In February 2016, attackers tried to steal nearly one billion dollars from a central bank without ever entering a building. They failed to take it all — but they got away with $81 million, by exploiting weaknesses that exist in ordinary businesses too. Here is how the attack unfolded, and the defensive lessons every organisation can take from it.
What happened
The target was Bangladesh Bank, the country’s central bank, which held reserves in an account at the Federal Reserve Bank of New York. Over one carefully chosen weekend, attackers used the bank’s own access to the SWIFT interbank messaging network to issue 35 fraudulent payment orders totalling roughly $951 million. Most were flagged and stopped, but five went through — $20 million to Sri Lanka (later recovered) and $81 million to accounts in the Philippines, where it was laundered through casinos. Researchers later attributed the operation to a sophisticated state-linked group.
The anatomy of the attack — phase by phase
What makes this case so instructive is that the theft was the last step, not the first. The attackers spent months inside the network before moving any money. Understanding these phases is how businesses learn to break the chain early.
What actually stopped them
Only $81 million left instead of $951 million — and partly by luck. Many orders were held for manual review, and one large transfer was reportedly halted after a spelling mistake in a recipient name raised a flag. Human review and simple sanity-checks caught what automated systems let through.
The defensive lessons for every business
You don’t need a billion dollars in reserves to face the same attack pattern — the techniques scale down to any company with a bank account and email:
- Phishing (Phase 2): train staff to recognise suspicious attachments and use email filtering. The entire heist began with one opened file.
- Lateral movement (Phase 3): segment networks so a single compromised computer can’t reach critical systems.
- Credential theft (Phase 4): enable multi-factor authentication everywhere — stolen passwords alone should never be enough.
- Detection (Phases 5–6): monitor for unusual activity and keep an independent record of transactions.
- Human review: require a second person to approve high-value actions. It was manual checks, not machines, that saved the bulk of the money.
How InfraBit helps businesses stay protected
The Bangladesh Bank heist started with one compromised computer and stolen credentials. The same two weaknesses — phishing and unprotected logins — are behind most breaches at ordinary businesses too.
InfraBit’s cybersecurity services help small and mid-sized businesses close exactly these gaps — from website and system hardening to guidance on access controls and staff awareness. You can also run a free scan of your own website with the InfraBit Website Security Scanner to spot weaknesses before attackers do. And every InfraBit platform is built with security in mind, including encrypted credential storage and role-based access.