Technology

SWIFT and interbank network intrusion techniques

SWIFT and interbank network intrusion techniques are the methods used to compromise the credentials, terminals and workflows through which banks send payment instructions over the SWIFT messaging network and related interbank systems, in order to inject fraudulent transfers that the receiving institutions treat as legitimate. In economic warfare they are the class of attack that turns the integrity of financial messaging itself into a target, exemplified by the Bangladesh Bank heist.

Function

The attack does not break SWIFT's cryptography; it subverts the bank's use of it. Intruders gain access to a member institution's environment, study its payment operations, steal or misuse the operator credentials that authorise SWIFT messages, and then submit fraudulent MT-type payment instructions during windows when detection is least likely. Sophisticated variants also tamper with the bank's local confirmation and reconciliation software to hide the fraudulent messages and delay discovery. Because the messages carry valid credentials, correspondent banks and the settlement systems downstream process them as authentic, so the fraud succeeds at the level of the message standard rather than the network.

Strategic significance

This technique attacks the trust model of the global payment system: SWIFT's security rests on members securing their own endpoints, so a single weak member becomes an entry point to move value across the network. For a sanctioned state, it is a way to extract hard currency directly from the financial system that excludes it, a striking inversion in which the excluded actor loots the infrastructure of exclusion. It sits within an adversary's Economic Kill Chain as an execution technique against a financial node, and it exposes the systemic fragility that defensive resilience doctrine must address. The response, SWIFT's Customer Security Programme and mandatory controls, is a collective-defence measure against a shared vulnerability.

Control and weaponisation history

The Bangladesh Bank heist (2016) involved fraudulent instructions seeking approximately USD 951 million from Bangladesh Bank's account at the Federal Reserve Bank of New York. About USD 81 million reached accounts in the Philippines before most instructions were stopped. The attempted and realised amounts measure different stages and should not be combined. United States complaints and indictments associated the operation with named North Korean programmers and the Lazarus Group; those charges are procedural allegations, not a judicial finding against every attributed actor. SWIFT's Customer Security Programme, checked on 30 July 2026, continues to organise member endpoint controls and assurance. It does not secure local credentials, correspondent processing or final settlement by itself.

The payment chain matters to loss allocation and defence. A valid-looking message may be rejected by a correspondent, paused by fraud controls, accepted but not finally settled, or settled and later recovered. Local printers, reconciliation records and operator workflows can expose a compromise even when the network delivered the message as designed. Separating those stages prevents an endpoint intrusion from being described inaccurately as a breach of SWIFT's core network.

See also

Bangladesh Bank heist (2016) · Lazarus Group · SWIFT · Cross-border payment messaging: SWIFT MT and ISO 20022 · Economic statecraft

Sources

Recommended citation

Cite this entry

Tennant, James J., ed. 'SWIFT and interbank network intrusion techniques.' The Encyclopedia of Economic Statecraft, version 2.0, last reviewed 30 July 2026. https://jamesjtennant.com/entries/swift-and-interbank-network-intrusion-techniques/.

Suggest an edit