How Did the Bangladesh Bank Cyber Heist Work?

450 views
•
November 1, 2016
by
RSAC Cybersecurity
YouTube video player
How Did the Bangladesh Bank Cyber Heist Work?

TL;DR

The Bangladesh Bank heist succeeded through coordinated preparation, a targeted intrusion, fraudulent SWIFT transactions, and rapid money laundering through criminal networks. Most attempted transfers were stopped, but funds sent to accounts in the Philippines were quickly withdrawn and laundered, showing how cybercrime and financial crime can combine against a critical banking function.

Transcript

Hello. Hey, um, my name is Bilan Tekcezoz. I am the global cyber secure strategist at BAE System. And today, we'll have a preview of the, uh, of a true story of a cyber takedown, and we will talk about the biggest cyber heist in history. But I also want to talk about a little bit on the financial crime and the cyber crime convergence that we see in... Read More

Key Insights

  • The Bangladesh Bank attack was a coordinated financial operation, not merely a technical intrusion. The presentation indicates that it probably involved specialists in software exploitation, banking systems, targeted access, criminal networks, and money laundering, with different participants performing distinct roles.
  • The setup phase began with bogus bank accounts in Sri Lanka and the Philippines. Those accounts were created during 2015 and left available for more than a year, demonstrating that the attackers prepared financial infrastructure long before initiating the fraudulent transfers.
  • The intrusion may have begun through social engineering, although the presentation identifies this as speculation rather than a confirmed fact. What mattered most was gaining sufficient access to manipulate the banking environment and generate transaction instructions that appeared capable of passing through established systems.
  • The attack timing exploited differences in working days and major events. Peculiar transaction alerts appeared on Thursday, activity continued across the following days, and Chinese New Year coincided with unusually large amounts of casino cash, which probably assisted the laundering process.
  • The US Federal Reserve stopped most of the attempted fraudulent transactions. Of thirty-five transactions discussed in the presentation, thirty were blocked, limiting an attempted theft that approached one billion dollars and showing that intermediary controls prevented most of the intended transfers.
  • A typographical error helped stop a twenty-million-dollar transfer to Sri Lanka. A clerk at the receiving bank noticed the mistake, raised a warning, and prevented the payment, illustrating how attentive human review can interrupt a sophisticated operation when technical controls do not act first.
  • The successful Philippine transfers totaled eighty-one million dollars. The money was withdrawn from the banks and laundered within a very short period through a complex web of criminal networks, making recovery and intervention much more difficult after the payments had cleared.
  • The convergence of cybersecurity and financial crime is the central risk highlighted by the case. Digital access enabled the fraudulent instructions, while banking knowledge, prepared accounts, withdrawal channels, casinos, and laundering networks turned the technical compromise into a completed financial theft.

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How did the Bangladesh Bank cyber heist work?

The operation followed several connected stages. Criminals first established bogus bank accounts in Sri Lanka and the Philippines and left them available for later use. They then gained access to the banking environment, possibly through social engineering, and issued fraudulent SWIFT transactions. Most transfers were stopped, but funds reaching the Philippines were quickly withdrawn and laundered through criminal networks.

Q: Why was timing important in the Bangladesh Bank attack?

Timing helped the attackers exploit periods when organizations and financial systems operated on different schedules. Unusual alerts appeared on a Thursday, while transaction activity continued across the following days. The period also coincided with Chinese New Year, when casinos held especially large amounts of cash. The presentation suggests that this condition probably helped criminals launder the transferred funds.

Q: How much money reached the Philippines in the cyber heist?

Four successful transfers sent a total of eighty-one million dollars to a bank in the Philippines. According to the presentation, the money was withdrawn from the banks and laundered extremely quickly through a complex web of criminal networks. This rapid movement demonstrates why stopping suspicious transfers before settlement is critical, because intervention becomes harder once funds enter laundering channels.

Q: Why was the transfer to Sri Lanka stopped?

The transfer to Sri Lanka was stopped because a clerk at the receiving bank noticed a typographical error in the payment order and raised a warning. The transaction was worth twenty million dollars. The incident shows that careful human review can provide an important defensive layer, even when attackers have already penetrated systems and produced otherwise convincing fraudulent instructions.

Q: What roles were likely involved in the Bangladesh Bank heist?

The presentation suggests that the operation required multiple teams or specialists. Likely roles included people capable of conducting the intrusion, developers able to build tools tailored to the target environment, individuals familiar with banking processes and software vulnerabilities, and criminals experienced in withdrawing and laundering funds. Their coordination connected the cyberattack directly to a broader financial crime network.

Q: Did the US Federal Reserve stop the fraudulent transfers?

The US Federal Reserve stopped thirty of the thirty-five transactions described in the presentation. Five initially passed through, although the Sri Lankan payment was later halted after a clerk identified a typo. The remaining four transfers reached the Philippines. These outcomes show that transaction screening blocked most attempts, but a smaller number of successful payments still produced a major loss.

Q: How did software manipulation enable the cyber heist?

The presentation contrasts breaking into a physical bank vault with altering software code. It states that changing only two bytes, affecting eight bits, could modify an algorithm and allow bogus transactions to pass. Although the code change sounds small, carrying it out required substantial preparation, specialized expertise, access to the environment, and knowledge of the software and banking operation.

Q: Why does the case show a convergence of cybercrime and financial crime?

The case combined a digital compromise with traditional mechanisms for moving and disguising stolen money. Cyber specialists allegedly gained access and manipulated transaction processes, while prepared bank accounts received the funds. Other participants then withdrew and laundered the money through criminal networks, with casinos probably assisting. Neither the technical intrusion nor the financial network alone would have completed the operation.

Summary & Key Takeaways

  • The operation began well before the fraudulent transfers, with bogus bank accounts established in Sri Lanka and the Philippines and then left unused for more than a year. The attackers likely required separate specialists for intrusion, custom software tools, banking processes, criminal networks, and laundering the stolen funds.

  • The attackers initiated fraudulent transactions through the SWIFT network during a carefully selected period involving weekends and Chinese New Year. Bank officials noticed unusual transaction alerts, while the timing complicated intervention and placed substantial cash in casinos, which the presentation suggests probably helped the subsequent laundering process.

  • Most fraudulent transactions were stopped by the US Federal Reserve. A Sri Lankan transfer was also blocked after a bank clerk noticed a typographical error in the payment order. However, four transfers reached the Philippines, where the funds were rapidly withdrawn and laundered through a complex network of criminal participants.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚