- Attackers gained unauthorized access to the Bangladesh Bank’s internal network
- Malware was installed on systems connected to SWIFT terminals
- The compromise remained undetected in the early stages
World Informatix Cyber Security played a key role in the historic cyber heist at Bangladesh’s Central Bank in 2016. In this whitepaper, “Bangladesh Bank Heist: The Decade That Changed Financial Security. We analyze the Bangladesh Bank cyber heist and its long-term impact on payment security, SWIFT-connected environments, and financial system resilience. It explores systemic risk, identity-driven payment fraud, continuous assurance, and the governance models required to detect and respond to modern payment-integrity incidents.
This FAQ seeks to answer some of the most common questions and confusions about this topic.
Attackers exploited weaknesses in Bangladesh Bank’s SWIFT messaging environment to issue fraudulent transfer instructions against its account at the New York Federal Reserve. They succeeded in moving roughly $101 million out of the account before the fraud was detected, one of the largest cyber-financial crimes in banking history.
World Informatix supported incident response, forensic investigation, and security remediation in the aftermath of the attack, helping to analyze how the intrusion occurred and to strengthen controls against future breaches.
The attack was a key catalyst for SWIFT’s Customer Security Programme (CSP), which introduced mandatory security controls across the entire SWIFT user community to prevent similar messaging-layer fraud from happening again.
The heist demonstrated that endpoint and access control weaknesses, not flaws in SWIFT itself, are usually the entry point for attackers, which is why independent CSP assessments focused on access control, transaction monitoring, and crisis management remain critical today.