Home / Blog / The Bangladesh Bank Heist: How a Spelling Mistake Stopped a $951 Million Theft
Korp Labs · Field Notes

The Bangladesh Bank Heist: How a Spelling Mistake Stopped a $951 Million Theft

 ·  4 min read  ·  By Korp VPN

In February 2016, someone with legitimate access to the Bangladesh Bank's systems began issuing transfer instructions through SWIFT, the messaging network banks use to move money internationally.

The instructions were properly formatted and correctly authenticated. As far as the receiving institutions were concerned, Bangladesh's central bank was moving its own money.

Thirty-five transfer orders were issued, totalling roughly $951 million — a substantial share of the country's foreign reserves.

The timing

The attack was scheduled with real care.

The orders went out on a Thursday evening. In Bangladesh, the weekend runs Friday to Saturday, so the bank's offices would be closed. The receiving accounts were in the Philippines, where the following Monday was a public holiday for Lunar New Year.

The result was a window of several days in which the money could move, be converted and disappear, while nobody on the sending side was at work to notice and nobody on the receiving side was processing enquiries.

The attackers had also compromised the bank's SWIFT software so that confirmation messages — the paper trail a bank would normally review — were suppressed. A printer that should have produced a physical record of each transaction had been disabled. When staff eventually tried to investigate, the very systems they would use to check were the ones that had been tampered with.

What stopped it

Most of the $951 million never moved, and the reason is almost comically small.

One of the transfers, for $20 million, was directed to a non-governmental organisation in Sri Lanka. On the instruction, the word foundation was spelled "fandation."

A routing bank noticed the oddity and queried it. That query prompted a closer look, which surfaced the volume of unusual transfers coming from Bangladesh. The Federal Reserve Bank of New York, which held the account the money was leaving, began blocking the remaining instructions.

By then, five transfers totalling roughly $81 million had already completed into accounts at a bank in Manila. That money was moved rapidly through casinos — a sector then largely outside the Philippines' anti-money-laundering rules — and most of it was never recovered.

A typo saved approximately $870 million.

The uncomfortable part

Nothing about this attack broke cryptography. SWIFT was not defeated as a protocol. The messages were valid because they were sent with valid credentials from an authorised machine inside the bank.

Investigators found that the bank's network had been penetrated well in advance — reportedly with limited network segmentation between systems and a lack of monitoring that would have flagged unusual activity. Once attackers were inside and had obtained operator credentials, the fraudulent transfers were, technically speaking, ordinary transfers.

This is the recurring shape of serious financial intrusion. The attacker does not break the vault. They become someone who is allowed to open it, then use the ordinary mechanism at a moment when nobody is watching.

The attack has been widely attributed to the group known as Lazarus, associated with North Korea, and linked to a broader campaign against banks in several countries.

What generalises

Authentication is not authorisation, and neither is intent. Every control in the chain confirmed that the messages came from the right place. None asked whether a central bank emptying a fifth of its reserves over a long weekend was plausible. Anomaly detection asks a different question from access control, and systems that only do the second are easier to abuse than they look.

Attackers plan around your calendar. Holidays, weekends and the hours when your team is asleep are not incidental details; they are part of the design. This is true at every scale — fraudulent charges on personal cards cluster in the same windows.

Suppressing the alarm is part of the attack. Disabling the confirmation printer was as important as sending the transfers. When you evaluate any system you rely on, it is worth asking how you would find out if it were lying to you.

The catch was luck. No control detected this. A human noticed a spelling mistake. Institutions that depend on that kind of luck are not secure; they are fortunate, and the two are easy to confuse in hindsight.

For an individual, the practical echo is straightforward: the accounts that matter are the ones that can authorise things — your bank, and your email, which can reset your bank. Multi-factor authentication on those, alerts turned on for transactions so the anomaly reaches you rather than sitting in a log, and real caution about credentials entered on networks or devices you do not control.

The Bangladesh Bank did not lose $81 million because someone broke its encryption. It lost it because someone became an authorised user, waited for the office to close, and turned off the printer.

hacking historyfinancial fraudmalwarenetwork security

Read this on a network nobody is watching

Korp VPN encrypts every packet leaving your device with AES-256 and a stealth protocol that looks like ordinary HTTPS traffic. Unlimited bandwidth, 20+ countries, a strict no-logs policy, and a 5-day free trial — from $1.60 per month.

← Previous
Albert Gonzalez: The Informant Who Stole 170 Million Credit Cards While Working for the Government
Next →
What Your ISP Can Actually See — an Honest, Technical Answer

More from Korp Labs

What "No-Logs VPN" Really Means and How to Check the Claim

Almost every VPN says it keeps no logs. The phrase can mean very different things. Here is what a meaningful no-logs policy covers, and the questions that expose a weak one.

VPN vs Proxy vs Tor: What Each One Actually Protects

They all change your IP address, but they protect very different things. A plain-language comparison of VPNs, proxies and Tor, and how to pick the right one for what you are doing.

How to Test Your VPN for Leaks: DNS, IPv6 and WebRTC

A VPN can be connected and still leak your real IP address or DNS lookups. Here is how to run the three tests that matter in under five minutes, and how to fix what you find.