On the evening of Thursday, February 4, 2016, operators at the Federal Reserve Bank of New York began receiving payment instructions from the Bangladesh Bank. The instructions requested the transfer of nearly $1 billion from Bangladesh's account at the Fed to accounts in the Philippines, Sri Lanka, and other locations. By the time the fraud was discovered the following Tuesday, $81 million had been transferred to the Rizal Commercial Banking Corporation in Manila - and had disappeared into the Philippines casino industry, where cash transactions are largely outside anti-money-laundering frameworks. It was the largest cyber heist in history.

How the SWIFT Network Works

SWIFT - the Society for Worldwide Interbank Financial Telecommunication - is the messaging network that banks use to communicate international transfer instructions. When a bank wants to move money internationally, it sends a SWIFT message to the receiving bank or to a correspondent bank. The messages use standardized formats and are authenticated using credentials and encryption keys held by each member institution.

SWIFT itself does not move money - it moves instructions. The actual movement happens through correspondent banking relationships and central bank accounts. Bangladesh Bank maintained an account at the Federal Reserve Bank of New York, where it kept its foreign currency reserves. SWIFT messages from Bangladesh Bank's terminals in Dhaka instructed the New York Fed to transfer funds from that account.

[TECHNICAL NOTE]
The Bangladesh Bank SWIFT terminals ran on a local network connected to Bangladesh Bank's internal systems. The attackers had gained access to this network months before the heist - reconnaissance indicated access from at least late 2015. They studied the SWIFT terminal software, the message formats Bangladesh Bank used, and the authentication procedures. They also installed malware that could read and delete SWIFT transaction logs and manipulate the printer that Bangladesh Bank used to print confirmation of outgoing transactions - ensuring operators would not see the fraudulent messages.

The Attack Sequence

The attackers chose their timing carefully. They submitted the fraudulent transfer requests on Thursday evening New York time - which was Friday morning in Dhaka. Bangladesh Bank would be closed for the weekend (Friday-Saturday in Bangladesh). The New York Fed processes transactions during US business hours. The instructions would execute Friday, and Bangladesh Bank would not see them until Sunday at the earliest - and would not be able to act until Monday in the US.

The attackers submitted 35 transfer requests totaling $951 million. The New York Fed processed five of them totaling $101 million before flags were raised. One $20 million transfer to Sri Lanka was flagged by Deutsche Bank (acting as correspondent) because the recipient was "Shalika Foundation" and the routing instructions included the word "fandation" - a spelling error that triggered a manual review. That transfer was reversed.

The other four transfers - totaling $81 million - went to four accounts at RCBC in Manila, specifically at the Jupiter Street branch in Makati. The branch manager, Maia Deguito, had opened the accounts for an entity with fabricated documentation the previous year. The accounts had been dormant since opening, waiting. On February 5, 2016, the $81 million arrived and was almost immediately withdrawn in cash and converted into casino chips at two Manila casinos.

The Recovery Failure

When Bangladesh Bank discovered the fraud on Monday, February 8, they attempted to contact the New York Fed and RCBC to halt or reverse the transfers. The New York Fed had already processed the instructions. RCBC's Manila headquarters was initially unable to reach the Jupiter Street branch because of Lunar New Year - the branch was closed. By the time contact was established, the cash was gone.

$81 million moved through Manila casinos to Chinese nationals who had flown in specifically to collect the funds. A Filipino-Chinese casino junket operator named Kim Wong later came forward claiming he had received $21 million through a Chinese businessmen named Xu Wei and Ding Zhize. The money was broken into chips, played briefly to establish legitimacy, then cashed out. The Philippine casino industry's anti-money-laundering exemption - enacted in 2001 when the Philippines gambling industry lobbied against inclusion in AML law - meant no reporting requirements applied.

[WARNING]
The Philippines subsequently amended its AML law to include casinos. This was one direct legislative consequence of the Bangladesh Bank heist. The Jupiter Street branch manager Maia Deguito was eventually convicted of eight counts of money laundering in 2019 and sentenced to 32 to 56 years imprisonment. She was the only person convicted in the Philippines. The bulk of the $81 million was never recovered.

Lazarus Group Attribution

Attribution for the Bangladesh Bank heist was contested but ultimately pointed to North Korea's Lazarus Group. BAE Systems published a technical analysis in April 2016 identifying custom malware on the Bangladesh Bank systems - specifically a tool called evtdiag.exe for manipulating Windows event logs and a SWIFT terminal-specific component they named msoutc.exe. The code shared characteristics with malware previously attributed to Lazarus.

In 2018, the US Department of Justice indicted Park Jin Hyok - the same North Korean operator indicted for the Sony Pictures hack - for participation in the Bangladesh Bank heist. The FBI's technical analysis identified shared infrastructure, coding artifacts, and malware components across the Sony hack, the Bangladesh Bank heist, and the WannaCry ransomware campaign. All three were attributed to the same North Korean threat actor.

The connection made sense strategically. North Korea's Lazarus Group had been developing financial theft capabilities since at least 2013 with attacks on South Korean banks. After the Sony Pictures operation attracted enormous attention and sanctions, the group pivoted further toward financial operations - generating hard currency for the regime under sanctions. The Bangladesh Bank heist was followed by similar SWIFT-targeting attacks on banks in Vietnam, Ecuador, Taiwan, and other countries. The total attributed to Lazarus Group's banking operations over several years reached into the hundreds of millions of dollars.

Bangladesh Bank's Security Failures

Post-breach investigation revealed that Bangladesh Bank's SWIFT terminal infrastructure had significant security gaps. The terminals were connected to the wider internal network rather than isolated. The bank used second-hand, uncertified network switches purchased for approximately $10 each. There was no firewall between the SWIFT terminals and the rest of the network. Physical security for the terminal room was minimal.

SWIFT itself faced criticism for not having stronger security requirements for member institutions. SWIFT's messaging authentication relied on the security of member institutions' terminal environments - if an attacker could access a bank's terminal and use its credentials, SWIFT had no mechanism to distinguish legitimate from fraudulent messages. After the Bangladesh Bank heist and subsequent attacks, SWIFT introduced a Customer Security Programme (CSP) with mandatory security requirements for member institutions and anomaly detection for unusual transaction patterns.

The heist also revealed a systemic vulnerability: the global financial messaging system that processes trillions of dollars in transfers daily relied on the security of its weakest member. A central bank in a developing country with a $10 network switch and no firewall between its payment infrastructure and general IT systems had the same SWIFT credentials and message authority as the largest banks in the world. The Bangladesh Bank heist forced a reckoning with what "trusted" meant in a network where trust was not conditional on verified security standards.