On February 4–5, 2016, unidentified attackers used stolen SWIFT credentials belonging to Bangladesh's central bank to issue 35 fraudulent transfer instructions against the bank's foreign-reserve account at the Federal Reserve Bank of New York, attempting to move roughly $951 million to accounts across Sri Lanka and the Philippines. Automated sanctions-list screening, a correspondent bank's routine due diligence, and one attacker's misspelling of the word "foundation" combined to block all but five of those requests — but those five were enough. $101 million was authorized for release; $81 million of it reached a single branch of Rizal Commercial Banking Corporation (RCBC) in Manila and was laundered through the Philippine casino industry within days, largely beyond recovery.
The Bangladesh Bank heist remains the largest bank robbery ever conducted primarily through a computer network, and — depending on how one totals the fully attempted transfers — one of the largest attempted thefts of any kind in history. It is also the operation that definitively proved a state actor was willing and able to use offensive cyber capability not for espionage or sabotage but for direct, large-scale theft of hard currency, a distinction that reshaped how the U.S. Treasury, the SWIFT cooperative, and central banks worldwide model nation-state cyber risk.
The incident sits at the intersection of three distinct failure domains that, individually, might each have been survivable: Bangladesh Bank's own network security was exceptionally weak for an institution safeguarding sovereign foreign-currency reserves; the SWIFT messaging cooperative's security model assumed member banks would secure their own endpoints, an assumption this heist proved catastrophically optimistic; and the Philippine financial and gaming-industry regulatory regime at the time contained a gap — an anti-money-laundering exemption for casinos — that was almost perfectly shaped to launder exactly this kind of windfall. Understanding the heist requires understanding all three, not just the intrusion.
Nearly nine years later, the case remains a foundational teaching example precisely because so much of it was preventable at multiple, independent points along the chain — and because the actor responsible, subsequently tracked by U.S. authorities and private researchers as a specialized financially-motivated cluster (APT38) operating under the broader Lazarus Group umbrella, went on to apply the same playbook against dozens of other financial institutions and cryptocurrency exchanges in the years that followed.
By 2016, North Korea's Reconnaissance General Bureau had been operating offensive cyber units — publicly tracked later as Bureau 121 and its subordinate elements — for over a decade, historically oriented toward espionage and, following the 2014 Sony Pictures Entertainment attack, destructive sabotage. International sanctions imposed after North Korea's nuclear and missile tests had progressively cut the regime off from conventional international finance, creating strong incentive to develop hard-currency-generating capabilities that did not depend on legitimate trade. Cyber-enabled bank theft filled that gap: unlike espionage, it produced directly usable foreign currency; unlike conventional smuggling, it could be conducted from within North Korea's borders with plausible deniability.
Bangladesh Bank was not the actor's first target using this method. A nearly identical intrusion pattern — malware manipulating a SWIFT Alliance Access-equivalent local application to send unauthorized transfer instructions and falsify confirmation records — had already been used against Ecuador's Banco del Austro in January 2015 (approximately $12 million stolen, routed through Hong Kong) and attempted against Vietnam's Tien Phong Bank (TPBank) in December 2015, where it was caught before completion. Symantec and other researchers later identified shared code and technique overlap across all three intrusions, indicating Bangladesh Bank was the third — and by far most consequential — operation in an established campaign, not an isolated event (Symantec, 2016; CFR Cyber Operations Tracker).
Bangladesh Bank's own security posture compounded the risk. Investigators who examined the bank's network after the theft found it lacked a firewall segmenting the room housing its SWIFT terminals from the rest of the institution's IT environment, and that the network relied on secondhand, roughly $10 network switches rather than enterprise-grade hardware — for an institution with direct SWIFT access to global reserve accounts (Reuters, reported via multiple outlets, April 2016). SWIFT's own security model at the time placed nearly all responsibility for endpoint security on member institutions; the cooperative provided the messaging network and standard client software (Alliance Access) but did not mandate or audit the security controls surrounding it — a design assumption this incident exposed as insufficient for an increasingly targeted threat landscape.
evtdiag.exe and compiled on February 4, 2016, the same day the fraudulent transfers were issued (BAE Systems, 2016). The malware was purpose-built for this environment: it could intercept and suppress the physical printer confirmations Alliance Access normally generates for every transaction, and could delete or alter specific rows in the local SWIFT transaction database corresponding to the fraudulent transfers, preventing bank staff from seeing evidence of the requests in their own logs. This is a hallmark of the actor's tradecraft across all three related SWIFT heists: anti-forensic tooling engineered specifically against the target institution's own audit trail, not generic malware.| Type | Value / Description | Source | Date |
|---|---|---|---|
| FILE HASH | evtdiag.exe — specific SHA-256 not consistently published in open sources reviewed for this compile | BAE Systems | 2016-04 |
| INFRASTRUCTURE | Monitoring server reported located in Egypt, used to observe SWIFT terminal usage patterns at Bangladesh Bank prior to the theft | BAE Systems | 2016-04 |
| BENEFICIARY (fraud) | "Shalika Fandation" [sic] — Sri Lanka, misspelled beneficiary name that triggered the Deutsche Bank compliance query | OCCRP / CNBC | 2016-03 |
| RECIPIENT BRANCH | RCBC Jupiter Street branch, Makati City, Philippines | Multiple (Reuters, Rappler) | 2016 |
| NOTE | No further specific network IOCs (defanged IPs/domains for C2) were located in open-source reporting reviewed for this compile with sufficient corroboration to publish; BAE Systems' full indicator set was not fully republished in the secondary sources consulted. | ||
Attribution to North Korean state actors rests on convergent evidence from multiple independent sources: private-sector malware analysis (Symantec, BAE Systems) identifying code overlap between the Bangladesh Bank malware and tools used in the 2014 Sony Pictures attack and the WannaCry ransomware outbreak, both already attributed to North Korean operators; a formal U.S. Department of Justice criminal complaint (2018) charging a named North Korean individual, Park Jin Hyok, within a single conspiracy spanning all three incidents; and subsequent U.S. Treasury sanctions explicitly naming Lazarus Group, Bluenoroff, and Andariel as instruments of the North Korean government. MITRE ATT&CK further refines this picture by tracking the SWIFT-targeting, financially-motivated operations specifically under APT38/BeagleBoyz (G0082) — a narrower cluster within the broader Lazarus Group umbrella (G0032) distinguished by Mandiant/FireEye's research as specializing in bank theft rather than the destructive or espionage operations associated with other Lazarus sub-clusters. This layered, multi-source convergence is why this repository assesses attribution confidence as [HIGH] rather than [MEDIUM] — a rarer outcome for nation-state financial crime, where deniability is typically easier to maintain than in destructive or espionage operations that leave more forensic signature.
The Bangladesh Bank heist is the incident that moved "nation-state bank robbery" from a theoretical category into a documented, repeatable operational pattern. Before 2016, the working assumption among central banks and the SWIFT cooperative was that state-sponsored cyber capability was aimed at espionage, sabotage, or political signaling — not straightforward theft of hard currency at scale. The heist, combined with the preceding Ecuador and Vietnam operations, established that a state actor could and would treat direct financial theft as a legitimate instrument of statecraft, particularly under sanctions pressure, and that it could execute such theft using the same trusted-messaging infrastructure (SWIFT) that underpins the entire international banking system.
It is taught today primarily as a case study in distributed, cross-institutional failure rather than a single dramatic breach: no single control failure caused the loss, and no single control fix would have prevented it. Bangladesh Bank's absent network segmentation enabled the intrusion; SWIFT's endpoint-security assumptions enabled the fraudulent messages to look authentic; the Philippines' casino AML exemption enabled the laundering; and only a combination of unrelated, largely accidental external checks — a sanctions-screening name match and a compliance officer's eye for a spelling error — kept the loss from being roughly twelve times larger. This is precisely the analytical lesson the case is used to teach: resilience in interconnected financial systems has to be modeled across the entire chain of institutions a transaction touches, not just the originating one.
The incident's aftermath also reshaped SWIFT's own governance. The Customer Security Programme it produced remains, a decade later, the primary mechanism by which the cooperative enforces baseline security expectations across thousands of member institutions worldwide — arguably making this the most consequential single incident in SWIFT's operating history. And the actor's continued evolution — Bureau 121's financially-motivated cluster went on to pursue cryptocurrency exchanges with the same playbook throughout the following decade — demonstrates that the underlying incentive structure this case exposed (a sanctioned state needing hard currency, and finding cyber theft cheaper and lower-risk than the alternatives) has not gone away.