The Bangladesh Bank robbery, also known colloquially as the Bangladesh Bank cyber heist, was a theft that took place in February 2016. Thirty-five fraudulent instructions were issued by security hackers via the SWIFT network to illegally transfer close to US$1 billion from the Federal Reserve Bank of New York account belonging to Bangladesh Bank, the central bank of Bangladesh. Five of the thirty-five fraudulent instructions were successful in transferring US$101 million, with US$81 million traced to the Philippines and US$20 million to Sri Lanka. The Federal Reserve Bank of New York blocked the remaining thirty transactions, amounting to US$850 million, due to suspicions raised by a misspelled instruction. As of 2025, only US$15 million out of US$81 million transferred to the Philippines has been recovered with little progress in recovering the remaining US$66 million, and all the money transferred to Sri Lanka has since been recovered. Most of the money transferred to the Philippines went to four personal accounts, held by single individuals, and not to companies or corporations.
Like many other national banks, Bangladesh Bank, the central bank of Bangladesh, maintains an account with the Federal Reserve Bank of New York to deposit, maintain, and transfer foreign currency reserve of Bangladesh. The foreign currency reserve of Bangladesh, a growing economy, often reaches multiple billions of US dollars. As of September 2020, Bangladesh has a foreign currency reserve of US$39 billion. The Society for Worldwide Interbank Financial Telecommunication (SWIFT) network is used to communicate with the bank holding the foreign exchange account in order to withdraw, transfer, or deposit the currency.
The 2016 cyber-attack on the Bangladesh Bank was not the first attack of its kind. In 2013, the Sonali Bank of Bangladesh was also successfully targeted by hackers who were able to remove US$250,000.
In both cases, the perpetrators were suspected to have been aided by insiders within the targeted banks, who assisted in taking advantage of weaknesses in the banks' access to the SWIFT global payment network.
Capitalizing on weaknesses in the security of the Bangladesh central bank, including the possible involvement of some of its employees, perpetrators attempted to steal US$951 million from the Bangladesh Bank's account with the Federal Reserve Bank of New York. The theft happened sometime between 4–5 February 2016, when Bangladesh Bank's offices were closed for the weekend.
The perpetrators managed to compromise Bangladesh Bank's computer network, observe how transfers are done, and gain access to the bank's credentials for payment transfers. They used these credentials to authorise about three dozen requests to the Federal Reserve Bank of New York. These requests were made to transfer funds to accounts in the Philippines and Sri Lanka.
Thirty transactions worth US$851 million were flagged by the banking system for staff review, but five requests were granted; US$20 million to Sri Lanka (later recovered), and US$81 million lost to the Philippines, entering the Southeast Asian country's banking system on 5 February 2016. This money was laundered through casinos and some later transferred to Hong Kong.
According to a report published in The Straits Times, investigators suspected that the criminals used the Dridex malware for the attack.
Funds diverted to the Philippines
The money transferred to the Philippines was deposited in five separate accounts with the Rizal Commercial Banking Corporation (RCBC); the accounts were later found to be under fictitious identities. The funds were then transferred to a foreign exchange broker to be converted to Philippine pesos, returned to the RCBC and consolidated in an account of a Chinese-Filipino businessman; the conversion was made from 5 to 13 February 2016. It was also found that the four U.S. dollar accounts involved were opened at the RCBC as early as 15 May 2015, remaining untouched until 4 February 2016, the date the transfer from the Federal Reserve Bank of New York was made.
On 8 February 2016, during the Chinese New Year, Bangladesh Bank informed RCBC through SWIFT to stop the payment, refund the funds, and to "freeze and put the funds on hold" if the funds had already been transferred. Chinese New Year is a non-working holiday in the Philippines and a SWIFT message from Bangladesh Bank containing similar information was received by RCBC only a day later. By this time, a withdrawal amounting to about US$58.15 million had already been processed by RCBC's Jupiter Street (in Makati City) branch.
On 16 February, the Governor of Bangladesh Bank requested Bangko Sentral ng Pilipinas' assistance in the recovery of its US$81 million funds, saying that the SWIFT payment instructions issued in favor of RCBC on 4 February 2016, were fraudulent.
Attempted fund diversion to Sri Lanka
The US$20 million transfer to Sri Lanka was intended by hackers to be sent to the Shalika Foundation, a Sri Lanka-based private limited company. The hackers misspelled "Foundation" in their request to transfer the funds, spelling the word as "Fandation" or "Fundation". This spelling error gained suspicion from Deutsche Bank, a routing bank which put a halt to the transaction in question after seeking clarifications from Bangladesh Bank.
Sri Lanka-based Pan Asia Bank initially took notice of the transaction, with one official noting the transaction as too big for a country like Sri Lanka. Pan Asia Bank was the one which referred the anomalous transaction to Deutsche Bank. The Sri Lankan funds have been recovered by Bangladesh Bank.
Initially, Bangladesh Bank was uncertain if its system had been compromised. The governor of the central bank engaged World Informatix Cyber Security, a US-based firm, to lead the security incident response, vulnerability assessment and remediation. World Informatix Cyber Security brought in the forensic investigation company Mandiant, for the investigation. These investigators found "footprints" and malware of hackers, which suggested that the system had been breached. The investigators also said that the hackers were based outside Bangladesh. An internal investigation has been launched by Bangladesh Bank regarding the case.
The Bangladesh Bank's forensic investigation found out that malware was installed within the bank's system sometime in January 2016, and gathered information on the bank's operational procedures for international payments and fund transfers.
The investigation also looked into an unsolved 2013 hacking incident at the Sonali Bank, wherein US$250,000 was stolen by still unidentified hackers. According to reports, just as in the 2016 central bank hack, the theft also used fraudulent fund transfers using the SWIFT global payment network. The incident was treated by Bangladeshi police authorities as a cold-case until the suspiciously similar 2016 Bangladesh central bank robbery.