ECONOMY & WORK
MONEY 101
NEWS
PERSONAL FINANCE
NET WORTH
About Us Contact Us Privacy Policy Terms of Use DMCA Opt-out of personalized ads
© Copyright 2023 Market Realist. Market Realist is a registered trademark. All Rights Reserved. People may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.
MARKETREALIST.COM / NEWS

Few hackers almost stole $1 billion from a bank. They were stopped because of a simple typo

While five transactions were worth about $80 million, one payment order worth $20 million didn't clear.
UPDATED OCT 1, 2024
Image Source: Getty Images | Photo by boonchai wedmakawand
Image Source: Getty Images | Photo by boonchai wedmakawand

A simple spelling mistake in an online bank transfer instruction prevented a billion-dollar heist. Back in 2016, the central bank of Bangladesh was hit by a cyber attack that directly impacted the New York Federal Reserve. While a series of lucky coincidences saved the banks hundreds of millions of dollars, the hackers did manage to steal $80 million, in one of the most daring bank heists in history, as per Reuters. 

Marriner S. Eccles Federal Reserve Board Building | Getty Images | Photo By Raymond Boyd/Michael Ochs Archives
Marriner S. Eccles Federal Reserve Board Building | Getty Images | Photo By Raymond Boyd/Michael Ochs Archives

In February 2016, Zubair Bin Huda, a director at Bangladesh’s central bank, realized that the bank's software 'Swift' had crashed. According to a detailed report from the New York Times,  the Brussels-based electronic network which was used by 11,000 financial institutions in over 200, was primarily used to dispatch the payment orders and manage communication. 

Chittagong City Skyline | Getty Images |  Stock photo
Chittagong City Skyline | Getty Images | Stock photo

When Huda finally got the software to run, he found that an employee of The New York Fed had written to the bank asking for clarification about 46 payment instructions received over the past 24 hours. The transactions totaled nearly $1 billion. It was highly unusual as the bank never made such large payment orders before, especially over a weekend.

Upon looking further, the bank officials learned that they had been under a cyber attack and the Swift system was compromised. This was shocking as the Swift was considered a titan and an unbreachable software. Hackers issued over three dozen payment orders for bank accounts and institutions located across Sri Lanka, the Philippines, and more. 



 

However, out of the 46 payment requests, only 5 went through. Transactions worth over $850 million were held up after spelling and naming errors were found in some of the payment orders.

While five transactions were worth about $80 million, one payment order worth a $20 million deposit for the Shalika Foundation, an agricultural NGO in Sri Lanka didn't clear. This was primarily due to a spelling error made in the word 'foundation'. The hackers accidentally misspelled the word as "fandation" which was noticed by the Deutsche Bank which had a financial relationship with the bank in Sri Lanka. The bank sought clarification from the Central Bank of Bangladesh, halting the payment, as per Reuters. 

Representative image of a woman's hand typing on computer keyboard | Getty Images | Stock photo
Representative image of a woman's hand typing on computer keyboard | Getty Images | Stock photo

The next series of payments totaling about $850 to $870 million were stopped by another coincidence. The payments were for individual accounts at the Jupiter branch of Rizal Commercial Banking Corporation near Manila. They didn’t clear as the automated system flagged the word “Jupiter,” which matched the name of a totally different business that was blacklisted for circumventing sanctions against Iran, per The Times report. Thus, these two lucky coincidences prevented the bank from losing nearly $900 million more. 

While nothing much has been shared in the media about the perpetrators of the heist, The Times reported that Bangladesh Bank hired a US cybersecurity firm FireEye, to investigate the matter. The firm reportedly signed a nondisclosure agreement with the bank but some details of their investigation leaked. 



 

The attack had similarities to previous cyber attacks like the 2014, Sony Pictures hack, “Dark Seoul,” a March 2013 hack that targeted three South Korean banks, and the WannaCry ransomware attack in May 2017.  All of these attacks bore the markings of the "Lazarus Group", a shady organization that U.S. intelligence experts claim to be affiliated with North Korea.

MORE ON MARKET REALIST
The Amazon house now stands as a symbol of unconventional homeownership in the digital age, leaving viewers both fascinated and entertained.
14 hours ago
Through luck, quick thinking, and due dilligence, the woman claimed she got to keep the money.
14 hours ago
The man didn't provide too many details about the incident mentioned in the lawsuit.
1 day ago
Cross isn't the first person to pick the same number for multiple tickets, but won big with more than a hundred of them.
1 day ago
Cavanagh first started collecting credit cards as part of a bet, but didn't stop even after winning.
1 day ago
The mother decided to look up the cup and saucer set online since it appeared to be something fancy.
1 day ago
The former US President is known for visiting the fast food chain's outlets for campaigning.
1 day ago
The students were amused to find out about the unusual test that their professor had come up with.
2 days ago
Even after he won, the man had no idea about the amount that he was going to walk away with.
2 days ago
There are six different packages for donating to the campaign but it isn't clear what donors get.
2 days ago
The seller had accurately estimated the rock's value but the buyer argued that he also had to sell it forward.
2 days ago
The former president kept repeating the claim, while it was later revealed that he got a lot more than a million dollars.
3 days ago
The heated exchange triggered mixed reactions from social media users before it was deleted.
3 days ago
He even fetched water from the ocean to make salt from scratch and milked a cow himself to procure butter and cheese.
3 days ago
There's still no record of how many such coins might still be in circulation or sitting in someone's coin collection.
4 days ago
Durana Elmi, co-founder and COO of Cymbiotika, has been recognized for her outstanding global business achievements in the 2024 TITAN Women In Business Awards.
4 days ago
Her comments came at a time when several CEOs were slammed for insensitive comments about layoffs.
4 days ago
The expert who examined the helmet using an X-ray gun was bowled over by what he discovered.
4 days ago
The World War II veteran had no family to take care of him, hence the staff stepped forward.
5 days ago
He had no car or furniture, and his mobile home was almost empty except for a TV.
5 days ago