A detailed account of the biggest cyber bank robbery on record
On a Sunday morning in February 2016, a malfunctioning printer in the Bangladesh Central Bank’s ninth-floor accounts and budgeting department exposed what would become the largest attempted bank heist in recorded history. A routine technical glitch turned out to be evidence of a $951 million fraud scheme. The attackers did not tunnel through vaults or overpower security guards. They exploited one compromised email credential, used the world’s main interbank messaging network to send fraudulent instructions, and came close to emptying a developing nation’s foreign reserves in a matter of hours. This is a detailed account of how it happened, who was responsible, and how it changed the global financial system.
Understanding SWIFT: the backbone they attacked
Before getting into the mechanics of the breach, it helps to understand what SWIFT actually is, and what it is not. The Society for Worldwide Interbank Financial Telecommunication, founded in 1973 and headquartered in La Hulpe, Belgium, is a messaging network used by over 11,000 financial institutions across more than 200 countries. SWIFT does not hold funds, does not transfer money, and does not maintain accounts. What it does is transmit standardized, encrypted payment instructions between correspondent banks. When Bangladesh Bank instructs the Federal Reserve Bank of New York to move $20 million to an account in Sri Lanka, that instruction travels as a SWIFT MT103 message (or, in newer implementations, an ISO 20022 XML message) authenticated with cryptographic keys unique to the sending institution.
The security model of SWIFT relies on endpoint integrity. The network itself employs AES-256 encryption, mutual TLS authentication, and hardware security modules for key management. As of 2016, no external breach of SWIFT’s core infrastructure had ever been recorded. The vulnerability wasn’t in SWIFT’s network; it was in the endpoints connected to it. Each member institution is responsible for securing its own SWIFT Alliance Access terminals, the workstations from which operators compose, approve, and transmit payment messages. This design, trust distributed across thousands of endpoints with widely varying security, created exactly the kind of attack surface the Bangladesh heist exploited.
The initial compromise: a single email in January 2016

Approximately one month before the heist, in January 2016, an employee at Bangladesh Bank received and opened a malicious email. Forensic analysis later conducted by BAE Systems, FireEye (now Mandiant), and Symantec confirmed that the payload was a customized Trojan designed for persistent network infiltration. The malware, which cybersecurity researchers would later catalog under multiple designations including Trojan.Contopee and a variant of the backdoor known as “EvilBunny,” established a covert command-and-control channel to external servers.
Once inside the network, the attackers did not immediately strike. They conducted what threat intelligence professionals call a “dwell period”: a phase of reconnaissance lasting several weeks. During this window, the intruders mapped the bank’s internal network topology, identified workstations connected to the SWIFT Alliance system, harvested operator credentials, studied the approval workflows for international transfers, and cataloged the security protocols in place. They observed which employees handled SWIFT operations, what hours they worked, and how transaction confirmations were generated and distributed. This patience is a hallmark of advanced persistent threat actors and distinguishes state-level operations from opportunistic cybercrime.
Bangladesh Bank’s internal security posture, as later revealed in investigative reports, was inadequate for an institution holding billions in foreign reserves. The bank operated without a dedicated firewall separating its SWIFT infrastructure from general office networks. There were no intrusion detection systems monitoring for anomalous lateral movement. Antivirus signatures were outdated. The SWIFT terminals ran on aging Windows installations without the latest security patches. The attackers found a soft target guarding a hard asset.
The attack window: engineered around global time zones
The heist was launched on Thursday, February 4, 2016, deliberately timed to coincide with the Bangladeshi weekend, which in the Muslim-majority nation falls on Friday and Saturday. The attackers understood that the bank would be minimally staffed for the next two days. They also understood the downstream implications: the Federal Reserve Bank of New York would be closed over the American weekend (Saturday-Sunday), and the recipient institutions in the Philippines would be observing Chinese New Year on the following Monday.
This timing was one of the more calculated parts of the operation. The attackers needed a window of roughly five business days across three jurisdictions before any human reviewer could intervene. Every hour of delay in detection compounded their advantage. The attack combined a technical exploit with a logistics plan built around the operating calendars of central banks in three countries.
Executing the fraud: 35 SWIFT messages, $951 million

Using the stolen credentials and their detailed knowledge of the bank’s SWIFT operations, the attackers composed and transmitted 35 fraudulent payment instructions through Bangladesh Bank’s SWIFT terminal. These messages directed the Federal Reserve Bank of New York, where Bangladesh Bank maintained a correspondent account holding roughly $3 billion in foreign exchange reserves, to transfer a combined $951 million to accounts across Asia.
The messages were formatted correctly, carried valid authentication, and originated from the correct SWIFT BIC code. To the New York Fed’s automated processing systems, these were indistinguishable from legitimate instructions. The Fed’s systems began executing the transfers on Friday, February 5, processing them in batches as standard procedure dictated.
📬 Stay Ahead of Cyber Threats
Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.
Subscribe to the Newsletter →At the same time, the attackers ran a second operation inside the bank’s internal systems. They deployed additional malware targeting the SWIFT Alliance software’s database and the connected automated printing system. This printer, which normally produced real-time hard copies of all transaction confirmations, was deliberately crashed. The attackers also deleted transaction records from the SWIFT database, removing the electronic paper trail that would have alerted staff immediately. The printer malfunction that the director discovered on Sunday was not a coincidence. It was sabotage, meant to blind the bank’s internal monitoring during the 72-hour window.
The $870 million that was saved by a typo
Of the 35 transfer requests, 30 (totaling $870 million) were flagged by the New York Fed’s automated compliance systems for manual review. The trigger was, by all accounts, a fortunate accident. One of the payment instructions contained the word “Jupiter” in the beneficiary address field. This matched an entry in a sanctions screening database associated with a shipping company blacklisted for evading United States sanctions against Iran. The match was almost certainly coincidental (the “Jupiter” in question referred to Jupiter Street in Manila, where the recipient bank branch was located), but it was enough to halt automated processing.
When Fed compliance officers reviewed the flagged transactions on Monday, February 8, several red flags became apparent. The sheer volume of instructions, 35 in a single batch, was anomalous for Bangladesh Bank’s typical transaction patterns. The beneficiaries were private entities and non-governmental organizations rather than financial institutions, which is unusual for central bank settlements. The aggregate value was disproportionate to any legitimate operational need. The Fed placed all flagged transactions on hold and initiated a clarification request to Bangladesh Bank.
By the time Bangladesh Bank staff, returning from their weekend, confirmed that no such transfers had been authorized, the stop-payment orders were already in motion. The $870 million never left the New York account.
The $20 million rerouted: “Fandation” and the Sri Lanka transfer
One of the five transactions that initially cleared automated processing was a $20 million transfer routed through Deutsche Bank in Frankfurt to an account at Pan Asia Bank in Sri Lanka, designated for an entity called the “Shalika Foundation.” An alert compliance officer at Pan Asia Bank noticed that $20 million was a grossly disproportionate deposit for a small Sri Lankan NGO and initiated a verification request back through the routing bank.
During Deutsche Bank’s review in Frankfurt, analysts identified several irregularities, including a misspelling in the beneficiary name: “Fandation” instead of “Foundation.” Additional checks revealed that the Shalika Foundation had no verifiable registration, no operational history, and no legitimate reason to receive an eight-figure sum from a central bank. The transfer was reversed, and the $20 million was returned to Bangladesh Bank’s account at the New York Fed.
The $81 million that vanished: RCBC and the Philippines casino pipeline

The remaining four transfers, totaling $81 million, were routed to four accounts at the Jupiter Street branch of the Rizal Commercial Banking Corporation (RCBC) in Manila, Philippines. These accounts had been opened in May 2015, nine months before the heist, by two Chinese nationals identified in later investigations as Ding Zhize and Gao Shuhua. Each account was seeded with $500 and left dormant, a classic money laundering preparation technique meant to age the accounts and reduce the likelihood of triggering new-account monitoring thresholds.
When the $81 million arrived in four tranches, RCBC’s anti-money laundering systems failed to generate alerts. The funds were almost immediately withdrawn in cash and funneled into Philippine casino operations, where they were converted into gambling chips and then cashed out, severing the electronic trail. Philippine law at the time exempted casinos from the Anti-Money Laundering Act’s reporting requirements, a regulatory blind spot the launderers exploited.
Bangladesh Bank’s stop-payment order, transmitted on Sunday, February 7, was not received and acted on by RCBC until Tuesday, February 9, because Monday was a Philippine public holiday for Chinese New Year. By then, the funds had already been withdrawn and dispersed.
Attribution: Lazarus Group and the North Korean connection
In the months following the heist, cybersecurity firms including Symantec, BAE Systems, and Kaspersky Lab, and later the FBI and U.S. Department of Justice, conducted forensic analyses of the malware used in the attack. The codebase shared substantial overlaps with tools previously observed in operations attributed to a threat actor designated Lazarus Group (also tracked as APT38, Hidden Cobra, and Zinc by various vendors).
Key forensic indicators linking the Bangladesh operation to Lazarus included shared code libraries, identical encryption routines, overlapping command-and-control infrastructure, and matching compilation timestamps. Researchers at Kaspersky and Symantec also identified a North Korean IP address that had accessed one of the attack servers during the operational window, and Korean-language strings embedded in portions of the malware code, including comments and variable names consistent with North Korean computing conventions.
In September 2018, the U.S. Department of Justice unsealed a criminal complaint against Park Jin Hyok, a North Korean programmer allegedly working for the Reconnaissance General Bureau, the country’s primary intelligence agency. The complaint detailed his involvement in the Bangladesh Bank heist, the 2014 Sony Pictures intrusion, the WannaCry ransomware campaign of 2017, and numerous other operations. In February 2021, the DOJ further indicted three additional North Korean military intelligence officers, Jon Chang Hyok, Kim Il, and Park Jin Hyok, for a conspiracy spanning multiple years and targeting financial institutions, aerospace companies, and entertainment firms worldwide.
The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) subsequently designated Lazarus Group, Bluenoroff (the subgroup focused on financial theft), and Andariel (focused on espionage) as Specially Designated Nationals, freezing any assets under U.S. jurisdiction and prohibiting transactions.
North Korea has consistently denied involvement, calling the accusations a “hostile plot.” The consensus among Western intelligence agencies, cybersecurity researchers, and financial regulators, however, is that the operation was directed by or on behalf of the DPRK regime, likely to generate hard currency for sanctioned programs including nuclear weapons development.
The broader Lazarus campaign: not an isolated incident
The Bangladesh Bank heist was not an isolated event. Investigations revealed that the same infrastructure and tradecraft were deployed against financial institutions in Vietnam, Ecuador, Mexico, Poland, and at least 18 other countries between 2015 and 2018. In several cases, the attacks were detected before funds could be moved. In others, smaller sums were successfully stolen.
The 2017 WannaCry ransomware attack, which crippled the UK’s National Health Service, disrupted FedEx operations, and affected over 230,000 computers in 150 countries, was also attributed to Lazarus. The 2014 Sony Pictures breach, which leaked unreleased films and internal communications in retaliation for the comedy “The Interview,” shared forensic fingerprints with the banking operations. The pattern points to an organization with a broad mandate: espionage, disruption, and revenue generation, all in service of a sanctioned, isolated state.
Technical Analysis of the malware
The malware deployed at Bangladesh Bank was a multi-stage implant. Initial access was achieved through a spear-phishing email carrying a weaponized document (likely a .doc or .rtf file exploiting a known CVE in Microsoft Office). Upon execution, the payload dropped a first-stage loader that established persistence via registry run keys and scheduled tasks. This loader then downloaded a second-stage backdoor capable of keylogging, screen capture, file exfiltration, and arbitrary command execution.
The SWIFT-specific component was a tailored module that interfaced directly with the SWIFT Alliance Access application’s database (typically a DB2 or Oracle instance storing message logs). This module could suppress confirmation messages, alter transaction records, and trigger the printer crash by corrupting the print spooler service’s configuration files. The attackers demonstrated detailed knowledge of the SWIFT software’s architecture, suggesting either prior reconnaissance of similar installations or access to leaked documentation.

Network traffic analysis showed the malware communicating with C2 servers over HTTPS using self-signed certificates, with fallback channels over DNS tunneling for environments where direct outbound connections were restricted. The encryption used for C2 communications was a custom implementation of AES-128 in CBC mode with a hardcoded key derivation function, sophisticated enough to evade basic network inspection but ultimately breakable by skilled reverse engineers.
Regulatory and industry aftermath
The Bangladesh Bank heist sent shockwaves through the global financial system and triggered immediate regulatory responses. SWIFT launched its Customer Security Programme (CSP) in 2017, introducing mandatory security controls for all member institutions. The CSP framework includes requirements for secure environments, access control, operational integrity, and detection and response capabilities. Institutions must now attest annually to their compliance, and SWIFT gained authority to report non-compliant members to their national regulators.
Bangladesh Bank itself underwent significant leadership changes. Governor Atiur Rahman resigned in March 2016 amid the fallout. Subsequent investigations by the Bangladesh government and international bodies identified systemic failures in the bank’s IT governance, procurement practices, and incident response capabilities. A forensic audit revealed that the bank’s antivirus software had not been updated in months, that network segmentation was nonexistent, and that the SWIFT environment was accessible from general-purpose workstations without multi-factor authentication.
In the Philippines, the incident exposed critical gaps in the country’s anti-money laundering framework. The Philippine Congress subsequently amended the Anti-Money Laundering Act to include casinos as covered entities, requiring them to report suspicious transactions exceeding 500,000 pesos. The Bangko Sentral ng Pilipinas (Philippine central bank) also tightened know-your-customer requirements for new account openings.
RCBC faced significant regulatory scrutiny and was fined by the Philippine central bank. The bank’s Jupiter Street branch manager was dismissed, and internal investigations revealed failures in transaction monitoring protocols. The incident also prompted a broader review of correspondent banking relationships and the due diligence obligations of intermediary banks in multi-jurisdictional transfers.
The geopolitical dimension: state-sponsored financial crime
Nation-state hacking before this had mostly meant espionage, intellectual property theft, and disruption. The idea that a government would direct its intelligence apparatus to rob another country’s central bank, effectively financial warfare carried out through crime, had no clear precedent.
For North Korea, cyber-enabled financial theft is a strategic necessity. Subject to comprehensive international sanctions that restrict its access to the global banking system, the DPRK has limited avenues for generating foreign currency. Cyber operations provide a low-cost, high-revenue, and deniable mechanism for funding the regime’s priorities. Estimates from the United Nations Panel of Experts on North Korea suggest that the country has stolen over $2 billion through cyber operations between 2015 and 2020, targeting banks, cryptocurrency exchanges, and financial institutions globally.
The implications extend beyond North Korea. The Bangladesh heist demonstrated that a resource-constrained actor with skilled programmers and patient tradecraft could threaten the integrity of the global payments system. It forced central banks in developing nations, many of which had underinvested in cybersecurity relative to their financial holdings, to reassess their risk exposure.
Recovery efforts and outstanding losses
Bangladesh has recovered the $20 million rerouted from Sri Lanka and the $870 million blocked at the New York Fed. The $81 million transferred to the Philippines, however, remains largely unrecovered. Philippine authorities conducted investigations, and several individuals were charged, including RCBC branch personnel and the two Chinese nationals who opened the accounts. Ding Zhize and Gao Shuhua fled to Macau before they could be apprehended, and the casino trail severed the money’s traceability.
In 2018, a Philippine court ordered the return of approximately $15 million that had been partially traced, but the bulk of the $81 million is believed to have been converted to cash, moved through Macau’s financial channels, and ultimately delivered to North Korean operatives. The Bangladesh government has pursued legal action against RCBC and the Philippine government, seeking restitution, but progress has been slow and complicated by jurisdictional challenges.
Lessons for financial institutions: what the heist taught the industry
The Bangladesh Bank incident taught the global financial sector several lessons.
First, endpoint security is the primary attack surface for SWIFT-based fraud. No amount of network-level encryption compensates for a compromised operator workstation. Institutions need strict network segmentation, so SWIFT terminals run in isolated environments with no direct connection to corporate networks or the internet.
Second, transaction monitoring must incorporate behavioral analytics rather than relying solely on rule-based thresholds. Bangladesh Bank’s typical transaction volume and pattern made the 35-payment batch a statistical anomaly that should have triggered alerts even without the sanctions keyword match. Modern systems now use machine learning models trained on historical transaction patterns to flag deviations in real time.
Third, the incident showed the importance of multi-factor authentication and dual-control approval workflows for high-value transactions. Had Bangladesh Bank required two independent operators to authenticate each SWIFT message using hardware tokens, the attackers’ stolen credentials alone would have been insufficient.
Fourth, incident response planning must account for coordination across time zones and jurisdictions. The heist succeeded in part because the attack exploited gaps between operating hours and public holidays across three countries. Financial institutions now run tabletop exercises that simulate cross-border fraud scenarios and set up communication channels with correspondent banks and regulators in advance, to cut response time.
Fifth, the printer sabotage showed the need for redundant monitoring channels. Relying on a single automated printing system as the primary mechanism for transaction awareness created a single point of failure. Modern implementations use distributed logging, real-time SIEM dashboards, and automated SMS/email alerts to ensure that no single system failure can blind operators to account activity.
The human element: social engineering and insider risk
While the technical dimensions of the heist dominate the narrative, the human element deserves equal scrutiny. The initial compromise began with a single employee clicking a malicious email attachment, a reminder that even sophisticated technical controls can be undone by human error. Phishing remains the most common initial access vector in financial sector breaches, and the Bangladesh incident reinforced the need for ongoing security awareness training.
Whether any insider helped the attackers is an equally significant question. The attackers’ detailed knowledge of the bank’s SWIFT operations, printer configurations, and approval workflows raises questions that remain partially unresolved. While the dominant account places full responsibility on the external Lazarus operators, the depth of operational knowledge involved has led some investigators to suggest either an unusually thorough reconnaissance phase or possible insider awareness, though no evidence of direct insider involvement has been made public.
The ongoing threat: Lazarus in the 2020s
Lazarus Group has not ceased operations. In the years following the Bangladesh heist, the group has shifted much of its focus to cryptocurrency theft, targeting decentralized finance protocols, cross-chain bridges, and cryptocurrency exchanges. The 2022 Ronin Network hack ($625 million), the 2022 Harmony Horizon Bridge exploit ($100 million), and numerous smaller exchange breaches have been attributed to DPRK-linked actors. The U.S. Treasury estimates that North Korea stole approximately $1.7 billion in cryptocurrency in 2022 alone.
The tradecraft has evolved, but the strategic objective remains unchanged: generate revenue for a sanctioned regime through cyber operations. Financial institutions, cryptocurrency platforms, and central banks worldwide continue to face an adaptive, patient, and technically capable adversary that treats cybercrime as a state function.
a turning point in cyber-financial security
The Bangladesh Bank heist of February 2016 was a proof of concept. It showed that a determined, state-backed adversary could exploit the global financial system’s reliance on trust-based systems like SWIFT once endpoint security fails. It also showed how geopolitical isolation can push a nation toward organized bank robbery, and how timing, technical skill, and regulatory gaps almost combined to steal a billion dollars from one of the world’s poorest countries.
The $81 million that was actually stolen is more than a financial loss. For Bangladesh, a country where that sum could fund infrastructure, healthcare, or education for millions, it was a national wound. For the global financial system, it led to the largest overhaul of interbank security protocols since SWIFT’s founding.
The printer that malfunctioned that Sunday morning in Dhaka revealed more than a heist. It showed how thin the line was between the world’s payment network and the security of its weakest endpoints.









