Hackers stole $9M from Ecuadorian Banco del Austro in 2015 by sending Wells Fargo SWIFT messages to transfer funds, court documents show
Context & Ripple Effects
This disclosure lands mid-arc: researchers had already tied an $81M theft from Bangladesh's central bank to malware subverting the SWIFT messaging network, and SWIFT responded with a warning of another commercial-bank attack it framed as part of a wider, highly adaptive campaign targeting banks.
The court documents now push the timeline back: Banco del Austro was hit in 2015, before Bangladesh, with fraudulent transfer messages sent through its US correspondent, Wells Fargo. That makes the Ecuador case evidence for SWIFT's campaign theory — and it shows the playbook reaching smaller banks through their correspondent relationships, not just central banks.
First-order effects
- Banco del Austro is out $9M, and the court documents place Wells Fargo in the frame as the correspondent whose SWIFT channel carried the fraudulent transfers — immediately raising questions about its verification obligations to a smaller client bank.
- SWIFT's patch-and-warn posture now covers a confirmed additional victim, hardening its 'adaptive campaign' warning from precaution into documented pattern.
Second-order effects
- Correspondent banks face pressure to add out-of-band confirmation before executing large third-party transfers, because validly formatted SWIFT messages proved insufficient protection in both heists.
- Smaller banks with weak endpoint security — the Bangladesh breach traced to second-hand $10 switches and no firewall ([[a:868521]]) — become the preferred entry points, pushing them toward infrastructure upgrades or outsourced security they previously skipped.
Third-order effects
- If the pattern holds, SWIFT membership stops functioning as a shorthand for safety, and liability fights like this court case will decide whether fraud losses executed over authentic-looking messages land on the victim bank, the correspondent, or the network operator.
- Regulators gain a case file for treating interbank messaging security as shared systemic infrastructure rather than each institution's private cyber-hygiene problem.
The trend: Bank thieves are moving upstream from individual endpoints to the interbank messaging layer itself, forcing SWIFT and correspondent banks to rebuild trust around more than authenticated member messages.