How North Korean hackers nearly stole $951M from Bangladesh Bank's New York Fed account in 2016, only to be stopped at the last moment after transferring $81M
Context & Ripple Effects
The story runs in three beats across this coverage. In March 2016 reporting, hackers had tried to move nearly $1B out of Bangladesh Bank's account at the New York Fed and got away with $81M before the transfer chain was cut off — a near-miss only because the remaining orders were caught mid-flight. By April, forensics traced the entry point to embarrassingly cheap infrastructure: second-hand $10 switches connecting the bank's SWIFT-linked computers, with no firewall in front of them.
The deeper finding was that the attackers did not break SWIFT itself — they used malware to subvert the interbank messaging layer, forcing SWIFT to ship an emergency patch to its member banks. The 2020 book excerpt from "The Hacker and the State" reframes all of it as one campaign in North Korea's systematic pursuit of banks worldwide, which is why a five-year-old heist is still worth retelling.
First-order effects
- Bangladesh Bank is permanently short $81M from its New York Fed account, with the bulk of the $951M attempt blocked only because downstream transfers were stopped in time.
- SWIFT must respond operationally: once researchers confirm its messaging network was subverted by malware rather than breached directly, it releases a patch across its member-bank software.
Second-order effects
- Every central bank running legacy SWIFT terminals now has to audit its own setup — the disclosure that cheap, unfirewalled, second-hand gear sat on a national reserve account turns compliance into an urgent procurement question for Bangladesh Bank's peers.
- For the New York Fed, the incident puts its correspondent-settlement plumbing under scrutiny, sharpening institutional appetite for alternatives such as its later work with major banks on tokenized-deposit pilots for wholesale payments.
Third-order effects
- If a state's hackers can reach reserve accounts through one weak national node, cross-border settlement stops being purely financial plumbing and becomes a shared security problem that regulators and central banks must treat as systemic.
- The pattern points toward hardening or replacing legacy messaging rails — SWIFT patches now, and experiments with tokenized wholesale payments later — because trust in the existing stack erodes each time a nation-state actor gets this close.
The trend: State-sponsored attacks on interbank payment rails are steadily pushing central banks to harden legacy SWIFT infrastructure and test alternative settlement mechanisms like tokenized deposits.