Hackers penetrated Bangladesh Bank’s systems and used stolen payment credentials to send fraudulent transfer requests from the bank’s account at the Federal Reserve Bank of New York, attempting to steal nearly $1 billion. Most of the transfers were halted after a misspelled instruction tied to a $20 million payment to a Sri Lankan entity drew scrutiny, along with concerns over the unusual volume and nature of the requests. Even so, about $81 million was successfully transferred to the Philippines, prompting investigations by Bangladesh Bank, Philippine authorities, and incident responders including FireEye Mandiant.
The theft exposed weaknesses in cross-border banking controls and intensified a dispute over responsibility for the losses. Bangladesh criticized the New York Fed’s handling of the transfer requests, while suspicions grew that stolen funds were funneled through Philippine casinos. The fallout later expanded into litigation, with Philippine bank RCBC suing Bangladesh’s central bank over what it described as damaging allegations tied to the cyber heist.

See the actors and campaigns active against you right now.
6 events from the most recent confirmed update back to the earliest known activity.
In March 2019, Philippine bank RCBC filed a lawsuit against Bangladesh's central bank over what it described as 'vicious' claims tied to the 2016 cyber heist. The suit marked a legal escalation in the dispute over responsibility and handling of the stolen funds.
Following discovery of the fraudulent transfers in February 2016, Bangladesh Bank, Philippine authorities, and incident responders including FireEye Mandiant began investigating the heist and attempting to recover the stolen money. The incident drew attention to weaknesses in international banking controls and prompted criticism of the New York Fed.
During processing of the transfer requests in early February 2016, a misspelling in a $20 million instruction to a Sri Lankan entity and concerns about the unusual volume and nature of the transactions triggered additional scrutiny. As a result, most of the attempted transfers were blocked before completion.
Despite the failed larger theft attempt, roughly $81 million was successfully moved from Bangladesh Bank to accounts in the Philippines. The stolen funds were later suspected of being funneled onward through Philippine casinos.
In early February 2016, attackers compromised Bangladesh Bank's systems and used stolen payment credentials to submit fraudulent transfer requests from the bank's account at the Federal Reserve Bank of New York. The requests sought to move nearly $1 billion to accounts in Sri Lanka and the Philippines.
Hackers reportedly compromised Bangladesh Bank's internal systems and planted malicious software in January 2016, before launching the fraudulent SWIFT transfer requests the following month. This earlier foothold suggests advance preparation for the February bank heist.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
6 references tracked. Mallory keeps watching after this page renders.
nytimes.com
Open sourceinsurancejournal.com
Open sourcenytimes.com
Open sourcenytimes.com
Open sourceindependent.co.uk
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.