First reportedFebruary 8, 2016
ActivityFebruary 5, 2016
Last updatedFeb 2, 2026, 12:00 AM UTC
Record confidencemed

Key facts

Affected

  • Bangladesh Bank (central bank of Bangladesh)
  • Federal Reserve Bank of New York
  • Correspondent banks and intermediaries involved in fraudulent transfers

Initial access

  • stolen_creds
  • unknown

Impact

  • financial_loss
  • fraud

Attribution

North Korea-linked actor (charged in U.S. case) med confidence

DOJ filings and public statements tie a DPRK-linked programmer to a campaign that included the Bangladesh Bank heist.

CVEs and ATT&CK

CVEs

ATT&CK techniques

  • T1078: The heist relied on unauthorized use of legitimate banking messaging workflows and credentials within the victim environment to issue fraudulent SWIFT messages.

Mitigations

Now

  • Enforce SWIFT Customer Security Controls Framework (CSCF) and isolate SWIFT infrastructureReduces compromise risk by hardening SWIFT endpoints and separating them from less trusted networks.

Soon

  • Require multi-person approval and out-of-band verification for high-risk transfersPrevents single compromised operator credentials from authorizing large fraudulent transactions.

Later

  • Continuously monitor printers/logging, and implement tamper-resistant transaction monitoringDetects suppression or manipulation of alerting mechanisms and enables rapid identification of anomalous transfer attempts.

Detection ideas

Detect anomalous SWIFT message patterns and beneficiary anomalies

Alert on unusual beneficiary banks/countries, atypical amounts, new beneficiary accounts, or abnormal burst patterns outside business hours.

Data sources: SWIFT message logs, Payment processing logs, Case management records

Monitor for malware or tool activity on SWIFT operator workstations

Alert on unauthorized executables, service installs, or attempts to disable printing/logging components on SWIFT endpoints.

Data sources: EDR telemetry, Windows Security Event Logs

Sources