How the Bangladesh Bank heist happened: $81 million over SWIFT, stopped short by a typo
Over one weekend in February 2016, someone used Bangladesh's own central bank terminals to ask the Federal Reserve Bank of New York for close to $1 billion, and $81 million of it actually left. One of the few things that went wrong for the thieves was a spelling mistake. This case file covers how the payment orders got out, how the scheme was caught, what it cost, and the one check that would have raised the alarm days earlier.
What happened
Bangladesh Bank, the country's central bank, keeps part of its reserves in a US-dollar account at the New York Fed. Banks move that kind of money by sending instructions over SWIFT, the secure messaging network banks use to tell each other where to send funds. On the evening of Thursday, February 4, 2016, Bangladesh time, 35 payment instructions went out from the bank's SWIFT terminals asking New York to move about $951 million.[5][6] The timing was deliberate: Friday is the start of the weekend in Bangladesh while New York was open, and by the time Dhaka was back at work, New York had closed for its own weekend.[6]
Most of the orders were stopped. Five were paid, worth $101 million.[5][8] Four of those, about $81 million, went to accounts at a branch of a Philippine bank that had been opened under fictitious names months earlier.[2][5] The fifth, $20 million, was headed to a supposed charity in Sri Lanka whose name had been typed with "foundation" misspelled as "fandation." The bank routing that payment asked Bangladesh Bank to confirm it, and the money was halted.[2][3]
Meanwhile, back in Dhaka, a printer that normally spat out a paper record of every SWIFT message had gone quiet. Staff noticed the problem on Friday, February 5, and on Saturday the software reported that a file was missing or changed. Only once it was working again did the bank see what had been approved in its name. Cancellation requests went out on February 8 and 9, several days after the orders were sent.[4] The Philippine money had by then been moved on, much of it through casinos.[2][5]
How they got in
According to the US Justice Department, the intruders first got into the bank's network through spear-phishing, meaning emails written to look legitimate to specific staff. From there they reached the computers that connect to SWIFT and sent messages that the system treated as properly authenticated, because they came from the bank's own terminals.[1] Reporting describes the bait as fake job applications sent about a year before the theft.[6]
The network made that easier. A later review of the case noted that SWIFT-connected machines were not separated from other systems, had no firewall in front of them, and were reachable from the open internet.[8] Malicious software also covered the intruders' tracks, which is why the one independent-looking record the bank relied on, the printout, simply stopped appearing.[4][8] The confirmations and the fraud lived on the same compromised system, so the thieves controlled both.
How it was caught and what it cost
Detection came from outside the bank. The New York Fed grew wary of the unusual number of payment requests and the transfers to private parties, and the bank handling the Sri Lanka payment flagged the misspelled name.[2][3] One report says the word "Jupiter" in the Manila branch's street address also tripped a sanctions screen at the Fed, because it matched the name of a sanctioned ship.[6]
The $20 million sent toward Sri Lanka was recovered. Of the $81 million that reached the Philippines, only around $15 million was clawed back, according to a Philippine investigative center's summary.[5] Philippine regulators fined the receiving bank 1 billion pesos in August 2016 for failing to follow banking rules in the affair.[7] In January 2019 the branch manager who handled the accounts was convicted of 8 counts of money laundering and sentenced to 4 to 7 years per count.[5]
In September 2018 the Justice Department announced a criminal complaint, filed that June in Los Angeles, charging a North Korean programmer with conspiracy to commit computer fraud and wire fraud. Prosecutors say he was part of a North Korean government-sponsored hacking team, and the DOJ attributed the Bangladesh theft and attempts on other banks to that group. He has been charged, not convicted.[1]
The missing control
The missing control: independent verification of outgoing payment orders, meaning a check on money leaving the account that does not depend on the same system that sent it.
Bangladesh Bank's main check was a printout produced by the SWIFT setup itself. When the attackers controlled that setup, they controlled the check. A daily reconciliation against the New York Fed's own statement of the account, or a rule that any large or unusual order must be confirmed through a separate channel by a second person, would have shown within hours that $101 million had gone out to accounts nobody at the bank recognized. The outside banks did exactly this kind of checking, which is why most of the money was stopped. The bank itself did not, which is why the remaining $81 million had days to disappear.
What to do in your business
- Check the bank's version, not yours. Reconcile outgoing payments against your bank's online statement every business day, not against your own accounting software or email confirmations.
- Require a second person for new payees. Any payment to a new account, or any change to an existing payee's bank details, gets approved by someone other than the person who entered it.
- Confirm by phone on a known number. Verify changed banking details by calling a number you already had on file, never one supplied in the same message.
- Turn on bank alerts. Set text or email alerts for every outgoing transfer above a modest threshold, sent to someone who does not initiate payments.
- Know who watches on weekends and holidays. Decide who checks those alerts when the office is closed, because thieves pick exactly those days.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- How the Hot Lotto was rigged: the security director who wrote the numbers
- How the Target breach happened: a vendor's billing login and the alarms nobody answered
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- What caused the Equifax breach? An unpatched website and an expired certificate
- How the Capital One breach happened: one misconfigured cloud firewall
Facts are drawn from court records, government reports and reputable reporting, listed below. People are named only where they were convicted or spoke publicly in an official role.
- U.S. Department of Justice: North Korean Regime-Backed Programmer Charged With Conspiracy to Conduct Multiple Cyber Attacks and Intrusions
- Fortune: A typo helped stop a billion-dollar bank heist
- OCCRP: Bangladesh typo triggers alarm, prevents billion-dollar bank heist
- Business Standard (IANS): Bangladesh bank printer was hacked for heist
- Philippine Center for Investigative Journalism: What went before: The Bangladesh Bank heist
- Dhaka Tribune (BBC): The Lazarus heist: How North Korea almost stole $1 billion from Bangladesh
- Rappler: RCBC pays Bangladesh Bank heist fine in advance
- ISACA Journal: Lessons Learned From the Bangladesh Bank Heist