Bangladesh Bank robbery

Last reviewed:

The Bangladesh Bank robbery, also known as the Bangladesh Bank cyber heist, was a significant cyberattack that occurred in February 2016. Cybercriminals attempted to steal nearly $1 billion from the Bangladesh Bank, the central bank of Bangladesh, by exploiting vulnerabilities in the SWIFT (Society for Worldwide Interbank Financial Telecommunication) network. The attackers successfully transferred $81 million to accounts in the Philippines before the heist was detected. This incident highlighted the vulnerabilities in financial systems and the potential for large-scale cybercrime.

Overview

The Bangladesh Bank robbery involved a sophisticated cyberattack targeting the central bank of Bangladesh. The attackers exploited weaknesses in the bank's security systems and the SWIFT network, which is used for international financial transactions. The cybercriminals managed to transfer $81 million to accounts in the Philippines before the fraudulent transactions were discovered. The heist was part of a larger attempt to steal nearly $1 billion, but the remaining transactions were blocked due to a typographical error in one of the transfer requests. The incident raised significant concerns about the security of financial institutions and the potential for cybercrime to cause substantial financial losses.

How it works

The Bangladesh Bank robbery was executed through a series of coordinated actions by the attackers. Initially, the cybercriminals gained access to the bank's internal systems by installing malware. This malware allowed them to monitor the bank's activities and gather information necessary to execute fraudulent transactions. The attackers then used the SWIFT network to send unauthorized transfer requests to the Federal Reserve Bank of New York, where Bangladesh Bank held an account.

The attackers crafted these requests to appear legitimate, using stolen credentials and information obtained through their surveillance. They attempted to transfer nearly $1 billion to various accounts in the Philippines and Sri Lanka. However, a typographical error in one of the transfer requests raised suspicion, to the detection of the fraudulent transactions. Despite this, the attackers successfully transferred $81 million before the heist was discovered.

Applications

The Bangladesh Bank robbery demonstrated the potential for cybercriminals to exploit vulnerabilities in financial systems for large-scale theft. It highlighted the importance of robust cybersecurity measures and the need for financial institutions to regularly update and secure their systems. The incident also underscored the significance of international cooperation in combating cybercrime, as the stolen funds were transferred across multiple countries.

In response to the heist, many financial institutions have strengthened their cybersecurity protocols and increased their focus on monitoring and detecting suspicious activities. The incident has also led to increased collaboration between banks, cybersecurity firms, and law enforcement agencies to prevent similar attacks in the future.

Limitations

Despite the significant impact of the Bangladesh Bank robbery, there are limitations to the methods used by the attackers. The reliance on human error, such as the typographical mistake that led to the detection of the fraudulent transactions, highlights the potential for such attacks to be thwarted by vigilant monitoring and verification processes. Additionally, the use of the SWIFT network, while a critical component of international financial transactions, also presents a point of vulnerability that can be exploited by cybercriminals.

The incident also demonstrated the challenges in recovering stolen funds once they have been transferred across international borders. The complexity of tracing and reclaiming the money highlights the need for improved international cooperation and legal frameworks to address cybercrime effectively.

Bangladesh Bank Robbery Process

Timeline of Bangladesh Bank Robbery

See also

Sources

Categories: Incidents
Last updated: September 9, 2026