Get 40% Off
🚨 Volatile Markets? Find Hidden Gems for Serious Outperformance
Find Stocks Now

How a hacker's typo helped stop a billion dollar bank heist

Published 03/10/2016, 04:53 PM
© Reuters. Commuters pass by the front of the Bangladesh central bank building in Dhaka

By Serajul Quadir

DHAKA (Reuters) - A spelling mistake in an online bank transfer instruction helped prevent a nearly $1 billion heist last month involving the Bangladesh central bank and the New York Federal Reserve, banking officials said.

Unknown hackers still managed to get away with about $80 million, one of the largest known bank thefts in history.

The hackers breached Bangladesh Bank's systems and stole its credentials for payment transfers, two senior officials at the bank said. They then bombarded the Federal Reserve Bank of New York with nearly three dozen requests to move money from the Bangladesh Bank's account there to entities in the Philippines and Sri Lanka, the officials said.

Four requests to transfer a total of about $81 million to the Philippines went through, but a fifth, for $20 million, to a Sri Lankan non-profit organization was held up because the hackers misspelled the name of the NGO, Shalika Foundation.

Hackers misspelled "foundation" in the NGO's name as "fandation", prompting a routing bank, Deutsche Bank (DE:DBKGn), to seek clarification from the Bangladesh central bank, which stopped the transaction, one of the officials said.

There is no NGO under the name of Shalika Foundation in the list of registered Sri Lankan non-profits. Reuters could not immediately find contact information for the organization.

Deutsche Bank declined to comment.

At the same time, the unusually large number of payment instructions and the transfer requests to private entities - as opposed to other banks - raised suspicions at the Fed, which also alerted the Bangladeshis, the officials said.

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

The details of how the hacking came to light and was stopped before it did more damage have not been previously reported. Bangladesh Bank has billions of dollars in a current account with the Fed, which it uses for international settlements.

The transactions that were stopped totaled $850-$870 million, one of the officials said.

Last year, Russian computer security company Kaspersky Lab said a multinational gang of cyber criminals had stolen as much as $1 billion from as many as 100 financial institutions around the world in about two years.

Iraqi dictator Saddam Hussein's son Qusay took $1 billion from Iraq's central bank on the orders of his father on the day before coalition forces began bombing the country in 2003, American and Iraqi officials have said. In 2007, guards at the Dar Es Salaam bank in Baghdad made off with $282 million.

MONEY RECOVERED

Bangladesh Bank has said it has recovered some of the money that was stolen, and is working with anti-money laundering authorities in the Philippines to try to recover the rest.

A bank spokesman could not be reached for comment late on Thursday.

The recovered funds refer to the Sri Lanka transfer, which was stopped, one of the officials said.

Initially, the Sri Lankan transaction reached Pan Asia Banking Corp (CM:PABC), which went back to Deutsche Bank for more verification because of the unusually large size of the payment, a Pan Asia official said. "The transaction was too large for a country like us," the official said. "Then (Deutsche) came back and said it was a suspect transaction." A Pan Asia spokesman could not immediately be reached for comment.

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

The dizzying, global reach of the heist underscores the growing threat of cyber crime and how hackers can find weak links in even the most secure computer networks.

More than a month after the attack, Bangladeshi officials are scrambling to trace the money, shore up security and identify weaknesses in their systems. They said there is little hope of ever catching the hackers, and it could take months before the money is recovered, if at all.

FireEye Inc's (O:FEYE) Mandiant forensics division is helping investigate the heist, people familiar with the matter told Reuters on Thursday.

The sources said Silicon Valley-based FireEye, which has investigated some of the biggest cyber thefts on record, was brought in by World Informatix, a smaller firm that is advising Bangladesh Bank on the investigation.

Security experts said the perpetrators had deep knowledge of the Bangladeshi institution's internal workings, likely gained by spying on bank workers.

The Bangladesh government, meanwhile, is blaming the Fed for not stopping the transactions earlier. Finance Minister Abul Maal Abdul Muhith told reporters on Tuesday that the country may resort to suing the Fed to recover the money. 

"The Fed must take responsibility," he said.

The New York Fed has said its systems were not breached, and it has been working with the Bangladesh central bank since the incident occurred.

The hacking of Bangladesh Bank happened sometime between Feb. 4-5, over the Bangladeshi weekend, which falls on a Friday, the officials said. The bank's offices were shut.

Initially, the central bank was not sure if its system had been breached, but cyber security experts brought in to investigate found hacker "footprints" that suggested the system had been compromised, the officials said.

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

These experts could also tell that the attack originated from outside Bangladesh, they said, adding the bank is looking into how they got into the system and an internal investigation is ongoing.

The bank suspects money sent to the Philippines was further diverted to casinos there, the officials said. 

The Philippine Amusement and Gaming Corp, which oversees the gaming industry, said it has launched an investigation. The country's anti-money laundering authority is also working on the case.

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.