains a relatively low profile despite the volume of attacks it carries out,” Flashpoint said.
“They are particularly aggressive towards organisations within the manufacturing and infrastructure sectors, though they have demonstrated a willingness to attack a wide range of industries.”
LockBit has also been ranked top of the biggest ransomware groups by Israel-based cyber security company CyberInt, which described the third quarter of 2023 as a “new record” for the ransomware industry.
The US and business services remained the biggest targets of ransomware operators at a country and sector level, respectively, CyberInt said.
RACECARD
4.30pm Jebel Jais – Maiden (PA) Dh60,000 (Turf) 1,000m
5pm: Jabel Faya – Maiden (PA) Dh60,000 (T) 1,000m
5.30pm: Al Wathba Stallions Cup – Handicap (PA) Dh70,000 (T) 2,200m
6pm: The President’s Cup Prep – Conditions (PA) Dh100,000 (T) 2,200m
6.30pm: Abu Dhabi Equestrian Club – Prestige (PA) Dh125,000 (T) 1,600m
7pm: Al Ruwais – Group 3 (PA) Dh300,000 (T) 1,200m
7.30pm: Jebel Hafeet – Maiden (TB) Dh80,000 (T) 1,400m
Heavily-sugared soft drinks slip through the tax net
Some popular drinks with high levels of sugar and caffeine have slipped through the fizz drink tax loophole, as they are not carbonated or classed as an energy drink.
Arizona Iced Tea with lemon is one of those beverages, with one 240 millilitre serving offering up 23 grams of sugar - about six teaspoons.
A 680ml can of Arizona Iced Tea costs just Dh6.
Most sports drinks sold in supermarkets were found to contain, on average, five teaspoons of sugar in a 500ml bottle.
History's medical milestones
1799 - First small pox vaccine administered
1846 - First public demonstration of anaesthesia in surgery
1861 - Louis Pasteur published his germ theory which proved that bacteria caused diseases
1895 - Discovery of x-rays
1923 - Heart valve surgery performed successfully for first time
1928 - Alexander Fleming discovers penicillin
1953 - Structure of DNA discovered
1952 - First organ transplant - a kidney - takes place
1954 - Clinical trials of birth control pill
1979 - MRI, or magnetic resonance imaging, scanned used to diagnose illness and injury.
1998 - The first adult live-donor liver transplant is carried out
UAE Falcons
Carly Lewis (captain), Emily Fensome, Kelly Loy, Isabel Affley, Jessica Cronin, Jemma Eley, Jenna Guy, Kate Lewis, Megan Polley, Charlie Preston, Becki Quigley and Sophie Siffre. Deb Jones and Lucia Sdao – coach and assistant coach.
The biog
Name: Timothy Husband
Nationality: New Zealand
Education: Degree in zoology at The University of Sydney
Favourite book: Lemurs of Madagascar by Russell A Mittermeier
Favourite music: Billy Joel
Weekends and holidays: Talking about animals or visiting his farm in Australia
WHY%20AAYAN%20IS%20'PERFECT%20EXAMPLE'
%3Cp%3EDavid%20White%20might%20be%20new%20to%20the%20country%2C%20but%20he%20has%20clearly%20already%20built%20up%20an%20affinity%20with%20the%20place.%3Cbr%3E%3Cbr%3EAfter%20the%20UAE%20shocked%20Pakistan%20in%20the%20semi-final%20of%20the%20Under%2019%20Asia%20Cup%20last%20month%2C%20White%20was%20hugged%20on%20the%20field%20by%20Aayan%20Khan%2C%20the%20team%E2%80%99s%20captain.%3Cbr%3E%3Cbr%3EWhite%20suggests%20that%20was%20more%20a%20sign%20of%20Aayan%E2%80%99s%20amiability%20than%20anything%20else.%20But%20he%20believes%20the%20young%20all-rounder%2C%20who%20was%20part%20of%20the%20winning%20Gulf%20Giants%20team%20last%20year%2C%20is%20just%20the%20sort%20of%20player%20the%20country%20should%20be%20seeking%20to%20produce%20via%20the%20ILT20.%3Cbr%3E%3Cbr%3E%E2%80%9CHe%20is%20a%20delightful%20young%20man%2C%E2%80%9D%20White%20said.%20%E2%80%9CHe%20played%20in%20the%20competition%20last%20year%20at%2017%2C%20and%20look%20at%20his%20development%20from%20there%20till%20now%2C%20and%20where%20he%20is%20representing%20the%20UAE.%3Cbr%3E%3Cbr%3E%E2%80%9CHe%20was%20influential%20in%20the%20U19%20team%20which%20beat%20Pakistan.%20He%20is%20the%20perfect%20example%20of%20what%20we%20are%20all%20trying%20to%20achieve%20here.%3Cbr%3E%3Cbr%3E%E2%80%9CIt%20is%20about%20the%20development%20of%20players%20who%20are%20going%20to%20represent%20the%20UAE%20and%20go%20on%20to%20help%20make%20UAE%20a%20force%20in%20world%20cricket.%E2%80%9D%C2%A0%3C%2Fp%3E%0A
MATCH INFO
Arsenal 1 (Aubameyang 12’) Liverpool 1 (Minamino 73’)
Arsenal win 5-4 on penalties
Man of the Match: Ainsley Maitland-Niles (Arsenal)
Ten tax points to be aware of in 2026
1. Domestic VAT refund amendments: request your refund within five years
If a business does not apply for the refund on time, they lose their credit.
2. E-invoicing in the UAE
Businesses should continue preparing for the implementation of e-invoicing in the UAE, with 2026 a preparation and transition period ahead of phased mandatory adoption.
3. More tax audits
Tax authorities are increasingly using data already available across multiple filings to identify audit risks.
4. More beneficial VAT and excise tax penalty regime
Tax disputes are expected to become more frequent and more structured, with clearer administrative objection and appeal processes. The UAE has adopted a new penalty regime for VAT and excise disputes, which now mirrors the penalty regime for corporate tax.
5. Greater emphasis on statutory audit
There is a greater need for the accuracy of financial statements. The International Financial Reporting Standards standards need to be strictly adhered to and, as a result, the quality of the audits will need to increase.
6. Further transfer pricing enforcement
Transfer pricing enforcement, which refers to the practice of establishing prices for internal transactions between related entities, is expected to broaden in scope. The UAE will shortly open the possibility to negotiate advance pricing agreements, or essentially rulings for transfer pricing purposes.
7. Limited time periods for audits
Recent amendments also introduce a default five-year limitation period for tax audits and assessments, subject to specific statutory exceptions. While the standard audit and assessment period is five years, this may be extended to up to 15 years in cases involving fraud or tax evasion.
8. Pillar 2 implementation
Many multinational groups will begin to feel the practical effect of the Domestic Minimum Top-Up Tax (DMTT), the UAE's implementation of the OECD’s global minimum tax under Pillar 2. While the rules apply for financial years starting on or after January 1, 2025, it is 2026 that marks the transition to an operational phase.
9. Reduced compliance obligations for imported goods and services
Businesses that apply the reverse-charge mechanism for VAT purposes in the UAE may benefit from reduced compliance obligations.
10. Substance and CbC reporting focus
Tax authorities are expected to continue strengthening the enforcement of economic substance and Country-by-Country (CbC) reporting frameworks. In the UAE, these regimes are increasingly being used as risk-assessment tools, providing tax authorities with a comprehensive view of multinational groups’ global footprints and enabling them to assess whether profits are aligned with real economic activity.
Contributed by Thomas Vanhee and Hend Rashwan, Aurifer