Episode · BANGLADESH BANK 2016

The Bangladesh Bank heist, start to finish: a fake job seeker, a dead printer and $81 million

Published 2026-09-29 · 9 min read · Episode 02 of the Cyber Heists long-form series
The billion-dollar bank heist: 35 orders, a broken printer, one typoPremieres 2026-10-07

On a Thursday night in February 2016, 35 payment orders left the central bank of Bangladesh asking the Federal Reserve Bank of New York to move about $951 million, and the one machine meant to show staff what was leaving had gone silent.[1][3] This long read follows the whole heist in order: the fake job seeker, the time-zone gap, the casinos in Manila, the one person convicted, and the check that would have caught it within hours.

The fake job application that opened the bank

The theft began about a year before any money moved. In January 2015, several Bangladesh Bank employees received emails from someone presenting himself as a job seeker, inviting them to download a CV and cover letter. The applicant was invented, and at least 1 employee who opened the files let the intruders into the bank's systems.[3] The U.S. Justice Department later described the entry point the same way: targeted emails written to look legitimate to specific staff.[4]

What the intruders wanted was not a vault but a messaging system. Bangladesh Bank keeps part of its foreign reserves in a U.S. dollar account at the New York Fed, and orders to move that money travel over SWIFT, the network banks use to send each other payment instructions. A message that comes from the bank's own SWIFT terminals, using the right operators' credentials, looks genuine to the bank on the other end.[1][4] So the crew spent months inside learning how payments were made and whose logins could make them.

The landing zone was built in parallel. On May 15, 2015, 4 U.S. dollar accounts were opened at the Jupiter Street branch of Rizal Commercial Banking Corporation (RCBC) in Makati, the business district of Metro Manila, in names that turned out to be fictitious.[1][2] Each started with a small deposit of about $500 and then sat idle for roughly 9 months.[1][3]

That wait is the tell of a planned job. Dormant accounts draw less scrutiny than brand-new ones that suddenly receive millions, and they gave the thieves a place to land the money the moment the orders cleared. The long quiet period also meant the break-in and the payout were separated by most of a year, which made the connection harder to see after the fact.

Why the heist was timed around 3 weekends

The orders were sent at 8:36 p.m. on Thursday, February 4, 2016, Dhaka time.[3] In Bangladesh the weekend falls on Friday and Saturday, so the office was emptying out. In New York it was Thursday morning, a full business day at the Fed. By the time Dhaka came back to work on Sunday, New York was on its own Saturday-Sunday weekend.[3] And Monday, February 8, was the Lunar New Year, a public holiday in the Philippines.[1] Put together, there was a stretch of days in which the sending bank, the paying bank and the receiving bank were never all open at once.

The malware had a second job: hiding the evidence. Bangladesh Bank relied on a printer that produced a paper record of SWIFT messages. That printer, on the 10th floor, started misbehaving around the time the orders went out.[3] Staff treated it as an ordinary technical fault, the kind that gets fixed after the weekend. When the system was finally working again, the bank found messages from New York asking about transfers nobody in Dhaka had authorized.[1]

This is the heart of the case. The bank's only routine view of outgoing payments came from the same compromised system that was sending them. Once the attackers controlled that system, they controlled what the staff could see.

35 payment orders and 1 misspelled word

Of the 35 instructions, the Fed blocked 30, worth about $850 million. Five were paid, totaling $101 million.[1] Four of them, about $81 million, went to the dormant accounts in Manila. The fifth, $20 million, was addressed to a supposed charity in Sri Lanka, the Shalika Foundation, with "foundation" misspelled. A routing bank in the chain paused the payment and asked for clarification, and a Sri Lankan bank separately judged the transfer too large for the recipient. All $20 million came back.[1]

The Manila money moved fast. The $81 million reached the RCBC accounts on Friday, February 5.[2] Bangladesh Bank's stop requests went out on February 8, the holiday, and RCBC received the SWIFT message on February 9.[1] By the time the accounts were frozen, about $58.1 million had already been withdrawn over the counter.[1][2]

Much of the rest passed through a money remittance company, Philrem Service Corporation, which received about $80.9 million through various accounts, converted it to pesos and passed it on between February 5 and 13.[2] The bank that stopped the Sri Lanka payment did what the sending bank could not: it looked at an odd detail and asked a question before the money moved.

How the money vanished into Manila's casinos

From the remittance company, the pesos went to the gaming floor. Reporting on the case says about $50 million was deposited across 2 Manila casinos, Solaire and Midas, and about $31 million was handed to a businessman who left the country.[3] At the time, Philippine casinos were outside the country's anti-money-laundering law, so they did not have to report suspicious transactions the way banks did.[7] Once money is turned into chips and back again, the paper trail thins out quickly.

Bangladesh did not handle the news well either. The theft became public about a month after the transfers, through reports in the Philippine press, and the finance minister said he had not been told by the central bank. He called its handling of the matter very incompetent.[5] On March 15, 2016, Governor Atiur Rahman resigned.[5]

The Philippine regulators moved next. On June 1, 2016, the central bank revoked the licenses of Philrem and 2 other remittance firms. On August 5, 2016, it fined RCBC 1 billion pesos.[2] A casino junket operator returned about $15 million, and that was most of what came back from the Philippines.[1][2] In July 2017, the Philippines brought casinos under its anti-money-laundering law, closing the gap the thieves had used.[7]

The branch manager, the North Korea charge and the lawsuit

Only 1 person has been convicted. Maia Santos-Deguito, the manager of the Jupiter Street branch, was found guilty by a Makati court on January 10, 2019, of 8 counts of money laundering, and sentenced to 4 to 7 years on each count. She was also ordered to pay about $109 million.[1][2] The Philippine Court of Appeals dismissed her appeal on February 6, 2023.[1][6]

The people at the keyboards were never in the Philippines. In September 2018, the Justice Department announced charges against a North Korean programmer. Prosecutors say he belonged to a North Korean government-sponsored hacking team, and the DOJ attributed the Bangladesh Bank theft, the 2014 Sony Pictures attack and the 2017 WannaCry ransomware outbreak to that group. He has been charged, not convicted, and is not in U.S. custody.[4]

Bangladesh Bank also went after the money in court. It sued RCBC and others in New York in 2019. A federal judge dismissed the racketeering case in March 2020, and the bank took its claims to New York state court, where appeals by RCBC and other defendants to end the case were rejected.[8][9] Of the $81 million that reached Manila, roughly $65 million has never been recovered.[3]

What actually stopped most of the money

Look at where the heist failed and a pattern appears. The 30 blocked orders were stopped by people at the Fed looking at requests that did not fit. The $20 million was saved by a bank that noticed a spelling error and asked. Every successful defense came from someone outside Bangladesh Bank checking a payment through their own eyes and their own systems.[1]

The $81 million got through because the sending bank had no independent view of its own account. Its record of outgoing payments came from the compromised system, and nobody was checking over the weekend. A daily comparison against the Fed's own statement, or a phone call on a known number for any unusually large order, would have raised the alarm while the money was still sitting in Manila.[1][2] After the heist, SWIFT launched a customer security program with mandatory baseline controls for the banks on its network.[1]

Timeline

DateWhat happened
Jan 2015Fake job application emails reach bank staff; malware gets in.[3]
May 15, 20154 dollar accounts opened at RCBC's Jupiter Street branch under fictitious names.[1]
Feb 4, 201635 SWIFT orders for about $951 million sent at 8:36 p.m. Dhaka time.[1][3]
Feb 5, 2016$81 million lands in the Manila accounts.[2]
Feb 8–9, 2016Stop requests sent during the Lunar New Year holiday; accounts frozen after most withdrawals.[1][2]
Mar 15, 2016Governor Atiur Rahman resigns.[5]
Jun 1, 2016Philippine central bank revokes Philrem's license.[2]
Aug 5, 2016RCBC fined 1 billion pesos.[2]
Jul 2017Philippine casinos brought under the anti-money-laundering law.[7]
Sep 2018DOJ announces charges against a North Korean programmer.[4]
Jan 10, 2019Branch manager convicted on 8 counts of money laundering.[1]
Feb 6, 2023Court of Appeals upholds the conviction.[1][6]

The missing control

The missing control: independent, out-of-band verification of outgoing payments, checked every day including weekends and holidays. Bangladesh Bank's only check lived on the same system the thieves controlled, so it went dark exactly when it was needed.[1][3]

  1. Reconcile against the bank's own record. Compare outgoing payments to your bank's online statement every business day, not to your accounting software or emailed confirmations.
  2. Call back on a number you already have. Confirm any large, unusual or first-time payment by phone using contact details on file, never ones in the request.
  3. Split entry and approval. The person who sets up a payment should never be the only person who approves it, especially for new payees.
  4. Send transfer alerts to someone outside the process. Turn on your bank's text or email alerts for outgoing transfers above a set amount and route them to an owner or partner.
  5. Treat a silent safeguard as an alarm. If a report, alert feed or printout that normally arrives stops arriving, investigate that day instead of waiting for Monday.

What it means now

The Bangladesh Bank heist is remembered for the typo, but the typo only saved $20 million. What saved $850 million was other people's diligence, and what lost $81 million was a bank that could not see its own money leaving. Luck and strangers are not a plan.

A small business faces the same shape of risk with a smaller number attached. If the only place you can see a payment is the system that sent it, a thief who controls that system controls your view. A second, independent look, checked by a person who does not send payments, turns a weekend-long head start into a same-day phone call.

The short version

How the Bangladesh Bank heist happened: $81 million over SWIFT, stopped short by a typo: the case file and the Shorts from this case.

Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

Related case files

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. Wikipedia: Bangladesh Bank robbery
  2. Philippine Center for Investigative Journalism: What went before: The Bangladesh Bank heist
  3. The Daily Star: When North Korean hackers almost pulled off a billion-dollar heist from Bangladesh Bank
  4. U.S. Department of Justice: North Korean Regime-Backed Programmer Charged With Conspiracy to Conduct Multiple Cyber Attacks and Intrusions
  5. Al Jazeera: Bangladesh Bank governor resigns after $81m hack
  6. ABS-CBN News: CA upholds Maia Deguito's money laundering conviction over Bangladesh bank heist
  7. Philippine Daily Inquirer: Duterte signs law including casinos in AMLC coverage
  8. Steptoe (court filing): Opinion dismissing Bangladesh Bank RICO case, 19 Civ. 00983, March 20, 2020
  9. The Business Standard: Reserve heist: US court rejects RCBC, 6 others' appeal