$81M hack of Bangladesh central bank made possible by second-hand $10 switches linking computers connected to SWIFT global payment network, and no firewall
Context & Ripple Effects
The forensic picture has been assembling for weeks: the Wall Street Journal first reported in March that hackers had tried to move nearly $1B out of Bangladesh Bank and settled for $81M. This report supplies the why — the bank's SWIFT-connected machines sat on second-hand $10 network switches with no firewall between them and the global payments network.
Two days later, researchers established that the thieves used malware to subvert the SWIFT messaging system itself, forcing SWIFT to ship a patch, and SWIFT then warned customers the Bangladesh case was not isolated. The story matters because it reframes the breach from one bank's negligence into a template for attacking the plumbing of cross-border payments.
First-order effects
- Bangladesh Bank must rebuild its payments infrastructure from the switch layer up — replacing commodity hardware and segmenting its SWIFT terminals behind firewalls before it can trust the connection again.
- SWIFT is immediately on the defensive: it has released a patch to member institutions and now carries the reputational burden of proving its messaging layer wasn't the weak point.
Second-order effects
- Every bank running SWIFT terminals faces pressure to audit endpoint hardware and network segregation, since the attackers demonstrated that a single poorly defended member exposes the whole network's trust model.
- SWIFT's warnings about additional commercial-bank attacks force it into an ongoing disclosure posture — each new incident erodes the assumption that membership in the network implies minimum security competence.
Third-order effects
- If the campaign keeps expanding, interbank messaging likely shifts from trust-by-default in member institutions toward centrally enforced security standards and monitoring at SWIFT endpoints — making compliance a condition of network access rather than a courtesy.
- Central banks in emerging markets with legacy, under-segmented payments infrastructure become the preferred target class, pushing reserve-holding institutions to treat payment-rail security as a sovereign-risk issue.
The trend: Cross-border payment networks are being pulled from a model where each member bank secures its own endpoint toward one where the network operator imposes and verifies security standards, because attackers now target the rails themselves rather than individual accounts.