Case

Bangladesh Bank heist (2016)

The Bangladesh Bank heist was a cyber-enabled attempt to steal approximately USD 951 million through fraudulent SWIFT payment messages in February 2016. United States authorities attribute the operation to North Korean state-backed actors and place it within a wider revenue-generation campaign. The public record supports classification as state-attributed competitive statecraft and criminal conduct outside armed conflict. It does not establish compromise of SWIFT's core network or the Federal Reserve Bank of New York's systems.

Attack path

Bangladesh Bank held a United States dollar account at the Federal Reserve Bank of New York and used SWIFT messages to instruct payments. Attackers compromised the bank's local environment, obtained or used payment credentials and generated fraudulent instructions. SWIFT carries authenticated financial messages rather than customer funds. The attack exploited trust in messages originating from a connected institution.

According to the United States 2018 criminal complaint, the intruders also used malware to interfere with local confirmation and reporting. The complaint is an allegation and evidential statement by prosecutors, not a conviction. Private analysis by BAE Systems linked technical artefacts and reconstructed parts of the attack. It should remain labelled as private technical analysis rather than substituted for a judicial finding.

Attackers submitted 35 transfer instructions totalling about USD 951 million between 4 and 8 February. Five instructions were executed, moving approximately USD 101 million. A roughly USD 20 million transfer to Sri Lanka was reversed, while about USD 81 million reached the Philippines and moved through accounts and casinos. Attempted, executed, reversed, laundered, frozen and recovered amounts are separate measures. Recovery and litigation continued after the event, so USD 81 million should not be presented as an unchanged final loss.

Attribution and state nexus

The United States Department of Justice charged Park Jin Hyok by criminal complaint in 2018 and unsealed an indictment against three named defendants in 2021. Charges against untried defendants remain allegations. The two instruments have different defendants, allegations and procedural status and must not be collapsed into a conviction.

The United States Treasury attributed and designated named North Korean malicious cyber groups in 2019. The Cybersecurity and Infrastructure Security Agency later placed the activity within its BeagleBoyz campaign assessment. The United Nations Panel of Experts also assessed North Korean cyber-enabled revenue generation and sanctions evasion in its 2019 final report. Together, these records support a probable direct state nexus in the Encyclopedia's classification. They do not expose every command link or constitute an admission by North Korea.

No operational objective was publicly declared by North Korea. Revenue generation and sanctions resilience are therefore inferred from official attribution, campaign pattern and laundering behaviour. The entry does not claim that the proceeds financed a particular weapons programme without a separate traceable evidential chain.

Institutional response and assessment

The New York Fed's 11 March 2016 statement said there was no evidence that its systems had been compromised. Later institutional cooperation and the joint statement by Bangladesh Bank, the New York Fed and SWIFT focused on security and recovery. Public evidence locates the initial compromise in Bangladesh Bank's environment, not SWIFT's core network.

The operation was significant but incomplete. Most instructions were stopped, yet the attackers converted trusted messages into real transfers and laundered a substantial sum. The case exposes linked vulnerabilities in customer endpoints, correspondent banking, message verification and downstream anti-money-laundering controls. It does not prove that central financial messaging is intrinsically insecure or that every intermediary acted negligently or knowingly.

The use of state-attributed cyber theft outside armed conflict is competitive statecraft, not wartime economic action. Military affiliation of an alleged operator does not by itself change the conflict classification. Any claim of armed attack or use of force would require a separate legal analysis not supplied by the charging and attribution records.

See also

SWIFT and interbank network intrusion techniques · Offensive cyber tools against financial infrastructure · North Korean cryptocurrency theft campaign (2017-present) · Lazarus Group · SWIFT · Correspondent banking and Nostro/Vostro architecture · Digital economic warfare · Financial warfare

Sources

Recommended citation

Cite this entry

Tennant, James J., ed. 'Bangladesh Bank heist (2016).' The Encyclopedia of Economic Statecraft, version 2.0.0-alpha, last reviewed 29 July 2026. https://jamesjtennant.com/entries/bangladesh-bank-heist-2016/.

Suggest an edit