CASE FILE
FC-2016-001
2016-02-04 / 05
TLP:CLEAR
// Cyber Incident Case File — Financial Crime (Nation-State, Sanctions-Evasion Motivated)

BANGLADESH BANK SWIFT HEIST

COMPILED: 2026-08-30  |  INCIDENT DATE: 2016-02-04 / 2016-02-05 (fraudulent transfers) — preceded by intrusion from ~2015  |  SOURCES: 15
Incident Type: FINANCIAL CRIME
Attribution: Lazarus Group / APT38 [HIGH]
Severity: CRITICAL
Era: 2016 (Post-ATT&CK launch, pre-CSP era)
ATT&CK Framework: Enterprise
$81M
Stolen — of $951M+ requested across 35 fraudulent SWIFT transfers
35
Fraudulent SWIFT transfer requests issued in the batch
$20M
Blocked by one misspelled word ("fandation") in a single transfer
~20-25%
Of the stolen $81M recovered, as of most recent public reporting
00
Case File Overview
Attributed Actor → Lazarus Group / APT38 (Bluenoroff) — No companion actor card on file
Incident NameBangladesh Bank SWIFT Heist
Date RangeIntrusion: ~Jan 2015 – Jan 2016 · Theft: 2016-02-04/05
Incident TypeFinancial Crime (nation-state, sanctions-evasion)
Primary ActorLazarus Group / APT38 (North Korea, RGB Bureau 121)
Attribution Confidence[HIGH]
Primary TargetBangladesh Bank (central bank) — SWIFT Alliance Access terminal
Victim Count1 primary (Bangladesh Bank); 2 correspondent institutions drawn in (NY Fed, RCBC)
Initial Discovery2016-02-06 (Saturday, Dhaka) — printer failure noticed
Discovered ByBangladesh Bank IT staff (internally); BAE Systems (malware forensics, March 2016)
Dwell Time~13 months from likely initial compromise to theft execution
Primary Impact$81M stolen; ~$870M+ in further attempted transfers blocked
ATT&CK FrameworkEnterprise
MITRE Campaign IDNone dedicated — tracked under Group G0032 (Lazarus Group) / G0082 (APT38)
Historical IOCsYes — infrastructure and hashes are 10 years stale; archival value only
01
Situation Overview

On February 4–5, 2016, unidentified attackers used stolen SWIFT credentials belonging to Bangladesh's central bank to issue 35 fraudulent transfer instructions against the bank's foreign-reserve account at the Federal Reserve Bank of New York, attempting to move roughly $951 million to accounts across Sri Lanka and the Philippines. Automated sanctions-list screening, a correspondent bank's routine due diligence, and one attacker's misspelling of the word "foundation" combined to block all but five of those requests — but those five were enough. $101 million was authorized for release; $81 million of it reached a single branch of Rizal Commercial Banking Corporation (RCBC) in Manila and was laundered through the Philippine casino industry within days, largely beyond recovery.

The Bangladesh Bank heist remains the largest bank robbery ever conducted primarily through a computer network, and — depending on how one totals the fully attempted transfers — one of the largest attempted thefts of any kind in history. It is also the operation that definitively proved a state actor was willing and able to use offensive cyber capability not for espionage or sabotage but for direct, large-scale theft of hard currency, a distinction that reshaped how the U.S. Treasury, the SWIFT cooperative, and central banks worldwide model nation-state cyber risk.

The incident sits at the intersection of three distinct failure domains that, individually, might each have been survivable: Bangladesh Bank's own network security was exceptionally weak for an institution safeguarding sovereign foreign-currency reserves; the SWIFT messaging cooperative's security model assumed member banks would secure their own endpoints, an assumption this heist proved catastrophically optimistic; and the Philippine financial and gaming-industry regulatory regime at the time contained a gap — an anti-money-laundering exemption for casinos — that was almost perfectly shaped to launder exactly this kind of windfall. Understanding the heist requires understanding all three, not just the intrusion.

Nearly nine years later, the case remains a foundational teaching example precisely because so much of it was preventable at multiple, independent points along the chain — and because the actor responsible, subsequently tracked by U.S. authorities and private researchers as a specialized financially-motivated cluster (APT38) operating under the broader Lazarus Group umbrella, went on to apply the same playbook against dozens of other financial institutions and cryptocurrency exchanges in the years that followed.

02
Background & Context

By 2016, North Korea's Reconnaissance General Bureau had been operating offensive cyber units — publicly tracked later as Bureau 121 and its subordinate elements — for over a decade, historically oriented toward espionage and, following the 2014 Sony Pictures Entertainment attack, destructive sabotage. International sanctions imposed after North Korea's nuclear and missile tests had progressively cut the regime off from conventional international finance, creating strong incentive to develop hard-currency-generating capabilities that did not depend on legitimate trade. Cyber-enabled bank theft filled that gap: unlike espionage, it produced directly usable foreign currency; unlike conventional smuggling, it could be conducted from within North Korea's borders with plausible deniability.

Bangladesh Bank was not the actor's first target using this method. A nearly identical intrusion pattern — malware manipulating a SWIFT Alliance Access-equivalent local application to send unauthorized transfer instructions and falsify confirmation records — had already been used against Ecuador's Banco del Austro in January 2015 (approximately $12 million stolen, routed through Hong Kong) and attempted against Vietnam's Tien Phong Bank (TPBank) in December 2015, where it was caught before completion. Symantec and other researchers later identified shared code and technique overlap across all three intrusions, indicating Bangladesh Bank was the third — and by far most consequential — operation in an established campaign, not an isolated event (Symantec, 2016; CFR Cyber Operations Tracker).

Bangladesh Bank's own security posture compounded the risk. Investigators who examined the bank's network after the theft found it lacked a firewall segmenting the room housing its SWIFT terminals from the rest of the institution's IT environment, and that the network relied on secondhand, roughly $10 network switches rather than enterprise-grade hardware — for an institution with direct SWIFT access to global reserve accounts (Reuters, reported via multiple outlets, April 2016). SWIFT's own security model at the time placed nearly all responsibility for endpoint security on member institutions; the cooperative provided the messaging network and standard client software (Alliance Access) but did not mandate or audit the security controls surrounding it — a design assumption this incident exposed as insufficient for an increasingly targeted threat landscape.

03
Kill Chain Narrative Phase-by-phase account of the attack as it progressed
Initial Access — Spear-Phishing Compromise BLIND
Beginning as early as January 2015 per the DOJ's later criminal complaint, operators sent spear-phishing emails to Bangladesh Bank employees carrying malicious attachments disguised as job-application documents and résumés. At least one recipient opened an attachment, executing malware that established a foothold inside the bank's internal network. Bangladesh Bank had no email-gateway sandboxing or attachment-detonation capability at the time capable of catching a targeted, low-volume spear-phish of this kind, and no contemporaneous alert exists in the public record indicating this initial compromise was ever detected as it happened.
A single opened attachment gave the operators a durable internal foothold from which to begin months of quiet reconnaissance.
Internal Reconnaissance & SWIFT Credential Theft BLIND
Over roughly a year, the operators moved laterally through Bangladesh Bank's flat, unsegmented internal network — a network reachable from the compromised foothold with no firewall isolating it from the SWIFT terminal environment — mapping the bank's payment operations and ultimately obtaining valid operator credentials for the SWIFT Alliance Access application used to originate international transfer instructions. No SWIFT network component itself was ever penetrated; the compromise was entirely of the bank's own local environment and its legitimately-issued access credentials, a distinction SWIFT itself later emphasized publicly. The absence of network segmentation meant this phase generated no meaningful internal alerting — there was effectively nothing to trip.
Legitimate SWIFT operator credentials, not a SWIFT platform vulnerability, gave the operators the ability to originate authentic-looking transfer instructions at will.
Malware Staging — DYEPACK / evtdiag.exe Deployment BLIND
In the days before the theft, the operators deployed a custom malware toolset — publicly named DYEPACK by researchers, with a core binary identified as evtdiag.exe and compiled on February 4, 2016, the same day the fraudulent transfers were issued (BAE Systems, 2016). The malware was purpose-built for this environment: it could intercept and suppress the physical printer confirmations Alliance Access normally generates for every transaction, and could delete or alter specific rows in the local SWIFT transaction database corresponding to the fraudulent transfers, preventing bank staff from seeing evidence of the requests in their own logs. This is a hallmark of the actor's tradecraft across all three related SWIFT heists: anti-forensic tooling engineered specifically against the target institution's own audit trail, not generic malware.
With the audit trail neutralized in advance, the operators could execute the theft with confidence that the bank's own systems would not raise an alarm before the money moved.
Fraudulent Transaction Execution BLIND
On the evening of Thursday, February 4, 2016 (Dhaka time — the start of Bangladesh's weekend), the operators used the stolen credentials to submit 35 SWIFT transfer instructions against Bangladesh Bank's account at the Federal Reserve Bank of New York, requesting a combined total of roughly $951 million be moved to accounts in the Philippines and Sri Lanka. The timing was deliberate: Thursday evening in Dhaka falls on a Thursday afternoon in New York, immediately ahead of the U.S. weekend, and Friday is itself part of Bangladesh's weekend — creating a compressed window in which any problem discovered by either side would be very slow to reach the other. DYEPACK's printer-suppression function activated as designed, so Bangladesh Bank staff saw no confirmation printouts and had no reason to suspect anything was underway.
The requests were now in the Federal Reserve's processing queue, and the only remaining opportunities to stop them lay entirely outside Bangladesh Bank's own visibility.
External Circuit-Breaker — Correspondent Screening & the Typo DETECTED (externally, not by the victim)
Detection, when it came, came from outside Bangladesh Bank entirely. The Federal Reserve Bank of New York's automated sanctions-compliance screening flagged one transfer request because it referenced "Jupiter" — matching the name of a vessel owned by a sanctioned Iranian shipping line — triggering manual review that held up a large share of the batch pending clarification. Separately, a $20 million transfer routed to the "Shalika Foundation" in Sri Lanka passed through Deutsche Bank as an intermediary correspondent; a Deutsche Bank compliance reviewer noticed the beneficiary was spelled "Shalika Fandation" and, treating the anomaly as suspicious, queried Bangladesh Bank directly for confirmation before releasing the funds (OCCRP, 2016; CNBC, 2016). That single query is widely credited with prompting Bangladesh Bank to instruct a halt on further transactions — by which point five requests, totaling $101 million, had already been authorized and released.
The intervention came too late to stop the theft, but early enough to prevent it from becoming the roughly billion-dollar loss the operators had actually attempted.
Delayed Discovery — The Weekend Gap VISIBLE — UNREVIEWED
On Saturday, February 6, 2016 — a working day in Bangladesh — bank staff noticed the SWIFT terminal's printer had stopped producing the routine confirmation slips it normally generated continuously, and discovered they could not access certain transaction records. Attempts to reach the Federal Reserve Bank of New York for clarification went unanswered, because Saturday in Dhaka is Saturday in New York too, and the Fed itself was closed for the weekend. By the time both institutions' business weeks overlapped again on Monday, February 8, the window in which the transfers might have been recalled had already closed for the funds that had reached Manila; the money was withdrawn from RCBC within the same window. The printer malfunction had, in effect, been visible to staff for over 48 hours before its significance was understood.
By the time the scale of the fraud was understood, the stolen funds had already entered the Philippine banking and casino system, where recovery jurisdictionally and practically became far harder.
Cash-Out — Philippine Money Laundering DETECTED (post-facto, by Philippine AMLC investigation)
The $81 million that reached RCBC's Jupiter Street branch in Makati City was deposited into accounts, some reportedly opened using fabricated documentation, then rapidly converted and moved through the remittance company PhilRem and into the Philippine casino ecosystem — notably Solaire Resort and the Midas Hotel and Casino — via junket operators including Kim Wong's Eastern Hawaii Leisure Company. At the time, Philippine law exempted casinos from the country's Anti-Money Laundering Act reporting requirements, allowing large sums to be converted into casino chips, gambled or simply cashed out, and dispersed with minimal paper trail — a loophole the operators appear to have exploited by design rather than coincidence. RCBC branch manager Maia Santos Deguito was later convicted of money laundering for her role in processing the transactions and sentenced to decades in prison; junket operators Kim Wong and Weikang Xu were separately investigated but ultimately not convicted for lack of sufficient evidence.
04
TTPs — MITRE ATT&CK Mapping Enterprise Framework — forward-mapped (post-dates ATT&CK's 2015 launch)
Initial Access
T1566.001
Phishing: Spearphishing Attachment
Job-application/résumé-themed malicious attachments sent to Bangladesh Bank employees, ~Jan 2015.
Discovery
T1046
Network Service Discovery
Extended internal reconnaissance to map payment-operations systems and locate the SWIFT Alliance Access terminal environment.
Credential Access
T1078
Valid Accounts
Operators obtained legitimate SWIFT operator credentials rather than exploiting a SWIFT platform vulnerability — the core enabling technique of the entire operation.
Persistence
T1053
Scheduled Task/Job
Reported use of persistence mechanisms to maintain access across the ~13-month dwell period between initial compromise and theft.
Defense Evasion
T1070.004
Indicator Removal: File Deletion
DYEPACK/evtdiag.exe used targeted SQL operations to delete database rows recording the fraudulent SWIFT transactions.
Defense Evasion
T1565.001
Data Manipulation: Stored Data Manipulation
Local Alliance Access transaction database records altered to mask evidence of the fraudulent transfer requests from bank staff.
Impact
T1491
Defacement (adapted: Output/Confirmation Manipulation)
Malware intercepted and suppressed physical printer confirmations for the fraudulent SWIFT messages, denying staff their normal paper audit trail.
Impact
T1657
Financial Theft
Direct theft of $81M via authorized-looking, fraudulently-originated interbank SWIFT transfer instructions.
Exfiltration (of Funds)
T1537
Transfer Data to Cloud Account (adapted: Transfer Funds to External Accounts)
Stolen funds moved to RCBC-held accounts, then rapidly laundered through remittance services and casino junket operators in Manila.
05
Defender Post-Mortem What was missed, when, and why
INITIAL ACCESS
MISSED
No email-gateway detonation/sandboxing existed to catch the spear-phishing attachment before an employee opened it — a basic control that was standard at better-resourced financial institutions by 2015 but absent here.
NETWORK SEGMENTATION
MISSED — ARCHITECTURAL
The absence of a firewall separating the SWIFT terminal environment from the general corporate network meant a single compromised workstation had an unobstructed path to the bank's most sensitive payment infrastructure — a design failure, not a detection failure.
EXTERNAL SCREENING
PARTIALLY EFFECTIVE
This is the phase that actually worked, imperfectly. The Federal Reserve's sanctions-list screening and Deutsche Bank's manual compliance review both caught anomalies the victim institution's own systems could not — demonstrating that correspondent-bank controls, even generic ones not designed for fraud detection, can function as a last line of defense when the originating institution's own defenses fail completely.
TIME-ZONE / WEEKEND GAP
MISSED — PROCESS
No 24/7 incident-communication channel existed between Bangladesh Bank and the Federal Reserve capable of surviving the mismatch between Bangladesh's Friday-Saturday weekend and the U.S. Saturday-Sunday weekend — a gap the operators appear to have deliberately timed the attack to exploit.
POST-INCIDENT
LESSON ADOPTED
SWIFT launched its Customer Security Programme (CSP) in 2016, introducing mandatory, annually-attested security controls for all member institutions — network segmentation, multi-factor authentication, and restricted operator privileges among them — effectively converting what had been optional guidance into a compliance requirement enforced across the entire cooperative (SWIFT, 2016; ISACA, 2022).
POST-INCIDENT
LESSON ADOPTED
The Philippines amended its Anti-Money Laundering Act in 2017 to bring casinos within its AML reporting regime, directly closing the specific laundering pathway this operation exploited.
06
Technical Artifacts Malware, tools, CVEs, IOCs
evtdiag.exe / DYEPACK
Custom malware — anti-forensic / SWIFT manipulation [HISTORICAL — Limited detection utility]
Core payload identified by BAE Systems, compiled February 4, 2016. Manipulated the local SWIFT Alliance Access database via targeted SQL operations to delete/alter rows corresponding to fraudulent transfer requests, and intercepted the local print spooler to suppress and forge physical confirmation printouts, preventing bank staff from noticing the unauthorized transactions through their normal paper-based audit process.
NESTEGG
Funds-transfer message forging tool [HISTORICAL — Limited detection utility]
Tool in the broader BeagleBoyz/APT38 toolset associated with forging and manipulating financial transfer messages, referenced across multiple US-CERT/CISA "HIDDEN COBRA" advisories covering the actor's SWIFT-targeting campaigns.
Spear-Phishing Lures (job-application themed)
Delivery mechanism [HISTORICAL — Limited detection utility]
Malicious documents disguised as résumés/job applications, per the DOJ's 2018 criminal complaint against Park Jin Hyok — a lure theme reused across multiple Lazarus Group operations of this era.
⚠ All IPs and domains defanged. Reconstruct before use in detection tooling.
⚠ HISTORICAL IOCs — These artifacts are archival, dating to 2016. Infrastructure has long since rotated. Use for research and retrospective analysis only.
TypeValue / DescriptionSourceDate
FILE HASHevtdiag.exe — specific SHA-256 not consistently published in open sources reviewed for this compileBAE Systems2016-04
INFRASTRUCTUREMonitoring server reported located in Egypt, used to observe SWIFT terminal usage patterns at Bangladesh Bank prior to the theftBAE Systems2016-04
BENEFICIARY (fraud)"Shalika Fandation" [sic] — Sri Lanka, misspelled beneficiary name that triggered the Deutsche Bank compliance queryOCCRP / CNBC2016-03
RECIPIENT BRANCHRCBC Jupiter Street branch, Makati City, PhilippinesMultiple (Reuters, Rappler)2016
NOTENo further specific network IOCs (defanged IPs/domains for C2) were located in open-source reporting reviewed for this compile with sufficient corroboration to publish; BAE Systems' full indicator set was not fully republished in the secondary sources consulted.
07
Consequences Strategic · Technical · Legal/Regulatory
⬡ Strategic / Geopolitical
Confirmed, for the first time at this scale, that a nation-state was willing to use offensive cyber capability for direct hard-currency theft rather than espionage or sabotage — reframing North Korea's cyber program in Western threat models as a sanctions-evasion and revenue-generation instrument. The case directly informed subsequent U.S. Treasury OFAC sanctions designations against North Korean cyber actors, including the September 2019 designation of Lazarus Group, Bluenoroff, and Andariel as instruments of the North Korean government.
⬡ Technical / Capability
SWIFT's Customer Security Programme (CSP), launched in 2016, converted previously optional security guidance into mandatory, annually self-attested controls for the entire SWIFT membership — network segmentation, restricted operator privileges, and multi-factor authentication chief among them. The heist also established the specific "local application manipulation + printer/log suppression" playbook as a recognized technique class, subsequently seen again in attacks against other regional banks.
⬡ Legal / Regulatory
The Philippines amended its Anti-Money Laundering Act in 2017 to close the casino-reporting exemption exploited during laundering. RCBC was fined by the Philippine central bank (Bangko Sentral ng Pilipinas) — at the time a record penalty for a Philippine bank. RCBC branch manager Maia Santos Deguito was convicted of money laundering. The U.S. DOJ's 2018 criminal complaint against Park Jin Hyok formally tied the heist to North Korean state cyber operations within a single continuing conspiracy that also encompassed the Sony Pictures attack and WannaCry.
08
Attribution
ATTRIBUTION CONFIDENCE: HIGH
Attributed ToLazarus Group (broad); APT38 / Bluenoroff / BeagleBoyz (specific financially-motivated cluster)
SponsorDemocratic People's Republic of Korea — Reconnaissance General Bureau (Bureau 121)
Formal AttributionYes — US DOJ criminal complaint (2018); US Treasury OFAC designations (2019)
IndictmentsPark Jin Hyok charged 2018 (conspiracy to commit wire fraud and computer-related fraud)
Companion Actor CardNone on file for Lazarus Group / APT38 as of this compile
Primary EvidenceMalware code-family overlap with Sony Pictures/WannaCry intrusions; shared infrastructure and tradecraft across the Ecuador/TPBank/Bangladesh SWIFT intrusion series; DOJ complaint's technical annex
Competing HypothesesBangladesh Bank officials floated an insider-involvement theory early in the investigation; no public evidence has substantiated insider complicity as the primary vector, and it is not treated as a serious competing attribution today
What Would Change AssessmentCredible new forensic evidence contradicting the malware code-overlap findings, or a demonstrated alternative actor with matching capability and motive

Attribution to North Korean state actors rests on convergent evidence from multiple independent sources: private-sector malware analysis (Symantec, BAE Systems) identifying code overlap between the Bangladesh Bank malware and tools used in the 2014 Sony Pictures attack and the WannaCry ransomware outbreak, both already attributed to North Korean operators; a formal U.S. Department of Justice criminal complaint (2018) charging a named North Korean individual, Park Jin Hyok, within a single conspiracy spanning all three incidents; and subsequent U.S. Treasury sanctions explicitly naming Lazarus Group, Bluenoroff, and Andariel as instruments of the North Korean government. MITRE ATT&CK further refines this picture by tracking the SWIFT-targeting, financially-motivated operations specifically under APT38/BeagleBoyz (G0082) — a narrower cluster within the broader Lazarus Group umbrella (G0032) distinguished by Mandiant/FireEye's research as specializing in bank theft rather than the destructive or espionage operations associated with other Lazarus sub-clusters. This layered, multi-source convergence is why this repository assesses attribution confidence as [HIGH] rather than [MEDIUM] — a rarer outcome for nation-state financial crime, where deniability is typically easier to maintain than in destructive or espionage operations that leave more forensic signature.

09
Historical Significance

The Bangladesh Bank heist is the incident that moved "nation-state bank robbery" from a theoretical category into a documented, repeatable operational pattern. Before 2016, the working assumption among central banks and the SWIFT cooperative was that state-sponsored cyber capability was aimed at espionage, sabotage, or political signaling — not straightforward theft of hard currency at scale. The heist, combined with the preceding Ecuador and Vietnam operations, established that a state actor could and would treat direct financial theft as a legitimate instrument of statecraft, particularly under sanctions pressure, and that it could execute such theft using the same trusted-messaging infrastructure (SWIFT) that underpins the entire international banking system.

It is taught today primarily as a case study in distributed, cross-institutional failure rather than a single dramatic breach: no single control failure caused the loss, and no single control fix would have prevented it. Bangladesh Bank's absent network segmentation enabled the intrusion; SWIFT's endpoint-security assumptions enabled the fraudulent messages to look authentic; the Philippines' casino AML exemption enabled the laundering; and only a combination of unrelated, largely accidental external checks — a sanctions-screening name match and a compliance officer's eye for a spelling error — kept the loss from being roughly twelve times larger. This is precisely the analytical lesson the case is used to teach: resilience in interconnected financial systems has to be modeled across the entire chain of institutions a transaction touches, not just the originating one.

The incident's aftermath also reshaped SWIFT's own governance. The Customer Security Programme it produced remains, a decade later, the primary mechanism by which the cooperative enforces baseline security expectations across thousands of member institutions worldwide — arguably making this the most consequential single incident in SWIFT's operating history. And the actor's continued evolution — Bureau 121's financially-motivated cluster went on to pursue cryptocurrency exchanges with the same playbook throughout the following decade — demonstrates that the underlying incentive structure this case exposed (a sanctioned state needing hard currency, and finding cyber theft cheaper and lower-risk than the alternatives) has not gone away.

10
References URLs are NOT defanged — navigate directly
MITRE ATT&CK
Accessed: 2026-08-30
MITRE ATT&CK
Accessed: 2026-08-30
U.S. Department of Justice / FBI
Accessed: 2026-08-30
BankInfoSecurity
Accessed: 2026-08-30
SecurityWeek
Accessed: 2026-08-30
CONTEMPORANEOUS REPORTING — 2016-04
OCCRP
Accessed: 2026-08-30
CONTEMPORANEOUS REPORTING — 2016-03
CNBC
Accessed: 2026-08-30
CONTEMPORANEOUS REPORTING — 2016-03
Wikipedia (secondary, corroborating)
Accessed: 2026-08-30
Council on Foreign Relations
Accessed: 2026-08-30
ISACA Journal
Accessed: 2026-08-30
National Security Archive (GWU)
Accessed: 2026-08-30
Wikipedia — Atiur Rahman
Accessed: 2026-08-30
SPUZ (technical analysis)
Accessed: 2026-08-30