Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CitrixBleed was reported as a suspected entry point in the November 2023 ransomware attack on ICBC Financial Services (ICBC FS), the New York-based U.S. broker-dealer subsidiary of China’s state-owned Industrial and Commercial Bank of China. The link was not forensically confirmed in public reporting. The attack disrupted Treasury clearing, leaving trades unsettled; a 2023 Cyber Cert Labs situational report said ICBC injected capital to settle approximately $9 billion with BNY Mellon.

What happened to ICBC Financial Services

ICBC FS disclosed the ransomware attack on 8 November 2023. It affected systems used for Treasury clearing, disrupting the processing of trades and leaving some unsettled. According to the 2023 Cyber Cert Labs situational report, ICBC injected capital to settle approximately $9 billion with BNY Mellon.

The affected entity identified in the reporting was ICBC FS, a U.S. broker-dealer subsidiary—not necessarily every system or banking operation of ICBC. The Bank of England later cited the incident as an example of operational contagion: ICBC FS disconnected from BNY Mellon, illustrating how a disruption at one firm can affect counterparties.

Was CitrixBleed the way attackers got in?

Public reporting described an unpatched Citrix vulnerability, CVE-2023-4966, known as CitrixBleed, as a suspected entry point. It also said LockBit claimed the ransomware attack. Public forensic details were not available in that reporting, so the ICBC-specific connection between CitrixBleed and the intrusion remains suspected rather than proven.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Claim What is established
CitrixBleed was exploited in ransomware activity The joint CISA, FBI, MS-ISAC and ASD advisory says LockBit 3.0 affiliates exploited the vulnerability in ransomware intrusions; the advisory also describes activity observed by Boeing.
CitrixBleed was the ICBC FS entry point Reported as suspected. Public forensic evidence confirming it in this specific incident was not available.
LockBit was responsible for the ICBC FS attack LockBit claimed the attack in contemporaneous reporting; a claim is not the same as a publicly established forensic attribution.
Ransom amount or share of ICBC systems compromised Not established in the cited public reporting.

What CVE-2023-4966 does

CitrixBleed is a buffer-overflow vulnerability in customer-managed Citrix NetScaler ADC and NetScaler Gateway appliances when configured as a Gateway or AAA virtual server. Gateway configurations include VPN virtual server, ICA Proxy, CVPN and RDP Proxy.

CISA says exploitation can disclose sensitive information, including session-authentication tokens. A stolen token can let an attacker take over an already authenticated user session. The joint advisory says LockBit affiliates used the flaw to bypass password requirements and multifactor authentication (MFA) through session hijacking. With a hijacked session, an attacker may gain elevated permissions, harvest credentials, move laterally and reach data or other resources. MFA therefore does not by itself protect a session whose token has been exposed.

How to patch and respond to possible exposure

Citrix’s bulletin lists fixed releases including NetScaler ADC/Gateway 14.1-8.50 and later, 13.1-49.15 and later, and 13.0-92.19 and later; it identifies version 12.1 as end of life. These are the releases listed in that bulletin, not a guarantee that every one remains supported today. Check Citrix’s current security bulletin and product lifecycle information for the appliance and deployment in question before selecting an upgrade.

  1. Identify exposed appliances. Inventory customer-managed NetScaler ADC and Gateway instances, their versions, and whether they use an affected Gateway or AAA configuration.
  2. Upgrade to a fixed, currently supported release. Use Citrix’s current bulletin to confirm the applicable version and follow the vendor’s upgrade guidance.
  3. Hunt for signs of compromise. CISA advises organizations to investigate malicious activity, not simply assume that upgrading removes an attacker who may already have obtained a session token or access.
  4. Report positive findings. CISA also urges organizations to report confirmed malicious activity through the appropriate channels.

If an appliance may have been exposed before it was fixed, treat patching and incident response as separate tasks: the upgrade addresses the vulnerable software, while investigation is needed to determine whether an attacker already used it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why the incident mattered beyond one bank

The attack illustrates how a cyber incident at a broker-dealer can become an operational problem for firms connected to its clearing activity. Unsettled trades and the reported capital injection show the potential financial consequences, while the Bank of England’s example highlights that disconnecting from a counterparty can transmit disruption through the wider system. The public information cited here does not establish a ransom amount, a victim count, or the percentage of ICBC systems affected.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.