How a Hacker's Typo Helped Stop a Billion Dollar Bank Heist

Advertisement
By Reuters | Updated: 10 March 2016 14:40 IST

A spelling mistake in an online bank transfer instruction helped prevent a nearly $1 billion (roughly Rs. 6,707 crores) heist last month involving the Bangladesh central bank and the New York Fed, banking officials said.

Unknown hackers still managed to get away with about $80 million (roughly Rs. 536 crores), one of the largest known bank thefts in history.

Advertisement

The hackers breached Bangladesh Bank's systems last month and stole its credentials for payment transfers, two senior Bangladesh Bank officials said.

They then bombarded the Federal Reserve Bank of New York with nearly three dozen requests to move money from the Bangladesh bank's account there to entities in the Philippines and Sri Lanka, the officials said.

Advertisement

Four requests to transfer a total of about $81 million (roughly Rs. 543 crores) to the Philippines went through, but a fifth, for $20 million (roughly Rs. 134 crores), to a Sri Lankan non-profit organisation got held up because the hackers misspelled the name of the NGO.

The full name of the non-profit could not be learned. But one of the officials said the hackers misspelled "foundation" in the NGO's name as "fandation", prompting a routing bank, Deutsche Bank, to seek clarification from the Bangladesh central bank, which stopped the transaction.

Advertisement

Deutsche Bank declined to comment.

At the same time the unusually high number of payment instructions and the transfer requests to private entities - as opposed to other banks - made the Fed suspicious, which also alerted the Bangladeshis, the officials said.

Advertisement

The details of how the hacking came to light and was stopped before it did more damage have not been previously reported. Bangladesh Bank has billions of dollars in a current account with the Fed, which it uses for international settlements.

The transactions that got stopped totalled between $850 million (roughly Rs. 5,700 crores) and $870 million (roughly Rs. 5,834 crores), one of the officials said.

Last year, Russian computer security company Kaspersky Lab said a multinational gang of cyber criminals had stolen as much as $1 billion from as many as 100 financial institutions around the world in about two years.

Iraqi dictator Saddam Hussein's son Qusay took $1 billion from Iraq's central bank on the orders of his father on the day before coalition forces began bombing the country in 2003, American and Iraqi officials have said. In 2007, guards at the Dar Es Salaam bank in Baghdad made off with $282 million (roughly Rs. 1,891 crores).

Money recovered
Bangladesh Bank has said it has recovered part of the money that was stolen, and is working with anti-money laundering authorities in the Philippines to try to recover the rest of the funds.

The recovered funds refer to the Sri Lanka transfer, which got stopped, one of the officials said.

The dizzying, global reach of the heist underscores the growing threat of cyber crime and how hackers can find weak links in even the most secure computer networks to steal money and wreak havoc.

More than a month after the attack, Bangladeshi officials are scrambling to trace the money, shore up security and identify weaknesses in their systems. They said there is little hope of ever catching the hackers, and it could take months before the money is recovered, if at all.

Security experts said the perpetrators had deep knowledge of the Bangladeshi institution's internal workings, likely gained by spying on bank workers.

The Bangladesh government, meanwhile, is blaming the Fed for not stopping the transactions earlier.

Finance Minister Abul Maal Abdul Muhith told reporters on Tuesday that the country may resort to suing the Fed to recover the money.

"The Fed must take responsibility," the minister said.

The New York Fed has said that its systems were not breached and that it has been working with the Bangladesh central bank since the incident occurred.

The hacking of Bangladesh Bank happened sometime between February 4 and February 5, over the Bangladeshi weekend, which falls on a Friday, the officials said. The bank's offices were shut for the holiday.

Initially, the central bank was not sure if their system had been breached, but then cyber security experts, brought from the outside to investigate, found hacker "footprints" that suggested their system had been compromised, the officials said.

These experts could also tell that the attack originated from outside Bangladesh, they said. The bank is still looking into how they got into the system and an internal investigation is also continuing, they said.

The bank suspects money sent to the Philippines was further diverted to casinos there, the officials said.

The Philippine Amusement and Gaming Corp, which oversees the gaming industry there, said it has launched an investigation. The country's anti-money laundering authority is also working on the case.

© Thomson Reuters 2016

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Bangladesh, Hackers, Hacking, Internet
Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo A6s 5G With 6,500mAh Battery Launched in India: See Price
  2. Poco X8 Series Arrives in India With 50-Megapixel Camera: See Price
  3. Samsung Could Equip Galaxy Z Fold 8, Wide Fold With These Batteries
  4. Vivo T5x 5G Goes Official in India With 7,200mAh Battery
  5. OnePlus 15T Will Be Launched in China Next Week, Company Confirms
  6. Vivo X300 Ultra, Vivo X300s Will Feature This New Colour Technology
  7. Jio Users Can Get Free Incoming SMS Abroad Using Wi-Fi Calling
  8. Here's How Much the Samsung Galaxy A57 5G and Galaxy A37 5G Might Cost
  9. Oppo K14 5G Debuts With 7,000mAh Battery at This Price in India
  10. Realme P4 Lite 5G Roundup: Price in India, Specifications Expected
  1. Powerbeats Pro 2 Nike Special Edition Launched in India With Apple's H2 Chip, ANC
  2. Xiaomi 17, Xiaomi 17 Ultra With Leica Optics and Snapdragon 8 Elite Gen 5 Chip Go on Sale in India: Price, Offers
  3. Huawei MatePad 11.5 Price in India, Launch Teased Along With Key Specifications
  4. Oppo A6s 5G Launched in India With 6,500mAh Battery, MediaTek Dimensity 6300 SoC: Price, Specifications
  5. Adobe, Nvidia Join Hands to Build the Next Generation of Firefly Models
  6. Amazon Rolls Out 1-Hour and 3-Hour Delivery Across Several US Cities and Towns
  7. Vivo X300 Ultra, Vivo X300s Teased to Feature New 'BluePrint Native' Colour Technology
  8. Samsung Galaxy A57 5G, Galaxy A37 5G Camera Configurations and Pricing Details Leaked
  9. Jio Reportedly Offers Free Incoming SMS Over VoWiFi Without Roaming Pack for International Travellers
  10. OnePlus 15T China Launch Date Announced for March 24; to Be Available in Five RAM, Storage Variants
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.