How A Hacker’s Typo Helped Stop A Billion Dollar Bank Heist

Reuters

A spelling mistake in an online bank transfer instruction helped prevent a nearly $1 billion heist last month involving the Bangladesh central bank and the New York Fed, banking officials said.

Unknown hackers still managed to get away with about $80 million, one of the largest known bank thefts in history.

The hackers breached Bangladesh Bank’s systems and stole its credentials for payment transfers, two senior officials at the bank said. They then bombarded the Federal Reserve Bank of New York with nearly three dozen requests to move money from the Bangladesh Bank’s account there to entities in the Philippines and Sri Lanka, the officials said.

Four requests to transfer a total of about $81 million to the Philippines went through, but a fifth, for $20 million, to a Sri Lankan non-profit organisation was held up because the hackers misspelled the name of the NGO, Shalika Foundation.

Hackers misspelled “foundation” in the NGO’s name as “fandation”, prompting a routing bank, Deutsche Bank, to seek clarification from the Bangladesh central bank, which stopped the transaction, one of the officials said.

There is no NGO under the name of Shalika Foundation in the list of registered Sri Lankan non-profits. Reuters could not immediately find contact information for the organization.

Deutsche Bank declined to comment.

At the same time, the unusually high number of payment instructions and the transfer requests to private entities – as opposed to other banks – raised suspicions at the Fed, which also alerted the Bangladeshis, the officials said.

The details of how the hacking came to light and was stopped before it did more damage have not been previously reported. Bangladesh Bank has billions of dollars in a current account with the Fed, which it uses for international settlements.

The transactions that were stopped totalled $850-$870 million, one of the officials said.

You might also like
HBO’s Harry Potter Reboot Announces First Cast Members – And It’s Already Raising Eyebrows
Prada Agrees To Buys Versace for $1.3B in Major Italian Fashion Merger
The Clock Stops For No One (Except in Bihar, Apparently)
Jaipur Isn’t an Accident. It’s Proof That Drunk Driving in India Is Practically a Free Pass
De-extinction Drama: Dire Wolves Are Back, and We’re Not Sure Whether to Celebrate or Hide!
“Excuse Me” Is Now a Crime — Women & Baby Attacked Over Two English Words