On 8 November 2023, ICBC Financial Services — the New York broker-dealer arm of Industrial and Commercial Bank of China, the largest bank on earth by assets — was hit by ransomware and cut off from the systems it used to clear US Treasury and repo trades. The company confirmed the attack publicly the next day, saying it had successfully cleared the Treasury trades executed on the 8th and the repo financing trades done on the 9th.
The detail that made the story famous was the workaround. With corporate email and its clearing connection down, ICBC FS was reported by the financial press to have sent settlement details to counterparties on a USB stick, hand-carried by a messenger across Manhattan. The bank itself never formally described doing so, and it belongs in the record as press reporting rather than corporate statement — but the image was too perfect to fade: the world's largest bank, in the world's deepest capital market, reverting to a courier and a thumb drive.
The measurable damage was real. ICBC's head office reportedly injected around $9 billion into its US unit to cover trades the subsidiary could not settle, and US Treasury repo "fails" — debt not delivered on time to complete a trade — rose to $62.2 billion during the disruption. It is worth being precise about scope: what broke was one broker-dealer's ability to clear and settle, not the Treasury market's central infrastructure. A LockBit representative told Reuters "They paid a ransom, deal closed" — a threat-actor claim ICBC has never confirmed, with no amount ever disclosed.
And the entry point, reportedly, was an unpatched Citrix NetScaler appliance: the same Citrix Bleed flaw that would run through nearly every major incident of the month.
Citrix Bleed, and a patch nobody applied fast enough
CVE-2023-4966 — "Citrix Bleed" — lets an attacker hijack valid session tokens and walk straight past authentication and MFA, with no user interaction and no privileged account required. Citrix patched it on 10 October 2023. Mass exploitation of unpatched appliances continued through November regardless. On 21 November, CISA, the FBI and international partners issued joint advisory AA23-325A on LockBit affiliates exploiting it — crediting Boeing with first detecting the activity against its own distribution business. The month's casualty list reads as a single vulnerability's résumé: ICBC Financial Services, Boeing, law firm Allen & Overy, and DP World Australia, whose 10 November attack left roughly 30,000 shipping containers stranded across Melbourne, Sydney, Brisbane and Fremantle.
Fidelity National Financial and the stalled house sales
Fidelity National Financial — the Fortune 500 title-insurance and escrow group — became aware of an intrusion on 19 November, filed with the SEC on 21 November, and said the incident was contained by 26 November. ALPHV/BlackCat claimed responsibility on 22 November; FNF's own disclosure attributed it to nobody. Because the company blocked access to affected systems, title, escrow and mortgage services stalled, freezing home closings and payments for buyers, sellers and agents across the United States. Filings in January 2024 put the data theft at roughly 1.3 million individuals. Ransomware had found its way into the moment when ordinary families move house.
Infosys McCamish, and six million American records
On 3 November 2023, Infosys disclosed that its US subsidiary Infosys McCamish Systems — which provides insurance-industry back-office platforms — had suffered a cybersecurity incident affecting some of its applications and systems. LockBit claimed the attack on 4 November. The eventual scope, established through notifications the following year, reached roughly six million people, largely customers of the American insurers McCamish served. For India's flagship IT-services sector, the incident was a preview of a theme this archive returns to repeatedly: when an Indian technology provider is breached, the victims are overwhelmingly its clients' customers, in other countries, under other regulators — and the reputational damage lands on the export brand. The same month, Apple's threat notifications to Indian opposition politicians triggered a parliamentary storm, with the IT ministry ordering Apple to explain the alerts; Apple has consistently declined to attribute such notifications to any specific state actor.
⏳ Time capsule — November 2023
- The UK hosted the first global AI Safety Summit at Bletchley Park on 1–2 November, where 28 countries and the EU signed the Bletchley Declaration.
- OpenAI's board fired Sam Altman on 17 November; after a near-total staff revolt he was reinstated within five days.
- Australia beat India by six wickets in the Cricket World Cup final in Ahmedabad on 19 November.
- On 28 November, all 41 workers trapped for 17 days in the Silkyara tunnel in Uttarakhand were brought out alive.
Financial plumbing, exposed
ICBC became the canonical example of cyber risk inside market infrastructure, cited in every subsequent regulatory discussion of operational resilience in clearing and settlement — and its $62.2 billion in repo fails gave supervisors a number to point at. Citrix Bleed, meanwhile, earned a permanent place in the edge-device story this archive keeps telling: patched in October, exploited through November and December, and still producing disclosures — Xfinity's 35.9 million among them — long after the fix was available. That gap between "patch exists" and "patch applied" is precisely the exploitation window our current cover story argues has since collapsed to days. In November 2023 it was still measured in months, and the bill arrived accordingly.