Other Research Assessment

Country
Bangladesh

Source
Wikipedia article

Title
Bangladesh Bank robbery

About
Hackers stole $101 million from Bangladesh Bank in a robbery in February 2016. Malicious code was introduced remotely to bank servers which allowed them to process and authorise fraudulent transactions via the banks SWIFT payment system. 35 fraudulent instructions were issued to transfer close to US $1 billion from the Federal Reserve Bank of NY account belonging to Bangladesh Bank. 5 of 30 transactions were successful in transferring $101 million, $20 million traced to Sri Lanka and $81 million to Philippines.

Key findings
Several agencies investigated the incident with assistance from police in Philippines, Japan, Sri Lanka & China and US FBI. Initially fingers were pointed at the SWIFT technicians introducing security holes in the banks network while connecting SWIFT to the RTGS. Suspicious activities of the staff at the Philippines Rizal Commercial Banking Corp (RCBC) were noted as they acted with lightning speed to launder the money out of the bank and into the gambling industry in complete violation of Philippines anti-money laundering laws. 11 months of investigating and still no suspects arrested, but suggested that hackers were assisted by bank staff. Questions over why a password token protecting the SWIFT international transactions network at Bangladesh Bank was left inserted in the SWIFT server months leading up to the heist. This should be removed and locked at end of each business day. Failure to remove this token allowed hackers to enter the system when it was not being monitored. No evidence to back this up and no staff were charged and the bank authorities suggested that the bank officials were guilty of nothing more than negligence. In Jan 2019 The bank manager of Philippines bank involved was found guilty of money-laundering the heist money.

Website
https://en.wikipedia.org/wiki/Bangladesh_Bank_robbery