Bangladesh Bank Exposed to Hackers by Cheap Switches, No Firewall: Police

Advertisement
By Reuters | Updated: 22 April 2016 15:30 IST
Bangladesh's central bank was vulnerable to hackers because it did not have a firewall and used second-hand, $10 switches to network computers connected to the SWIFT global payment network, an investigator into one of the world's biggest cyber heists said.

The shortcomings made it easier for hackers to break into the Bangladesh Bank system earlier this year and attempt to siphon off nearly $1 billion using the bank's SWIFT credentials, said Mohammad Shah Alam, head of the Forensic Training Institute of the Bangladesh police's criminal investigation department.

"It could be difficult to hack if there was a firewall," Alam said in an interview.

The lack of sophisticated switches, which can cost several hundred dollars or more, also means it is difficult for investigators to figure out what the hackers did and where they might have been based, he added.

Advertisement

Experts in bank security said that the findings described by Alam were disturbing.

"You are talking about an organisation that has access to billions of dollars and they are not taking even the most basic security precautions," said Jeff Wichman, a consultant with cyber firm Optiv.

Tom Kellermann, a former member of the World Bank security team, said that the security shortcomings described by Alam were "egregious," and that he believed there were "a handful" of central banks in developing countries that were equally insecure.

Advertisement

Kellermann, now chief executive of investment firm Strategic Cyber Ventures LLC, said that some banks fail to adequately protect their networks because they focus security budgets on physically defending their facilities.

Police blame bank, Swift
Cybercriminals broke into Bangladesh Bank's system and in early February tried to make fraudulent transfers totalling $951 million from its account at the Federal Reserve Bank of New York.

Advertisement

Most of the payments were blocked, but $81 million (roughly Rs. 538 crores) was routed to accounts in the Philippines and diverted to casinos there. Most of those funds remain missing.

The police believe that both the bank and SWIFT should take the blame for the oversight, Alam said in an interview.

Advertisement

"It was their responsibility to point it out but we haven't found any evidence that they advised before the heist," he said, referring to SWIFT.

A spokeswoman for Brussels-based SWIFT declined comment.

SWIFT has previously said the attack was related to an internal operational issue at Bangladesh Bank and that SWIFT's core messaging services were not compromised.

A spokesman for Bangladesh Bank said SWIFT officials advised the bank to upgrade the switches only when their system engineers from Malaysia visited after the heist.

"There might have been a deficiency in the system in the SWIFT room," said the spokesman, Subhankar Saha, confirming that the switch was old and needed to be upgraded.

"Two (SWIFT) engineers came and visited the bank after the heist and suggested to upgrade the system," Saha said.

Global whodunit
The heist's masterminds have yet to be identified.

Bangladesh police said earlier this week they had identified 20 foreigners involved in the heist but they appear to be people who received some of the payments, rather than those who initially stole the money.

Bangladesh Bank has about 5,000 computers used by officials in different departments, Alam said.

The SWIFT room is roughly 12 feet by 8 feet, a window-less office located on the eight floor of the bank's annex building in Dhaka. There are four servers and four monitors in the room.

All transactions from the previous day are automatically printed on a printer in the room.

The SWIFT facility should have been walled off from the rest of the network. That could have been done if the bank had used the more expensive, "managed" switches, which allow engineers to create separate networks, said Alam, whose institute includes a cybercrime division.

Moreover, considering the importance of the room, the bank should have deployed staff to monitor activity round the clock, including weekends and holidays, he said.

© Thomson Reuters 2016

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Further reading: Bangladesh, Hackers, Hacking, Internet
Advertisement

Related Stories

Popular Mobile Brands
  1. Here's When the Realme P4 Power 5G Will Launch in India
  2. Oppo A6 5G Launched in India With 7,000mAh Battery at This Price
  3. Redmi Note 15 Pro Series Might Launch in India With These Storage Options
  4. Motorola Edge 70 Fusion Leak Reveals Full Specifications Ahead of Launch
  5. Vivo X200T With Zeiss Cameras to Launch in India on This Date
  6. OnePlus 16 May Launch With These Display, Battery and Camera Upgrades
  7. Bindiya Ke Bahubali Season 2 OTT Release Date: Know Everyting About Cast, Plot, and Mo
  8. Red Magic 11 Air Launched With Snapdragon 8 Elite, 7,000mAh Battery
  9. Samsung Galaxy A57 Spotted on Certification Site With These Key Features
  10. SpaceX Adds 29 More Starlink Satellites in Rapid Falcon 9 Launch From Florida
  1. Scientists Find Clue to High-Temperature Superconductivity in Quantum Materials
  2. New Dark Matter Simulation Could Change How Galaxies Are Thought to Evolve
  3. SpaceX Adds 29 More Starlink Satellites in Rapid Falcon 9 Launch From Florida
  4. Sony to Cede Control of Bravia TVs to China’s TCL Electronics
  5. Adobe Premiere Integrated With AI-Powered Firefly Platform; New After Effects Features Rolling Out
  6. Samsung Upgrades Bixby With Perplexity-Powered AI Features, Takes Page Out of Apple’s Playbook
  7. Google Reportedly Working On New Live Features and Agentic Mode for Gemini Assistant
  8. Redmi Note 15 Pro+, Redmi Note 15 Pro RAM and Storage Options, Key Specifications Leaked Ahead of India Launch
  9. Eddington Arrives on OTT: What You Need to Know About Joaquin Phoenix and Pedro Pascal Starrer Thriller
  10. Red Magic 11 Air Launched With Snapdragon 8 Elite, RedCore R4 Gaming Chip and 7,000mAh Battery
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.