Inside the Bangladesh Bank Heist How Hackers Stole 81 Million Through SWIFT
On a quiet February weekend in 2016, a printer at Bangladesh Bank stopped working. That small failure should have been routine. Instead, it helped hide one of the most audacious bank robberies ever attempted.
The thieves did not enter a vault. They did not threaten a cashier. They sat behind keyboards, deep inside a central bank’s computer network, and sent payment orders in the bank’s own name.
Their target was Bangladesh Bank’s account at the Federal Reserve Bank of New York. Their weapon was access to the global SWIFT messaging system, the trusted network banks use to tell each other where money should move.
By the time the plot began to unravel, hackers had tried to steal close to US$1 billion. Most of it was stopped by chance, timing, and suspicion. But US$81 million escaped into the Philippine financial system, where much of it vanished through casinos and junket rooms.
The Bangladesh bank heist became a landmark case in modern financial crime. It showed that the greatest weakness in global banking may not be the code inside the networks, but the trust between the institutions that use them.

The intrusion began long before the money moved
The heist did not start on the night the transfer requests were sent. It began weeks, and likely months, earlier.
Investigators later found evidence that attackers had quietly entered Bangladesh Bank’s network and studied its systems. They were not smash-and-grab criminals. They behaved like patient operators. They watched. They mapped the environment. They learned how staff used the SWIFT terminal and how payment instructions were created.
SWIFT itself did not move money. That point matters. SWIFT is a secure messaging system that banks use to send instructions. If Bank A tells Bank B to transfer funds, SWIFT carries the message. The actual money moves through correspondent banking accounts, central bank accounts, and settlement systems.
In this case, Bangladesh Bank held reserves at the Federal Reserve Bank of New York. The attackers wanted the New York Fed to believe that Bangladesh Bank had authorised large withdrawals.
To do that, they needed valid credentials. They also needed to hide signs of fraud from bank staff in Dhaka. Malware found in the bank’s environment appeared designed to interfere with local records and suppress printed confirmations from the SWIFT system. That broken printer was not just bad luck. It was part of the fog.
Reports after the attack also pointed to weak local security. Bangladesh Bank’s SWIFT environment was said to have been connected to the wider network with poor separation. Simple hardware and weak controls made a high-value target easier to compromise. The attackers did not need to break the whole global banking system. They needed to compromise one trusted participant.
That distinction is central to the case.
A security chain is only as strong as the endpoint that signs the instruction. Once the attackers had the right access, the messages they sent looked, at first glance, like legitimate payment orders from a central bank.
The thieves chose the perfect weekend
The timing was precise.
The fraudulent payment instructions were sent in early February 2016, around the Lunar New Year period in parts of Asia and just before the weekend in Bangladesh. This created a narrow window where offices, correspondent banks, and compliance teams were not perfectly aligned.
The hackers sent dozens of requests through SWIFT to the Federal Reserve Bank of New York. The total value was close to US$1 billion. The instructions asked the Fed to move Bangladesh Bank funds to accounts in the Philippines and Sri Lanka.
To the system, these were not dramatic events. They were messages. Structured fields. Names. Account numbers. Beneficiary banks. Amounts. The machinery of international finance depends on such messages being processed quickly and reliably.
That reliability is what the attackers abused.
Several transfer requests made it through. Others began to raise alarms. Some were unusually large. Some recipients did not match expected patterns. The New York Fed and intermediary banks sought clarification.
Then came the mistake that has become infamous.
One fraudulent instruction sent money to a Sri Lankan entity whose name was meant to appear as “foundation”. The attackers misspelled it as “fandation”. That small error made a routing bank pause and ask questions. The payment, worth about US$20 million, was stopped and later recovered.
It is tempting to treat the typo as comic relief, but it was more than that. It shows how thin the line can be between a billion-dollar theft and a failed instruction. A single misspelt word did what layers of technology did not immediately do. It broke the spell of legitimacy.
Other requests were blocked or delayed for separate reasons, including sanctions-related screening triggers and manual review. In the end, most of the attempted theft did not succeed.
But the attackers did not need everything to work.
They needed enough.

The money landed in Manila and began to disappear
The transfers that succeeded sent US$81 million to accounts at a branch of Rizal Commercial Banking Corporation, known as RCBC, in the Philippines.
The accounts had been opened months earlier under names later described as false or suspicious. When the money arrived, it moved quickly. It was converted, withdrawn, and passed through channels that made tracing harder.
A large portion flowed into the Philippine casino sector.
At the time, casinos in the Philippines were not covered by the same anti-money laundering rules as banks. That gap mattered. Casino cash desks, gambling chips, junket operators, and high-roller rooms can create a blur of transactions. Money can enter as bank funds, turn into chips, move between players or junket operators, and leave in different forms.
The funds did not vanish all at once. They dissolved into a system built for speed, discretion, and large cash movement.
Some money was later recovered, including funds linked to individuals who cooperated with authorities. But much of the US$81 million was never fully returned.
The Philippines held public inquiries. Bank employees, casino figures, remittance operators, and regulators came under scrutiny. Bangladesh Bank pushed for recovery. RCBC was fined by Philippine regulators. Laws were later changed to bring casinos within the country’s anti-money laundering regime.
Still, the case exposed the uncomfortable truth of a multi million banking theft: once stolen funds cross borders and enter lightly regulated channels, recovery becomes painfully difficult.
The theft was digital at the start, but the laundering was physical. It moved through branches, cash rooms, casino cages, and gambling tables. That mix of cyber intrusion and old-fashioned money laundering made the crime so hard to unwind.

The heist worked because global banking runs on trust
The SWIFT system connects thousands of financial institutions across the world. It is central to cross-border finance because it gives banks a common language for payment messages.
That scale is a strength. It is also a weakness.
A receiving bank cannot manually investigate every message as if it were a crime scene. Global finance depends on speed. A bank in New York must be able to trust that a message from a central bank in Dhaka was generated by authorised users inside that institution.
The Bangladesh Bank case showed what happens when that trust is misplaced.
The attackers did not hack the New York Fed’s core systems. They did not break SWIFT encryption in some cinematic masterstroke. They compromised an endpoint and used real credentials to issue fraudulent instructions. The system then treated those instructions with the seriousness normally given to central bank orders.
That is the structural problem behind many global financial crime stories. The network can be secure in design, yet exposed through local weaknesses, human habits, and uneven regulation.
Several vulnerabilities came together:
Weak endpoint security
The attackers gained access inside Bangladesh Bank’s environment and operated close to systems used for international payments.
Poor network separation
Sensitive payment systems appeared too exposed to the wider internal network.
Limited real-time detection
The fraudulent activity was not stopped at the moment of instruction.
Operational timing
Weekends and holidays slowed communication between institutions in different countries.
Gaps in laundering controls
Casino flows in the Philippines helped the stolen money move out of reach.
This is where terms such as SWIFT network security, central bank cyber attack, financial system vulnerability, fed wire transfers fraud, and global banking risk stop being abstract. In this case, they described one connected failure chain.
The crime did not succeed because one control failed. It succeeded because several controls failed in sequence, across several countries.
The lesson for banks was not simply “protect SWIFT”. The lesson was broader: protect every machine, person, process, and institution that can create a trusted payment instruction.
The spelling mistake was luck, not a defence
The most memorable detail of the heist is the typo. “Fandation” stopped a transfer. It is a detail made for headlines.
But no serious bank can rely on misspellings to catch fraud.
The typo mattered because it triggered human doubt. Someone looked closely enough to ask why a payment instruction did not seem right. That moment of friction saved millions. Yet a system that depends on lucky friction is fragile.
A stronger defence would have raised concern earlier, based on behaviour and context:
Why were so many high-value transfers being requested in a short period?
Why were funds going to unfamiliar private accounts?
Why did the payment pattern differ from normal central bank activity?
Why did local confirmation tools stop working?
Why was a sensitive payment environment reachable by attackers?
Modern fraud detection must combine technical controls with operational judgement. Firewalls, multi-factor authentication, access controls, and network monitoring matter. So do escalation procedures, call-back checks, payment limits, and staff who feel able to halt a suspicious transaction.
Central banks and commercial banks have since paid closer attention to endpoint security around SWIFT systems. SWIFT also introduced customer security controls after the heist, pushing member institutions to harden local environments and report compliance against security standards.
That response was necessary. Yet the bigger issue remains: a global routing network links institutions with very different budgets, regulations, cultures, and technical maturity. An attacker does not need to defeat the strongest participant. They can look for the weakest trusted one.

What the heist still teaches global banking
The 2016 Bangladesh Bank theft remains one of the clearest warnings in financial cybersecurity.
It shows that cybercrime is not separate from banking operations. The attackers understood both. They knew how payment messages worked, how correspondent accounts functioned, how holidays could delay response, and how money laundering channels could absorb stolen funds.
The case also shows why security cannot stop at the perimeter. Banks often focus on keeping attackers out. That still matters, but defenders must also assume that attackers may get in. Once inside, the question becomes whether they can move freely, steal credentials, manipulate records, and send trusted instructions without challenge.
Good security in global banking now requires several layers:
Strong authentication for all payment systems
Strict separation between SWIFT environments and general networks
Continuous monitoring for unusual payment behaviour
Independent confirmation for large or unusual transfers
Fast cross-border escalation between banks and regulators
Anti-money laundering rules that cover casinos, remittance firms, and other non-bank channels
The deeper lesson is structural. The global financial system is built on standard messages, correspondent relationships, and institutional trust. That design allows money to move across borders at enormous speed. It also means a false instruction, if it looks authentic enough, can travel farther than anyone expects before doubt catches up.
The Bangladesh Bank heist was not just a story about hackers stealing US$81 million. It was a rehearsal for the kind of crime modern finance makes possible: patient, technical, international, and aimed at the seams between institutions.
The world’s banks do not only need stronger locks. They need better ways to recognise when a trusted key is being used by the wrong hand.








Comments