In February 2016, attackers tried to steal nearly one billion dollars from a central bank without ever entering a building. They failed to take it all — but they got away with $81 million, by exploiting weaknesses that exist in ordinary businesses too. Here is how the attack unfolded, and the defensive lessons every organisation can take from it.

What happened

The target was Bangladesh Bank, the country’s central bank, which held reserves in an account at the Federal Reserve Bank of New York. Over one carefully chosen weekend, attackers used the bank’s own access to the SWIFT interbank messaging network to issue 35 fraudulent payment orders totalling roughly $951 million. Most were flagged and stopped, but five went through — $20 million to Sri Lanka (later recovered) and $81 million to accounts in the Philippines, where it was laundered through casinos. Researchers later attributed the operation to a sophisticated state-linked group.

The anatomy of the attack — phase by phase

What makes this case so instructive is that the theft was the last step, not the first. The attackers spent months inside the network before moving any money. Understanding these phases is how businesses learn to break the chain early.

Phase 1 — Reconnaissance. Long before the heist, the attackers researched the bank — its systems, its people, and how it used SWIFT. Patient study of a target is the quiet first stage of almost every major breach.
Phase 2 — The phishing foothold. Investigators believe the entry point was a phishing email: a seemingly harmless attachment that, once opened by an employee, installed malware. One click gave the attackers their first foothold.
Phase 3 — Lateral movement. From that single machine, they moved sideways through the network over weeks, quietly reaching the servers connected to the SWIFT payment terminal.
Phase 4 — Credential theft. They captured the operator credentials needed to create payment messages. With legitimate logins, their fraudulent transfers looked like normal bank activity.
Phase 5 — Timing the strike. They launched on a Thursday night, the start of Bangladesh’s weekend, exploiting time-zone gaps so that by the time anyone noticed, days had passed.
Phase 6 — Covering tracks. Custom malware tampered with confirmation messages so the fraudulent transfers would not show up immediately, buying even more time.

What actually stopped them

Only $81 million left instead of $951 million — and partly by luck. Many orders were held for manual review, and one large transfer was reportedly halted after a spelling mistake in a recipient name raised a flag. Human review and simple sanity-checks caught what automated systems let through.

The defensive lessons for every business

You don’t need a billion dollars in reserves to face the same attack pattern — the techniques scale down to any company with a bank account and email:

  • Phishing (Phase 2): train staff to recognise suspicious attachments and use email filtering. The entire heist began with one opened file.
  • Lateral movement (Phase 3): segment networks so a single compromised computer can’t reach critical systems.
  • Credential theft (Phase 4): enable multi-factor authentication everywhere — stolen passwords alone should never be enough.
  • Detection (Phases 5–6): monitor for unusual activity and keep an independent record of transactions.
  • Human review: require a second person to approve high-value actions. It was manual checks, not machines, that saved the bulk of the money.
Important: this article explains a widely documented incident to help organisations defend themselves. It describes attack patterns, not methods — the goal is prevention, not instruction.

How InfraBit helps businesses stay protected

The Bangladesh Bank heist started with one compromised computer and stolen credentials. The same two weaknesses — phishing and unprotected logins — are behind most breaches at ordinary businesses too.

InfraBit’s cybersecurity services help small and mid-sized businesses close exactly these gaps — from website and system hardening to guidance on access controls and staff awareness. You can also run a free scan of your own website with the InfraBit Website Security Scanner to spot weaknesses before attackers do. And every InfraBit platform is built with security in mind, including encrypted credential storage and role-based access.

Talk to our security team →