Investigators tied the attempted theft of nearly $1 billion from Bangladesh Bank to hackers linked to North Korea, strengthening suspicions that the operation was part of a broader campaign against financial institutions using the SWIFT payment network. In the Bangladesh case, fraudulent transfer messages were sent through the bank’s compromised systems; most were blocked, but about $81 million reached accounts in the Philippines and was later laundered through casinos. The fraud was reportedly uncovered after a printer malfunction disrupted routine transaction records, helping expose the unauthorized transfers.
The inquiry widened to as many as 12 additional banks, with security firms reporting contacts from institutions in countries including New Zealand and the Philippines that feared similar compromises. Researchers from BAE Systems, Symantec, FireEye, and later Kaspersky said malware and operational overlaps connected the bank theft activity to the same cluster associated with attacks on U.S. and South Korean targets and the Sony Pictures breach, which U.S. authorities had attributed to North Korea. The case raised concern that once a bank connected to SWIFT is breached, fraudulent messages can appear legitimate to other institutions, undermining trust in the global payments system.

See the actors and campaigns active against you right now.
7 events from the most recent confirmed update back to the earliest known activity.
Kaspersky Lab said it had found a direct connection between the hackers behind the banking theft campaign and North Korea. The finding represented a further attribution development tying the SWIFT-related bank attacks to North Korean operators.
The New York Times reported that investigators had linked digital theft attempts against global banks to North Korea. The report marked a broader public framing of the Bangladesh Bank incident as part of a wider North Korean campaign targeting financial institutions.
Security researchers said malware and tactics in the Bangladesh Bank case resembled those used by the group behind attacks on U.S. and South Korean targets since 2009 and the 2014 Sony Pictures breach. This strengthened early technical attribution connecting the bank heists to the Lazarus threat cluster.
By May 2016, investigators were examining possible compromises at up to 12 more banks connected to the SWIFT network, including institutions in New Zealand and the Philippines. FireEye said multiple banks had contacted it, while SWIFT warned some reports might be false positives and urged banks to inspect their systems.
Reporting said RCBC branch manager Maia Santos Deguito approved withdrawals totaling $81 million even after Bangladesh Bank asked for the transfers to be stopped. Her lawyer said she acted under instructions from higher-level officials, suggesting broader involvement.
Bangladesh Bank discovered the unauthorized transfers after a printer error disrupted normal printing of transaction records, helping alert staff to the fraud. The discovery triggered urgent efforts to stop the transfers, though tens of millions had already been sent.
Fraudulent SWIFT transfer orders were sent from Bangladesh Bank to the Federal Reserve Bank of New York in an attempt to steal nearly $1 billion. Most transfers were blocked, but about $81 million was successfully routed to the Philippines and later laundered through casinos.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
4 references tracked. Mallory keeps watching after this page renders.
bbc.com
Open sourcenytimes.com
Open sourcearstechnica.com
Open sourcesmh.com.au
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.