Bangladesh Bank SWIFT fraud attempt resulting in $81 million theft
Attackers compromised systems at the central bank of Bangladesh and used the SWIFT financial messaging system to send fraudulent transfer requests from the bank’s account at the Federal Reserve Bank of New York. The operation resulted in approximately $81 million being transferred and laundered, with additional transfers blocked. U.S. authorities later charged a North Korean regime-linked programmer for a campaign that included the Bangladesh Bank heist, tying the theft to broader state-backed illicit cyber activity.
First reported February 8, 2016Fraudmed overall confidence
T1078: The heist relied on unauthorized use of legitimate banking messaging workflows and credentials within the victim environment to issue fraudulent SWIFT messages.
Mitigations
Now
Enforce SWIFT Customer Security Controls Framework (CSCF) and isolate SWIFT infrastructureReduces compromise risk by hardening SWIFT endpoints and separating them from less trusted networks.
Soon
Require multi-person approval and out-of-band verification for high-risk transfersPrevents single compromised operator credentials from authorizing large fraudulent transactions.
Later
Continuously monitor printers/logging, and implement tamper-resistant transaction monitoringDetects suppression or manipulation of alerting mechanisms and enables rapid identification of anomalous transfer attempts.
Detection ideas
Detect anomalous SWIFT message patterns and beneficiary anomalies
Alert on unusual beneficiary banks/countries, atypical amounts, new beneficiary accounts, or abnormal burst patterns outside business hours.
Data sources: SWIFT message logs, Payment processing logs, Case management records
Monitor for malware or tool activity on SWIFT operator workstations
Alert on unauthorized executables, service installs, or attempts to disable printing/logging components on SWIFT endpoints.
Data sources: EDR telemetry, Windows Security Event Logs