Case file · CITIBANK 1994

The 1994 Citibank hack: how $10 million moved on stolen customer passwords

Published 2026-09-29 · 4 min read · Missing control: Out-of-band verification of large transfers

In 1994 a computer programmer sitting in St. Petersburg, Russia, moved more than $10 million out of Citibank customer accounts without ever setting foot in a branch.[1] This case file covers how stolen customer logins let him do it, how a $400,000 gap gave him away, and the one control that would have stopped the money at the door.

What happened

Citibank ran a cash management system that let large corporate customers move money between accounts and wire it around the world from their own offices.[1] Starting in late June 1994, someone began logging into that system with real customer IDs and passwords and sending money to accounts overseas and in San Francisco.[1][2]

In July 1994, several corporate customers noticed that a total of $400,000 was missing from their accounts, and the bank called the FBI.[1] Rather than shut everything down at once, investigators watched as more transfers came through. In all, the FBI counted about 40 illegal transactions between late June and October 1994, adding up to more than $10 million.[1]

The trail led to Vladimir Levin, a programmer in St. Petersburg, who investigators said had been working from his own laptop.[1] Receiving accounts were in countries including Finland, the Netherlands, Germany, Israel and the United States, controlled by Levin and his co-conspirators.[2]

How they got in

Nothing about the bank's own staff logins was involved. Levin used identification codes and passwords that belonged to Citibank's corporate customers.[1][2] The FBI described the attack as exploiting the telecommunications network the system ran on and compromising valid user IDs and passwords.[1]

Once logged in as a customer, he looked like that customer. The system was built to let corporate treasurers send wires on their own, so a transfer request coming from a valid login was treated as a legitimate instruction. There was no separate step that asked the real customer, on a different channel, whether they had really just ordered a large wire to an unfamiliar account on the other side of the world.

To turn the balances into cash, the scheme needed people on the ground. A Russian couple in San Francisco, where the only U.S. transfers landed, acted as local helpers, and other couriers tried to pull money out of accounts abroad.[1]

How it was caught

The first alarm came from customers reading their own statements, not from the bank's systems.[1] Once the FBI was involved, overseas accounts receiving the money were frozen so it could not be withdrawn, and couriers were arrested when they tried to collect.[1] The woman in the San Francisco couple was arrested while trying to make a withdrawal, and her husband was picked up later.[1]

Investigators traced the rest of the operation back to Levin.[1] He was arrested by British police at a London airport in March 1995 and fought extradition for about 30 months before being handed to U.S. custody in September 1997.[2]

What it cost

Levin pleaded guilty in January 1998.[1] In his plea agreement he admitted to $3.7 million of the thefts, and on February 24, 1998, a federal judge in Manhattan sentenced him to 3 years in prison and ordered $240,015 in restitution.[2] Four co-conspirators pleaded guilty to conspiracy to commit bank fraud.[2]

Because most of the money was stopped in frozen accounts, the actual loss was far smaller than the total moved, and Citibank reimbursed its customers.[1][2] The bank also made changes to its network security.[1] The FBI says the case helped push it to build its first dedicated computer intrusion squads.[1]

The missing control

The missing control: out-of-band verification of large transfers. A big wire to a new destination went through on the strength of a password alone, with no call-back or second confirmation through a separate channel.

A password proves only that someone knows it. A quick confirmation through a different route, such as a phone call to a known number or a code on a separate device, proves that the real customer wants the money to move. Had that step been required for large or first-time transfers, most of the roughly 40 wires would have stalled at the first question, and the customers would have learned their logins were compromised in June instead of reading about missing money in July.[1]

What to do in your business

Watch the case
How Citibank was robbed of $10 million by computer in 1994Drops 2026-12-07
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More payments and fraud cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. FBI: A Byte Out of History, the $10 million hack
  2. CNN Money: Internet robber sentenced