$US81m SWIFT hack highlights everyday security concerns
Summary
This blueAPACHE post reports: In February 2016 during Chinese New Year, one of the most brazen and largest digital heists in history took place. A group of unidentified hackers used sophisticated malware to study bank workers and subsequently divert $US81 million from a Bangladesh Central Bank account at the Federal Reserve Bank of New York to multiple accounts in Sri Lanka and the Philippines. It concerns emPOWER Security, emPOWER Core Network & Data Centre Interconnect, emPOWER Connectivity. Published in 2016. Figures, product names and event details reflect that time; for current information see the linked service pages.
Key facts
| Label | Value |
|---|---|
| Publication year | 2016 |
| Services referenced | emPOWER Security, emPOWER Core Network & Data Centre Interconnect, emPOWER Connectivity |
| Cited figure | ...Reserve Bank of New York to transfer funds. 30 transactions worth $851 million were prevented by the banking system – but five requests were... |
Article
The 2016 $US81m heist (which could have been much worse!)
In February 2016 during Chinese New Year, one of the most brazen and largest digital heists in history took place. A group of unidentified hackers used sophisticated malware to study bank workers and subsequently divert $US81 million from a Bangladesh Central Bank account at the Federal Reserve Bank of New York to multiple accounts in Sri Lanka and the Philippines.
The instructions to steal the funds were issued via SWIFT – the Society for Worldwide Interbank Financial Telecommunication – a highly trusted and ubiquitous network used by thousands of financial institutions worldwide to facilitate transfers between banks. Computer security researchers have linked this theft to as many as 11 other attacks worldwide, all executed using the SWIFT banking network.
The attacks involved malware written to issue unauthorised SWIFT messages and to conceal that the messages had been sent. In some cases, access was gained through targeted social engineering attacks that encouraged employees to inadvertently disclose their credentials and private access information.
The hackers managed to compromise Bangladesh Bank’s system, observe how transfers are done, and gain access to the bank’s credentials for payment transfers, which they used to send requests to the Federal Reserve Bank of New York to transfer funds. 30 transactions worth $851 million were prevented by the banking system – but five requests were granted; totalling $20 million to Sri Lanka (later recovered) and $81 million lost to the Philippines.
According to reports, the core messaging system of SWIFT was not breached; instead, the criminals attacked the banks’ connections to the SWIFT network. Most banks have governance to identify fraudulent transactions, however the malware deletes evidence of the hackers’ activities and subverts normal business processes to remain undetected.

Implications
Hackers are increasingly focusing on SWIFT and other private platforms. Aside from the greater transactional values (and fewer alarms for high value transactions), SWIFT’s security is not equipped to deal with the progressively sophisticated attacks from modern day hackers. The 30 transactions that were prevented were typically halted through human intervention due to common spelling mistakes (“fundation” instead of “foundation” for example). According to BAE Systems, a defence and security company that analysed the attack, “the general tools, techniques and procedures used in the attack may allow the gang to strike again. All financial institutions who run SWIFT Alliance Access and similar systems should be seriously reviewing their security now to make sure they too are not exposed.
“The wider lesson learned here may be that criminals are conducting more and more sophisticated attacks against victim organisations, particularly in the area of network intrusions.”
Moving forward
These attacks signal a warning not just for the SWIFT platform and financial institutions, but any organisation that deals with private platforms. Users of procurement, contract and payment gateways need to be cautious. Private platforms might feel safe, but as the value and awareness increases, targeted threats against specific organisations are becoming increasingly common and effective. The way your network is structured can potentially open up your entire data infrastructure to threats. Dividing the network into segments or placing data in separate disconnected networks may minimise the impact of a targeted attack. Intelligent network architectures can contain attacks and minimise damage automatically, moving organisations away from a reactive solution. The SWIFT hacking also serve as a grim reminder that cyber security is as much about people as it is about technology – with sophisticated hackers being been able to recruit employees to hand over credentials and other key details. Cyber security awareness training is one of the most effective ways to prevent social engineering attacks. If employees know what to look out for, are vigilant, and question any suspicious information request, then they are less likely to become an unwitting accomplice to such attacks. If you have concerns about the threats of potential cyber-attacks on your organisation, or would like staff training on security awareness, contact the blueAPACHE account team.
Related
- emPOWER Security
- emPOWER Security (pillar)
- emPOWER Core Network & Data Centre Interconnect
- emPOWER Connectivity (pillar)
Frequently asked questions
How much money was ultimately stolen in the 2016 Bangladesh Bank SWIFT heist, according to the article?
The article says hackers stole $81 million to accounts in the Philippines, plus a further $20 million sent to Sri Lanka that was later recovered, out of 30 attempted transactions worth $851 million that the banking system prevented.
How did the article say the hackers gained access to issue the fraudulent SWIFT transfer requests?
The article says the hackers compromised Bangladesh Bank's system, in some cases through targeted social engineering that got employees to disclose credentials, then used the bank's own SWIFT payment transfer credentials to send fraudulent requests to the Federal Reserve Bank of New York.
What common error typically stopped the fraudulent transactions that were blocked, according to the article?
The article says the 30 blocked transactions were typically halted through human intervention due to common spelling mistakes, citing "fundation" instead of "foundation" as an example.
What did BAE Systems say about the risk of similar attacks recurring, according to the article?
BAE Systems, which analysed the attack, said the general tools, techniques and procedures used may allow the same group to strike again, and urged all financial institutions running SWIFT Alliance Access and similar systems to review their security.
Is the information in this post still current?
No. It reports a specific 2016 banking heist and its immediate aftermath; for blueAPACHE's current security services, see the emPOWER Security pillar page rather than this post.
Source
https://www.blueapache.com/blog/swift-hack-highlights-everyday-security-concerns/
Knowledge Base
What was the $US81 million SWIFT hack described in blueAPACHE's blog post?
In February 2016 during Chinese New Year, a group of unidentified hackers used sophisticated malware to study bank workers and divert $US81 million from a Bangladesh Central Bank account at the Federal Reserve Bank of New York to multiple accounts in Sri Lanka and the Philippines.
How were the fraudulent instructions issued in the 2016 SWIFT heist?
The instructions to steal the funds were issued via SWIFT (the Society for Worldwide Interbank Financial Telecommunication), a highly trusted and ubiquitous network used by thousands of financial institutions worldwide to facilitate transfers between banks.
How much money did the hackers attempt to steal, and how much was actually lost or recovered?
The hackers attempted 30 transactions worth $851 million, which were prevented by the banking system. Five requests were granted, totalling $20 million sent to Sri Lanka (later recovered) and $81 million lost to the Philippines.
How did the hackers gain access to Bangladesh Bank's systems and credentials?
The hackers compromised Bangladesh Bank's system, observed how transfers are done, and gained access to the bank's credentials for payment transfers, which they used to send requests to the Federal Reserve Bank of New York to transfer funds. In some cases, access was gained through targeted social engineering attacks that encouraged employees to inadvertently disclose their credentials and private access information.
Was the core SWIFT messaging system itself breached in the attack?
According to reports, the core messaging system of SWIFT was not breached; instead, the criminals attacked the banks' connections to the SWIFT network. The malware deleted evidence of the hackers' activities and subverted normal business processes to remain undetected.
How were the 30 fraudulent transactions that were prevented actually stopped?
The 30 transactions that were prevented were typically halted through human intervention due to common spelling mistakes, such as 'fundation' instead of 'foundation.'
What did BAE Systems say about the implications of the SWIFT attack?
BAE Systems, a defence and security company that analysed the attack, said the general tools, techniques and procedures used in the attack may allow the gang to strike again, and that all financial institutions running SWIFT Alliance Access and similar systems should be seriously reviewing their security. BAE Systems also noted that the wider lesson may be that criminals are conducting more sophisticated attacks against victim organisations, particularly in network intrusions.
What network architecture recommendations does the blog post make in response to the SWIFT hack?
The blog post recommends dividing the network into segments or placing data in separate disconnected networks to minimise the impact of a targeted attack, noting that intelligent network architectures can contain attacks and minimise damage automatically, moving organisations away from a reactive solution.
What role does human behavior play in attacks like the SWIFT hack, according to the blog post?
The blog post states that the SWIFT hacking serves as a grim reminder that cyber security is as much about people as it is about technology, since sophisticated hackers were able to recruit employees to hand over credentials and other key details. It recommends cyber security awareness training as one of the most effective ways to prevent social engineering attacks, so employees can recognize and question suspicious information requests.
Who published this blog post about the SWIFT hack and when?
The blog post was written by blueAPACHE and published on June 21, 2016, with a stated read time of 4 minutes.
Images on This Page
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bba_31b5a84971e1d1ce71dc99ca059bfbde_blueAPACHE.svg
blueAPACHE logo on a dark blue background
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701c03b153d68a8eeb8f4d_bankheist.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a713402a5a7f7ebf553f0bf_Background-Top.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701c06b153d68a8eeb906b_bank-heist-2016.jpeg
Bank Heist Malware
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701b59b153d68a8eeb0e36_BBanner-1-Windows-10-is-out.-AI-is-in.-.avif
You’ve Invest in Security. So Why Are Breaches Still Happening?
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb807b7741bf53e298a_BBanner-1-Windows-10-is-out.-AI-is-in.-8.avif
EOFY 2026: The Reset Is Done – Now It’s About Getting Ahead
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d0_BBanner-2-When-support-ends-risk-begins-4.avif
Why Every Business Needs AI Guardrails
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d7_BBanner-2-When-support-ends-risk-begins-3.avif
Ransomware Incident Response: Why Paying the Ransom Is a Failure of Preparation
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb707b7741bf53e297d_BBanner-2-When-support-ends-risk-begins-1.avif
The 7 Cyber Truths Boards Must Act On In 2026
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29f9_BBanner-1-Windows-10-is-out.-AI-is-in.-7.avif
Reflecting on an Outstanding 2025 – Thank You for Your Partnership
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e2a0c_Procurement-Portal.avif
The blueAPACHE e-Store: IT purchasing made simple
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29ec_BBanner-1-Windows-10-is-out.-AI-is-in.-5.avif
Building Our Cyber Safe Culture: A Practical Guide for CSAM 2025
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fbfad31fa678fefd51a_6a704f395a0a01b8e482853a_support-monitor.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4563e_6a704f3a400fc8e661400519_support-user.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45639_6a704f3a91ffd7d0dbc40847_support-phone.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4562f_6a704f3747d60bd3f65b7a31_support-globe.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45636_6a704f38eb60992797acf5d9_support-mail.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45633_6a704f3a07b7741bf54f2122_support-speech-bubble.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a707520ca872d1b5a69a518_Sensiba.avif
Sensiba ISO/IEC 27001 Certified badge with a diamond-shaped logo below the text.