Case
Bangladesh Bank heist (2016)
The Bangladesh Bank heist was a cyber-enabled attempt to steal approximately USD 951 million through fraudulent SWIFT payment messages in February 2016. United States authorities attribute the operation to North Korean state-backed actors and place it within a wider revenue-generation campaign. The public record supports classification as state-attributed competitive statecraft and criminal conduct outside armed conflict. It does not establish compromise of SWIFT's core network or the Federal Reserve Bank of New York's systems.
Attack path
Bangladesh Bank held a United States dollar account at the Federal Reserve Bank of New York and used SWIFT messages to instruct payments. Attackers compromised the bank's local environment, obtained or used payment credentials and generated fraudulent instructions. SWIFT carries authenticated financial messages rather than customer funds. The attack exploited trust in messages originating from a connected institution.
According to the United States 2018 criminal complaint, the intruders also used malware to interfere with local confirmation and reporting. The complaint is an allegation and evidential statement by prosecutors, not a conviction. Private analysis by BAE Systems linked technical artefacts and reconstructed parts of the attack. It should remain labelled as private technical analysis rather than substituted for a judicial finding.
Attackers submitted 35 transfer instructions totalling about USD 951 million between 4 and 8 February. Five instructions were executed, moving approximately USD 101 million. A roughly USD 20 million transfer to Sri Lanka was reversed, while about USD 81 million reached the Philippines and moved through accounts and casinos. Attempted, executed, reversed, laundered, frozen and recovered amounts are separate measures. Recovery and litigation continued after the event, so USD 81 million should not be presented as an unchanged final loss.
Attribution and state nexus
The United States Department of Justice charged Park Jin Hyok by criminal complaint in 2018 and unsealed an indictment against three named defendants in 2021. Charges against untried defendants remain allegations. The two instruments have different defendants, allegations and procedural status and must not be collapsed into a conviction.
The United States Treasury attributed and designated named North Korean malicious cyber groups in 2019. The Cybersecurity and Infrastructure Security Agency later placed the activity within its BeagleBoyz campaign assessment. The United Nations Panel of Experts also assessed North Korean cyber-enabled revenue generation and sanctions evasion in its 2019 final report. Together, these records support a probable direct state nexus in the Encyclopedia's classification. They do not expose every command link or constitute an admission by North Korea.
No operational objective was publicly declared by North Korea. Revenue generation and sanctions resilience are therefore inferred from official attribution, campaign pattern and laundering behaviour. The entry does not claim that the proceeds financed a particular weapons programme without a separate traceable evidential chain.
Institutional response and assessment
The New York Fed's 11 March 2016 statement said there was no evidence that its systems had been compromised. Later institutional cooperation and the joint statement by Bangladesh Bank, the New York Fed and SWIFT focused on security and recovery. Public evidence locates the initial compromise in Bangladesh Bank's environment, not SWIFT's core network.
The operation was significant but incomplete. Most instructions were stopped, yet the attackers converted trusted messages into real transfers and laundered a substantial sum. The case exposes linked vulnerabilities in customer endpoints, correspondent banking, message verification and downstream anti-money-laundering controls. It does not prove that central financial messaging is intrinsically insecure or that every intermediary acted negligently or knowingly.
The use of state-attributed cyber theft outside armed conflict is competitive statecraft, not wartime economic action. Military affiliation of an alleged operator does not by itself change the conflict classification. Any claim of armed attack or use of force would require a separate legal analysis not supplied by the charging and attribution records.
See also
SWIFT and interbank network intrusion techniques · Offensive cyber tools against financial infrastructure · North Korean cryptocurrency theft campaign (2017-present) · Lazarus Group · SWIFT · Correspondent banking and Nostro/Vostro architecture · Digital economic warfare · Financial warfare
Sources
- United States Department of Justice, "North Korean Regime-Backed Programmer Charged with Conspiracy to Conduct Multiple Cyber Attacks and Intrusions" (6 September 2018).
- United States District Court for the Central District of California, Criminal Complaint Against Park Jin Hyok (filed 8 June 2018).
- United States Department of Justice, "Three North Korean Military Hackers Indicted in Wide-Ranging Scheme" (17 February 2021).
- United States District Court for the Central District of California, Indictment of Jon Chang Hyok, Kim Il and Park Jin Hyok (unsealed 17 February 2021).
- United States Department of the Treasury, "Treasury Targets North Korea-Sponsored Malicious Cyber Groups" (13 September 2019).
- Federal Reserve Bank of New York, "Statement Regarding Bangladesh Bank" (11 March 2016).
- Federal Reserve Bank of New York, "New York Fed and Bangladesh Bank Agree to Cooperate" (23 June 2016).
- Bangladesh Bank, Federal Reserve Bank of New York and SWIFT, "Joint Statement" (16 August 2016).
- SWIFT, Customer Security Intelligence Report on the Bangladesh Bank Attack (2016).
- BAE Systems Applied Intelligence, "Two Bytes to USD 951 Million" (25 April 2016).
- Cybersecurity and Infrastructure Security Agency, FASTCash 2.0: North Korea's BeagleBoyz Robbing Banks (26 August 2020).
- United Nations Security Council Panel of Experts, Final Report Submitted Pursuant to Resolution 2455, S/2019/691 (30 August 2019).
Recommended citation
Cite this entry
Tennant, James J., ed. 'Bangladesh Bank heist (2016).' The Encyclopedia of Economic Statecraft, version 2.0.0-alpha, last reviewed 29 July 2026. https://jamesjtennant.com/entries/bangladesh-bank-heist-2016/.
Suggest an edit