Investigation into SWIFT breach expands to 12 more banks; Symantec corroborates BAE's report that hackers used code similar to North Korean Sony hack
Symantec becomes the second firm to link the hack to the Sony Pictures attack. — The investigation into the attempted $1 billion electronic heist …
Context & Ripple Effects
The arc here runs from theft to campaign to attribution. In April, researchers traced an $81M subversion of SWIFT's interbank messaging at Bangladesh's central bank — part of an attempted $1 billion heist — and SWIFT shipped a patch. By mid-May, SWIFT itself was warning of further attacks on commercial banks as part of what it called a highly adaptive campaign.
Today's development adds scale and a suspect: the investigation now covers 12 more banks, and Symantec has independently corroborated BAE's finding that the attackers used code resembling the toolset from the 2014 Sony Pictures intrusion — which earlier coverage had already flagged for its worm-based delivery despite slapdash construction.
First-order effects
- The 12 newly implicated banks move from bystanders to incident respondents overnight, facing forensic sweeps of their SWIFT terminal endpoints while SWIFT's April patch becomes their first line of defense.
- With Symantec confirming BAE's code analysis, two independent vendors now point at the same actor, hardening the North Korean attribution from one firm's claim into a convergent finding.
Second-order effects
- Member banks' confidence shifts from trusting SWIFT's network to auditing their own endpoints — security spend and scrutiny concentrate on the local machines that submit messages, the exact weakness the Bangladeshi heist exploited.
- Rival security vendors are pulled into the attribution race, since whoever publishes the next corroborating sample shapes how regulators and SWIFT members frame the threat.
Third-order effects
- If state-linked tooling keeps surfacing across both a media company and a dozen-plus banks, bank cyber-heists get treated less as crime and more as state action — pulling SWIFT security into the domain of sanctions and diplomatic response.
- A shared, enforced security baseline across SWIFT's member institutions becomes the likely structural outcome, converting a cooperative messaging network into one with mandatory audit obligations.
The trend: Financial messaging infrastructure is becoming a contested battlefield where reused state-grade malware forces banks, vendors, and SWIFT itself toward centralized security mandates.