Menu
Browse

Cyber Incident Victim: EquiLend

Date:

Jan 2024

Location:

United States of America

Summary

EquiLend experienced a ransomware incident resulting in unauthorized access to its systems, prompting temporary outages affecting several services including trading, post-trade, data analytics, and regulatory technology platforms. The firm secured its systems, initiated an investigation with third-party cybersecurity experts, and notified law enforcement, while confirming its Spire components and ECS Loan Market remained operational throughout. Restoration efforts are ongoing, with a focus on safely restoring full functionality to impacted services as the investigation continues.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On January 22, 2024, EquiLend identified a technical issue that forced portions of its systems offline, prompting an immediate internal investigation. This investigation confirmed a cybersecurity incident involving unauthorized access to company systems, leading EquiLend to take swift containment measures to secure affected infrastructure. The company engaged external cybersecurity firms and professional advisers to assist with forensic analysis and service restoration, notifying clients that recovery efforts might require several days. Specific services impacted included NGT, Post-Trade Solutions, Data & Analytics Solutions, and RegTech Solutions, all rendered temporarily unavailable. EquiLend Spire components and the ECS Loan Market remained fully operational throughout the incident. By January 24, EquiLend established a public communication channel via its website to provide periodic updates, emphasizing its focus on restoring services methodically while maintaining client transparency.

Cyber Incident Image

By January 25, EquiLend’s investigation with third-party experts determined the incident was a ransomware attack, though the specific threat actor remained unidentified. Law enforcement agencies were notified as part of the response protocol. Restoration work continued on the disrupted services, with no definitive timeline provided for full recovery. The company maintained its temporary service suspension for NGT, Post-Trade Solutions, Data & Analytics Solutions, and RegTech Solutions to ensure system integrity during remediation. EquiLend reiterated its commitment to rebuilding affected systems with enhanced security measures, leveraging external expertise to strengthen existing protocols. Clients were directed to an updated FAQ resource for operational guidance, with unresolved queries routed to relationship managers. The incident caused measurable operational disruption to core securities lending platforms but did not compromise EquiLend’s entire service portfolio.

Sources
Sources available to members
1 source