Skip to content
Security Notes

The Bangladesh Bank SWIFT heist and the typo that saved $850M

By Elias Lankinen10 min read

I have enough well-sourced material across primary and credible reporting, plus four verified images. Writing the post now.

The printer that wouldn't print

On the morning of Friday, 5 February 2016, staff at the Bangladesh Bank's headquarters in Dhaka noticed that a printer wasn't working. This was not, on its face, an emergency. The machine in question sat in a tenth-floor room and did one narrow job: it automatically printed out confirmations of the bank's international money transfers as they came in over SWIFT, the messaging network that banks use to move money across borders. The tray was empty. Someone tried to restart it, got nothing useful, and moved on. It was the start of the Bangladeshi weekend, which runs Friday to Saturday, and the office was winding down. That silent printer was the only visible symptom of what would become one of the largest bank robberies in history. While it sat dark, a group of hackers most investigators now attribute to North Korea was in the middle of trying to steal nearly a billion dollars from the country's foreign reserves, held in an account at the Federal Reserve Bank of New York. They very nearly got it. They walked away with $81 million. And the reason they didn't get the other $850 million or so has almost nothing to do with the story most people have heard.

Source: Wikimedia Commons
Source: Wikimedia Commons

The window nobody was watching

The attackers did not pick their moment by accident. They chose a seam in the world's timekeeping and slipped through it. The fraudulent transfer orders started hitting the New York Fed on the afternoon of Thursday, 4 February 2016, New York time. According to a timeline reconstructed by the US National Security Archive from court and investigative records, the orders were sent from Bangladesh Bank's SWIFT terminal in the evening in Dhaka, after the close of business on a Thursday, which is when the Bangladeshi working week ends. So when the orders arrived, Bangladesh Bank was already shutting for its Friday-Saturday weekend. Now run the clock forward. By the time Bangladesh Bank reopened on Sunday and began to realise something was wrong, New York had gone into its weekend, and the Fed was closed. And the accounts receiving the money sat in the Philippines, where Monday 8 February was the Chinese New Year, a bank holiday. Line those three calendars up and you get a gap of roughly three to four days during which almost nobody who could stop the money was at their desk at the same time as anyone else. That was the plan. The heist was, in a real sense, a scheduling exploit as much as a hacking one. Inside that window, the attackers submitted 35 payment instructions asking the Fed to move money out of Bangladesh Bank's account, totalling around $951 million, close to the entire relevant balance. Five of those orders went through. The rest, as we'll see, snagged on something the thieves could not have engineered.

Two bytes and a fake printout

To send instructions that the Fed would honour, the attackers needed to look exactly like Bangladesh Bank. That meant getting inside the bank's SWIFT setup, and it meant making sure no one noticed the theft until the money was gone. Investigators believe the intruders were quietly inside Bangladesh Bank's network for weeks beforehand, watching how staff performed transfers and harvesting the credentials they needed. The clever part came at the end. Researchers at the British defence firm BAE Systems, who obtained samples of the custom malware, published a technical breakdown in April 2016 that reads like a locksmith's confession. The core tool was a program called evtdiag.exe, compiled, the metadata suggests, on 5 February 2016, right in the middle of the operation. It targeted Alliance Access, the software banks use to connect to SWIFT, which stores its records in an Oracle database. The malware's signature trick, and the source of BAE's memorable title "Two bytes to $951m", was almost absurdly small. It found a specific security check in a database library in memory and overwrote a two-byte instruction, a conditional jump (0x75 0x04), with two "do-nothing" NOP instructions (0x90 0x90). With that check neutralised, the software would no longer object when its own transaction records were tampered with. From there the malware did three things. It read incoming SWIFT messages to learn the details it needed. It quietly deleted the database records of the fraudulent transfers and altered account balances so the numbers still looked right. And, crucially, it hijacked the confirmation trail. Every SWIFT transfer generates confirmation messages, and Bangladesh Bank's system automatically printed them so staff could reconcile them by hand each day. The malware intercepted those messages, generated doctored copies, and sent those to the printer, formatted for the bank's "HP LaserJet 400 M401" model, before overwriting the originals. This is why the printer story matters. The machine wasn't broken. It had been co-opted, and part of the sabotage was making sure the paper record that would have screamed "money is leaving" simply never appeared. When staff eventually got the printer working manually on Saturday, the confirmations they finally saw were the ones that gave the game away.

Following the money

Source: Wikimedia Commons
Source: Wikimedia Commons

The five successful orders split two ways. Twenty million dollars went to Sri Lanka. The other $81,001,662.12 went to the Philippines, where the real laundering plan lived. The money landed in four accounts at a single branch of Rizal Commercial Banking Corporation (RCBC), on Jupiter Street in the Makati district of Manila. According to reporting collected by the Philippine Center for Investigative Journalism, those accounts had been opened months earlier, in May 2015, under fictitious names, and had sat dormant with a token balance ever since, waiting. When the $81 million arrived, it was rapidly converted into Philippine pesos, funnelled through a money changer, and pushed into the Solaire and Midas casinos. Casinos were the perfect laundromat because, at the time, they were carved out of the Philippines' anti-money-laundering law entirely. Once dirty money is turned into gaming chips, played (even a little), and cashed back out, it re-emerges looking like winnings, its trail broken. Much of it disappeared into the hands of junket operators and high-roller gamblers and was gone. Only one person, the RCBC branch manager Maia Santos Deguito, has ever been convicted in the case, in January 2019, on eight counts of money laundering. She has maintained she was a scapegoat.

The typo, and the fluke that actually mattered

Here is the part everyone remembers, and the part almost everyone gets slightly wrong. The $20 million bound for Sri Lanka was meant for an outfit called the Shalika Foundation. But whoever typed the instruction spelled it "Fandation." A routing bank in the chain, Deutsche Bank, queried the misspelling, and a Sri Lankan bank official also balked at the unusually large sum going to a little-known non-profit. The transfer was stopped, and the $20 million was later returned. That is the origin of the famous headline: a typo foiled the heist. It is a great story. It is also, on the numbers, mostly wrong. The typo stopped one transfer worth $20 million, money that was recovered in full anyway. It did nothing to save the other $850 million or so, and the popular framing that a spelling mistake rescued the bulk of the reserves is a genuine misconception worth correcting. So what did save the rest? A different coincidence entirely, and a much stranger one. The RCBC branch in Manila was on Jupiter Street, so "Jupiter" appeared in the payment instructions as part of the address. As it happens, "Jupiter" was also the name of an oil tanker and shipping company on the United States' sanctions list against Iran. That word tripped the New York Fed's automated sanctions-screening filter. The flagged orders were pulled aside for manual review, and once humans were looking, the sheer oddity of the requests, dozens of transfers to personal accounts rather than institutions, became obvious. Thirty of the 35 orders were held and cancelled. A person familiar with the Fed's handling of the matter told Reuters it was a "total fluke" that the bank did not pay out the full $951 million. There is no suggestion the tanker or its owners had anything to do with the heist. A street name in Manila happened to collide with a sanctioned vessel's name, and that collision is what kept roughly $850 million from vanishing. The typo makes the better anecdote. The sanctions filter did the real work.

Who was on the other end

For months the attack had no named author, only a sophisticated fingerprint. Security researchers at BAE Systems and Symantec noticed that the code and techniques overlapped with the 2014 hack of Sony Pictures and with a family of intrusions they tracked as the work of the Lazarus Group, a hacking operation tied to the North Korean state. In September 2018 the US Department of Justice put a name to it, charging a North Korean programmer, Park Jin Hyok, with conspiracy to commit wire fraud and computer fraud. The complaint tied him to a single sprawling campaign: the Sony attack, the 2017 WannaCry ransomware outbreak, and the Bangladesh Bank theft. Prosecutors alleged the group worked on behalf of the North Korean government through a military intelligence arm, the Reconnaissance General Bureau, and that operators worked partly out of a front company in the Chinese city of Dalian. In February 2021 the DOJ broadened the case, charging two more North Koreans, Jon Chang Hyok and Kim Il, and framing the whole enterprise as a state programme to steal more than $1.3 billion from banks and cryptocurrency firms. North Korea has denied that Park Jin Hyok even exists.

Source: Wikimedia Commons / FBI
Source: Wikimedia Commons / FBI

The motive matters here. This was not a criminal gang chasing a payday for its own sake. If the attribution is right, it was a heavily sanctioned, cash-starved state treating the global banking system as a source of hard currency, using the same national resources another country might point at espionage or sabotage. That reframes the whole event. A bank robbery you can insure against. A nation-state that has learned it can reach into a central bank's reserve account through the plumbing of international finance is a different kind of problem.

What broke, and what got fixed

The fallout was uneven. Bangladesh Bank's governor, Atiur Rahman, resigned on 15 March 2016 as the scandal grew. In the Philippines, the central bank hit RCBC with a ₱1 billion fine, then roughly $53 million and the largest such penalty in its history. The Philippines later closed the loophole that had exempted casinos from anti-money-laundering rules. Bangladesh sued RCBC in New York to recover its money; the litigation has ground on for years. Recovery has been dismal. All $20 million sent to Sri Lanka came back. Of the $81 million that reached Manila, only about $15 million has been recovered, leaving roughly $66 million still missing a decade on. The deeper response was aimed at the network itself. SWIFT is a cooperative owned by the banks that use it, and it had always drawn a firm line: it was responsible for the messaging, and each member was responsible for securing its own connection to it. The Bangladesh case, followed quickly by evidence of similar attempts at other banks, made that division look untenable. In 2016 SWIFT launched its Customer Security Programme, a mandatory set of security controls that members must attest to and, increasingly, prove. The uncomfortable lesson was that a global network is only as trustworthy as its weakest participant, and that a central bank in a developing country, connected to the same rails as everyone else, could become that weak point. That is the part still worth watching. The Bangladesh heist wasn't a freak event; it was a proof of concept, and the same playbook has since been aimed at banks in Vietnam, Ecuador and elsewhere, and the broader Lazarus operation has pivoted hard into cryptocurrency exchanges, where the money moves faster and the sanctions filters are thinner. We tend to remember this story as a comedy of errors redeemed by a misspelled word. It is closer to the opposite: a meticulous operation that failed only because a street in Manila happened to share a name with an Iranian oil tanker. The interesting question is not why this heist fell short by $850 million. It is how much of that margin was skill on the defenders' side, and how much was luck that the next attacker already knows not to count on.

Sources

  1. Wikipedia, Bangladesh Bank robbery, accessed 2026.
  2. BAE Systems Threat Research, Two bytes to $951m, 2016.
  3. The Daily Star / Reuters, How the New York Fed fumbled over the Bangladesh Bank heist, 2016.
  4. NBC News, Hacker's Typo Tipped Off Authorities on Billion-Dollar Heist, 2016.
  5. Vice / Motherboard, Cunning Malware Covered Hackers' Tracks in $81M Bangladeshi Bank Heist, 2016.
  6. National Security Archive, Tainted Trove, 2019.
  7. Philippine Center for Investigative Journalism, What went before: The Bangladesh Bank heist, 2020.
  8. FindLaw, Bangladesh Bank v. Maia Santos Deguito, et al., 2024.
  9. BankInfoSecurity, Feds Charge North Korean With Devastating Cyberattacks, 2018.
  10. Al Jazeera, US charges three North Koreans for major hacks and cyber-thefts, 2021.
  11. Philippine Daily Inquirer, Bangladesh central bank governor quits over $81m heist, 2016.