/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

How North Korean hackers nearly stole $951M from Bangladesh Bank's New York Fed account in 2016, only to be stopped at the last moment after transferring $81M

BBC

Context & Ripple Effects

The story runs in three beats across this coverage. In March 2016 reporting, hackers had tried to move nearly $1B out of Bangladesh Bank's account at the New York Fed and got away with $81M before the transfer chain was cut off — a near-miss only because the remaining orders were caught mid-flight. By April, forensics traced the entry point to embarrassingly cheap infrastructure: second-hand $10 switches connecting the bank's SWIFT-linked computers, with no firewall in front of them.

The deeper finding was that the attackers did not break SWIFT itself — they used malware to subvert the interbank messaging layer, forcing SWIFT to ship an emergency patch to its member banks. The 2020 book excerpt from "The Hacker and the State" reframes all of it as one campaign in North Korea's systematic pursuit of banks worldwide, which is why a five-year-old heist is still worth retelling.

First-order effects

  • Bangladesh Bank is permanently short $81M from its New York Fed account, with the bulk of the $951M attempt blocked only because downstream transfers were stopped in time.
  • SWIFT must respond operationally: once researchers confirm its messaging network was subverted by malware rather than breached directly, it releases a patch across its member-bank software.

Second-order effects

  • Every central bank running legacy SWIFT terminals now has to audit its own setup — the disclosure that cheap, unfirewalled, second-hand gear sat on a national reserve account turns compliance into an urgent procurement question for Bangladesh Bank's peers.
  • For the New York Fed, the incident puts its correspondent-settlement plumbing under scrutiny, sharpening institutional appetite for alternatives such as its later work with major banks on tokenized-deposit pilots for wholesale payments.

Third-order effects

  • If a state's hackers can reach reserve accounts through one weak national node, cross-border settlement stops being purely financial plumbing and becomes a shared security problem that regulators and central banks must treat as systemic.
  • The pattern points toward hardening or replacing legacy messaging rails — SWIFT patches now, and experiments with tokenized wholesale payments later — because trust in the existing stack erodes each time a nation-state actor gets this close.

The trend: State-sponsored attacks on interbank payment rails are steadily pushing central banks to harden legacy SWIFT infrastructure and test alternative settlement mechanisms like tokenized deposits.

Discussion

  • @sisu_sanity Sisu Within on x
    “...the audacious hack was the culmination of years of methodical preparation by a shadowy team of hackers & middlemen across Asia, operating with the support of [North Korea]...” The Lazarus heist: How North Korea almost pulled off a billion-dollar hack https://www.bbc.com/...
  • @omarabdullah Omar Abdullah on x
    Reads like a season of ‘Money Heist’ - The Lazarus heist: How North Korea almost pulled off a billion-dollar hack https://www.bbc.co.uk/...
  • @geoffwhite247 Geoff White on x
    As North Korean hackers are accused of breaking into South Korea's nuclear research centre, check out my long read on Pyongyang's cyber activity and how its hackers are trained, with @newsjean for @BBCNews: https://www.bbc.co.uk/... #LazarusHeist
  • @bbcbusiness @bbcbusiness on x
    In 2016 North Korean hackers planned a $1bn raid on Bangladesh's national bank and came within an inch of success But how did they do it? https://www.bbc.co.uk/...
  • @dinodaizovi Dino A. Dai Zovi on x
    “It all started with a malfunctioning printer. It's just part of modern life, and so when it happened to staff at Bangladesh Bank they thought the same thing most of us do: another day, another tech headache. It didn't seem like a big deal.” https://www.bbc.com/...
  • @soutikbbc Soutik Biswas on x
    In 2016 North Korean hackers planned a $1bn raid on Bangladesh's national bank and came within an inch of success - it was only by a fluke that all but $81m of the transfers were halted. @geoffwhite247 and @newsjean report. https://www.bbc.com/... #NorthKorea