Cyberattack pushed Wall Street banking platform into recording transactions in spreadsheets
A recent cyberattack targeting the infrastructure supporting Wall Street's essential processes has forced major banks to resort to traditional manual methods. The attack, which affected financial technology firm EquiLend on January 22, 2024, disrupted its systems, compelling securities-lending teams at prominent banks to manually input certain stock loans and transactions into spreadsheets. EquiLend, responsible for

Cyberattack-pushed-Wall-Street-banking-platform-into-recording-transactions-in-spreadsheets-

A recent cyberattack targeting the infrastructure supporting Wall Street’s essential processes has forced major banks to resort to traditional manual methods. The attack, which affected financial technology firm EquiLend on January 22, 2024, disrupted its systems, compelling securities-lending teams at prominent banks to manually input certain stock loans and transactions into spreadsheets. EquiLend, responsible for processing trillions of dollars in transactions monthly, indicated that resolving the incident might take several days.
While the attack appears to have slowed operations rather than causing critical issues, it sheds light on the significance of lesser-known entities that facilitate the routine processing of trillions in stocks, bonds, and derivatives. This incident adds to a series of recent cyberattacks that have impacted various segments of the financial system, including the US Treasury market and derivatives trading, prompting global regulatory scrutiny.
The vulnerabilities exposed by these cyberattacks are raising concerns among industry experts. Larry Tabb, head of market structure research at Bloomberg Intelligence, emphasized the troubling nature of these incidents and questioned the speed of EquiLend’s recovery, pondering whether customers would regain trust in the firm.
EquiLend, owned by financial giants such as Goldman Sachs and JPMorgan Chase & Co., recently announced plans to sell a majority stake to Welsh, Carson, Anderson & Stowe. The cyberattack, attributed to the ransomware group LockBit, raises uncertainties about the timing and consequences of this ownership transition. LockBit, known for its prolific ransomware activities, had previously claimed responsibility for a significant attack on Industrial & Commercial Bank of China Ltd., affecting the world’s largest bank.
The EquiLend breach underscores the broader implications of cyber threats in the financial sector. Earlier attacks, such as the one on ION Trading UK, also orchestrated by LockBit, had forced banks and brokers to resort to manual processing of derivatives trades. With EquiLend, banks using its system are adopting manual processes to track trades, log counterparties, and minimize exposure to the compromised systems. The impact is particularly noticeable in the prime brokerage business, a critical service generating substantial revenue for major global firms.
As the financial industry deals with the aftermath, organizations are closely monitoring ongoing issues to ensure effective mitigation measures. The incident serves as a stark reminder of the persistent cybersecurity challenges faced by the financial system and the imperative of enhancing resilience against evolving threats.



