What Was the Bangladesh Bank Heist? Stopped by a Typo and a Street Name
They asked for nearly a billion dollars. A spelling mistake stopped most of it.
Over the weekend of 4 to 5 February 2016, someone sent 35 payment instructions over the SWIFT network from Bangladesh Bank's account at the Federal Reserve Bank of New York, asking to move close to $951 million. The timing was chosen with care: it was a Thursday night in Dhaka heading into the Bangladeshi weekend, and it ran into a public holiday in the Philippines, where the money was going. For three days almost nobody who could stop it was at work.
What was the Bangladesh Bank heist?
A theft carried out not by breaking SWIFT, the international system banks use to instruct each other to move money, but by getting inside one member and sending genuine, correctly authenticated messages through it. The attackers had been in Bangladesh Bank's network for weeks. When they sent the payment orders, SWIFT did exactly what it is built to do: it carried valid instructions from a trusted member.
The printer was made to go blind
Bangladesh Bank kept a paper record of every SWIFT transaction on a physical printer that ran continuously, so staff could see confirmations as they arrived. The attackers planted malware that tampered with that print process. The fraudulent confirmations did not print. Over the weekend, the one mechanism that would have shown a human being that a billion dollars was walking out the door simply produced nothing, and produced it quietly.
By the time the printer was working again and someone read the backlog, the money had moved.
Where it went
Five of the 35 orders cleared before the rest were caught, moving about $101 million. $81 million went to four accounts at a branch of Rizal Commercial Banking Corporation on Jupiter Street in Manila, and from there into casinos, where cash becomes very hard to trace. Another $20 million was routed to Sri Lanka.
Fandation
The Sri Lanka transfer was stopped for the least sophisticated reason imaginable. The attackers had misspelled the name of the payee, a body called the Shalika Foundation, writing it as Fandation. A bank in the chain queried the spelling, the transfer was held, and the $20 million was saved by a typo.
The larger transfers drew scrutiny for a reason almost as strange. The RCBC branch sat on Jupiter Street, and the word Jupiter matched the name of a sanctioned Iranian oil tanker on a financial-screening list. That coincidence tripped a manual review at the Fed and held up the remaining orders long enough for the alarm to be raised. A planet's name on a street sign did more than the bank's own controls.
Who did it
The FBI and multiple security firms attributed the operation to the Lazarus Group, the North Korean state hacking outfit later tied to the 2014 Sony Pictures attack and the 2017 WannaCry ransomware. A North Korean programmer, Park Jin Hyok, was named in a US criminal complaint. Most of the $81 million that reached Manila has never been recovered; the $20 million routed to Sri Lanka was.
A billion-dollar theft, engineered to the minute, undone by a typo and a street named after a planet.
Further reading
- US Department of Justice — criminal complaint, United States v. Park Jin Hyok, 2018.
- SWIFT — Customer Security Programme documentation issued in response to the 2016 attacks.
- BAE Systems Threat Research — analysis of the Bangladesh Bank malware and its links to the Lazarus Group, 2016.
- Report of the Philippine Senate Blue Ribbon Committee on the RCBC transfers, 2016.
EXHIBIT 0032 — BANGLADESH BANK
We put it on a shirt. An old dot-matrix line printer, drawn as an engraving, a torn continuous-feed page hanging from the platen. The one legible line on the printout: FANDATION.
Callouts: 35 ORDERS, 951 MILLION DOLLARS. THE PRINTER WAS MADE TO GO BLIND. STOPPED BY A MISSPELLING: FANDATION. AND A STREET NAMED JUPITER.
Stopped by a typo and a street name.
That's the whole idea.