Case Study - Financial Cyber Heist
Bangladesh Bank Heist
Year – 2016
Estimated Economic Losses – US$81 Million successfully stolen. Fraudulent transfer attempts totaled approximately US$951 Million.
Systems Affected – Bangladesh Bank’s SWIFT payment system, internal banking network, workstations, and international fund transfer infrastructure.
Type of Attack – Financial Cyber Heist | SWIFT Payment System Attack
Suspected Group / Organization – Widely attributed to the Lazarus Group, a North Korean state-sponsored cyber threat group.
Detailed Working
Attackers infiltrated Bangladesh Bank’s network, obtained SWIFT credentials, and issued fraudulent payment instructions through the SWIFT banking system. Malware was used to manipulate transaction records and delay detection while funds were transferred to overseas accounts.
Forensic Investigations
Investigators analyzed SWIFT transaction logs, malware samples, network traffic, and system logs to reconstruct the attack. The investigation confirmed unauthorized SWIFT payment messages, compromised credentials, malware used to conceal fraudulent activity, and evidence linking the operation to the Lazarus Group.