Hackers stole $9M from Ecuadorian Banco del Austro in 2015 by sending Wells Fargo SWIFT messages to transfer funds, court documents show
Cybercriminals stole $9 million in 2015 from an Ecuador bank in attack similar to one against Bangladesh's central bank about a year later
Context & Ripple Effects
Court documents show the Banco del Austro theft was carried out through fraudulent SWIFT messages sent via Wells Fargo in 2015 — months before researchers tied malware to the $81M subversion of SWIFT at Bangladesh's central bank. What looked like a one-off is now the second confirmed strike in the same playbook.
The timing matters because SWIFT had already flagged a wider, highly adaptive campaign targeting commercial banks, and reporting on Bangladesh traced the breach to second-hand $10 switches and no firewall on machines connected to the network — meaning the weak point is member banks' own infrastructure, not SWIFT's core.
First-order effects
- Banco del Austro gains a litigation path to recover funds from intermediaries in the transfer chain, with Wells Fargo's role as the correspondent bank that relayed the fraudulent messages now under legal scrutiny.
- Every bank using SWIFT correspondent relationships must re-audit who can originate transfer messages and what verification exists before funds move.
Second-order effects
- Correspondent banks like Wells Fargo face pressure to add out-of-band confirmation for high-value transfers, since they bear reputational exposure when their rails carry stolen money.
- SWIFT's patch-and-warn posture gives way to demands that it police member endpoint security, because two confirmed breaches make 'your network, our problem' untenable.
Third-order effects
- If the pattern holds, interbank messaging consolidates around mandatory baseline cyber-hygiene for connected institutions — effectively turning SWIFT membership into a security certification, with regulators treating lax endpoint controls as systemic risk rather than each bank's private problem.
The trend: Bank hacking is shifting from opportunistic breaches to a coordinated campaign against the weakest endpoints of the SWIFT network, forcing the messaging cooperative itself into the role of security enforcer.