How the Punjab National Bank fraud hid $1.8 billion outside the bank's own books
For years, one branch of Punjab National Bank, one of India's largest state-owned banks, sent out guarantees worth about $1.8 billion that its own accounting system never recorded.[1][2] This case file covers how the guarantees worked, why the bank's systems could not see them, what regulators did once it surfaced, and the one control that was missing.
What happened
At the bank's Brady House branch in Mumbai, staff issued documents called letters of undertaking on behalf of a group of diamond and jewelry companies.[2] A letter of undertaking is a bank's promise to another bank: lend to my customer overseas, and if they do not repay, we will. Overseas branches of other Indian banks relied on those promises and lent the companies money to pay for imports.[2]
According to the bank and later reporting, a junior official issued these guarantees without authorization and without the collateral or approvals that should have backed them.[1][2] The activity went back at least to 2011.[1] As old guarantees came due, new ones could be issued to cover them, so the exposure kept growing instead of ending.
In January 2018, the companies asked for fresh guarantees but could not provide the security the branch now asked for, and a guarantee issued on January 16 set off an internal inquiry.[2] The bank found that fraudulent letters of undertaking had been going out for years. It disclosed the fraud publicly on February 14, 2018, putting it at about $1.8 billion, or roughly 11,400 crore rupees.[1][3] Later tallies grew higher.[6]
How it worked
Banks send these guarantees to each other over SWIFT, the secure messaging network banks around the world use for payment and credit instructions. Inside the bank, a separate core banking system is supposed to record every transaction so managers, auditors and risk teams can see the bank's total exposure.[2]
At Punjab National Bank, those 2 systems were not connected. A SWIFT message could go out to an overseas bank without any matching entry appearing in the core system.[1][2] The staff involved sent guarantees over SWIFT and simply did not record them in the bank's books, which kept them out of view of the checks that would normally have flagged them.[1][2]
SWIFT access itself was meant to have 3 layers, someone to create a message, someone to check it and someone to verify it.[2] Reporting after the fraud described officials passing guarantees without the needed approvals, which suggests those layers were not working as separate people with separate judgment.[2]
What it cost
The bank was left facing claims from the overseas lenders for guarantees it had never knowingly approved. India's Central Bureau of Investigation arrested bank officials, including a former branch official, within days of the disclosure.[7] Prosecutors in India charged the businessmen behind the companies, who left the country; those cases are still being fought in court and through extradition proceedings, so they are not named here.
The regulatory response went well beyond one bank. The Reserve Bank of India told banks to link SWIFT with their core banking systems, and state-owned banks were given until April 30, 2018, to do it.[1][4] In March 2019, the central bank fined 36 banks for failing to follow its SWIFT rules on time, and Punjab National Bank itself was fined 2 crore rupees.[5][8]
The missing control
The missing control: reconciling every outgoing SWIFT message against the core banking system, every day, with someone independent reviewing any message that has no matching entry.
The whole scheme depended on a gap between 2 records: what the bank told other banks and what the bank told itself. A daily match between the two would have turned up the first unrecorded guarantee within a day, not after years. Linking the systems so that no message could go out without a booked transaction behind it would have closed the gap entirely, which is exactly what the regulator ordered once the fraud came out.[1][4]
What to do in your business
- Match what leaves with what you record. Compare your bank's list of outgoing payments against your accounting software every week, and look into anything that appears in one but not the other.
- Separate who sends from who approves. Set up your online banking so one person creates a payment and a different person releases it.
- List every promise you make on paper. Guarantees, credit terms and purchase commitments are liabilities too. Keep a register and review it monthly.
- Have someone outside the process do the check. The person who reconciles accounts should not be the one who makes the payments.
- Treat rollovers as red flags. A customer or supplier who keeps needing new credit to pay off old credit deserves a closer look.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: How to stop fake invoices, changed bank details and fake-boss payment requests
- How the Bangladesh Bank heist happened: $81 million over SWIFT, stopped short by a typo
- How Google and Facebook were scammed: the fake supplier invoices
- The Arup deepfake scam: the $25 million video call where everyone else was fake
- The first known AI voice scam: how a fake boss's call took $243,000
- The Bitfinex hack: how 119,754 bitcoin walked out, then sat still for 5 years
- How a fake Google support call stole 4,100 bitcoin from one person
- Every payments and fraud control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- Gulf News: India instructs banks to link their core systems with SWIFT after huge fraud
- Business Today: What is LoU, CBS, SWIFT? Know these terms to understand PNB fraud
- Steemit (explainer): How India's 2nd largest PSU bank lost Rs 11,400 crore
- Business Standard: State-owned banks to link SWIFT with Core Banking Solution by April 30
- Business Standard: RBI fines 36 state, private banks for non-compliance in SWIFT operations
- The Tribune: Web of deception: how Nirav Modi cheated PNB of Rs 14,000 crore through fraudulent LoUs
- WION: CBI arrests former head of PNB's Brady House Mumbai branch
- BloombergQuint: RBI slaps Rs 2-crore fine on Punjab National Bank for violating SWIFT norms