Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Hackers can steal money from a bank by breaking into its local IT environment, quietly learning how staff and payment systems operate, and then manipulating the systems that create or confirm payment instructions. The transfer may use a financial messaging network such as Swift without the network itself being hacked. After a fraudulent payment is sent, criminals may use intermediaries, front companies or other methods to move and disguise the proceeds.

How a bank attack can turn into a fraudulent payment

“APT-style” describes a persistent, targeted approach: attackers seek access, remain inside long enough to understand the target, and act when they think they can avoid notice. It does not prove that an attack was state-sponsored, nor does it identify one group as responsible for all bank thefts. The sources describe criminal operations as well as named groups, without establishing a single actor behind them all.

1. Gain access and study normal activity

Once inside a bank’s environment, attackers may observe how employees, systems and payments normally behave. Swift reported in 2019 that some attackers stayed quiet for weeks or months while learning a target’s patterns. Group-IB separately reported that the Cobalt group studied victim networks for about three weeks. Those are observations about particular investigations, not a timetable that applies to every attack.

2. Reach the systems involved in payments

An attacker who reaches a bank’s payment operations may try to manipulate the systems or processes used to generate instructions, or interfere with how confirmations are received and checked. In this kind of incident, the critical weakness can be in the customer bank’s local technology and operating procedures, even when a financial messaging service is involved in transmitting instructions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Send payments designed to look plausible

Attackers may adapt the timing, amount or destination of attempted payments to blend in with legitimate activity or exploit gaps in monitoring. In its 2019 findings, Swift said attackers shifted from issuing fraudulent payments outside business hours to acting during business hours. It also reported that most of the fraudulent transactions examined over the preceding 15 months used payment corridors not seen in the previous 24 months.

#1 Best Overall
Sale
2K Security Camera System, 5GHz&2.4GHz WiFi Solar Wireless Cameras for Home Security, Wire-free Installation, AI Detection, Two-way Audio, Mobile alerts, SD/Cloud Storage, Color Night Vision, 4 Packs
  • 100% Wireless Solar & Battery Powered: Enjoy true wireless installation with no outlets or messy cables. The detachable solar panel keeps your outdoor camera charged daily, 2 hours of daily sunlight to maintain 24/7 operation. while the built-in backup battery ensures reliable protection during cloudy days or bad weather.
  • 2K Color Night Vision with Smart Spotlight: Capture clear details day and night with crisp 2K resolution. The built-in spotlight enables full-color night vision when motion is detected, helping you clearly see people, packages, and activity even in low-light conditions.
  • 360° Pan-Tilt Coverage & IP65 Weatherproof: Remotely pan, tilt, and zoom through the app to monitor every corner of your property. Built with an IP65 waterproof rating, this wireless outdoor camera performs reliably in rain, snow, dust, and extreme temperatures year-round.
  • Smart Human Detection & Real-Time Two-Way Talk: Advanced PIR + AI human detection accurately identifies people—not just motion—reducing false alerts from animals or moving objects. Receive instant notifications and speak directly through two-way audio to greet visitors or deter unwanted activity from anywhere.
  • Flexible Storage Options & Alexa Compatible: Choose local 15x11x1mm MicroSD card recording (card not included) or optional cloud storage with no forced subscription. Easily view live feeds or play back recordings using Alexa voice commands for hands-free home monitoring.

Swift’s 2019 report found that four out of five investigated fraudulent transactions were issued to beneficiary accounts in East and South East Asia, and that approximately 70 per cent of attempted thefts were USD-based. It also reported a shift in individual attempted transaction values from more than US$10 million to between US$250,000 and US$2 million. These figures describe investigations in that report; they are not current global rates or a prediction of what a new attack will look like.

Was Swift hacked?

In the Bangladesh Bank case, Swift said its network, software and core messaging services were not compromised. Instead, attackers compromised the bank’s IT environment and reached systems where Swift payment instructions were generated and confirmations received. Gottfried Leibbrandt, Swift’s chief executive at the time, described the distinction this way: “In Bangladesh and the other cases, the thieves compromised the IT environment and worked their way to the bank systems where the Swift instructions are generated and the confirmations received.”

Swift is a financial messaging service; it is not the same thing as the bank’s entire payment environment. An incident involving instructions sent over Swift therefore does not, by itself, mean that Swift’s own network was breached. In the Bangladesh case, Swift’s account points to a compromise at the customer bank.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Bangladesh Bank: attempted, paid and traced amounts

The February 2016 Bangladesh Bank incident shows why the attempted amount must not be confused with money actually paid or with the amount reported as stolen. ISACA’s 2023 account says attackers sent 35 fraudulent instructions. Five transactions totaling US$101 million were authorized and paid; US$81 million was traced to the Philippines, while a US$20 million transaction to Sri Lanka was stopped and later retrieved.

Stage Amount What the figure means
Attempted Close to US$1 billion The approximate total targeted in the attempted theft, according to ISACA’s 2023 account.
Authorized and paid US$101 million The total for five transactions that were authorized and paid, according to ISACA.
Traced to the Philippines US$81 million The portion ISACA says was traced to the Philippines.
Stopped and later retrieved US$20 million The Sri Lanka transaction that was stopped and later retrieved, according to ISACA.

So “hackers stole nearly US$1 billion” is not an accurate description of the amount that left the bank: that was the approximate amount attempted. The cited account distinguishes US$101 million authorized and paid from the US$81 million traced to the Philippines and the US$20 million later retrieved.

Rank #2
ANNKE 3K Lite Wired Security Camera System Outdoor, 8X 2MP Cameras, 1TB HDD
  • AI Motion Detection 2.0 – Driving AI to the next level, human&vehicle detection and flexible detection area are more accurate than before. For quicker locating in crucial moments, human&vehicle smart searching in recordings offers you great help.
  • Tried-and-True Safe Guard – This one-stop security solution can work with TVI, AHD, CVI, CVBS & IP cameras, the kit includes 1080P cams. The 8CH 3K lite DVR can hook up with 1080P@30fps or 3K/5MP@20fps cams. Therefore, you can also DIY it with other cameras in your home.
  • Reliable 24/7 Continuous Recording – With a pre-installed 1TB HDD(Support up to 10TB HDD), providing 24/7 surveillance recording for you. Upgraded H.265+ saves more storage space and uses less bandwidth, recording videos longer and smoother viewing.
  • Smart Dual-Light Effectively Guard Your Home – This newly upgraded security system offers you a crisp full color night vision, IR mode and color night vision switch flexibly. Once detect intruders, immediate pushes pop up on your phone, securing your peace of mind day&night.
  • Color Night Vision & IP67 Weatherproof – Built-in IR lights and white lights, these cameras can see up to 100ft in B&W night vision, full-color night vision up to 66ft. Rated IP67, these wired cameras can brave all weather, and stand from cold to hot.

What happens to the money after a transfer?

A fraudulent payment is not the end of the operation. Swift and BAE Systems’ 2020 report describes criminal networks using money mules, front companies and cryptocurrency among the ways to move or obscure stolen funds. The report also notes possible exploitation of insiders or weak due diligence, and conversion of proceeds into assets such as property and jewellery. These are reported methods, not steps used in every case.

This is why detection cannot sit only with the network-security team. The joint report’s central implication is that cybersecurity, payment fraud and anti-money-laundering (AML) teams need to connect their information and response processes. A suspicious technical event may help explain an unusual payment, while payment and customer-risk information may help identify where proceeds are going.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the reports say about other attacks

Swift’s 2019 report said approximately 70 per cent of attempted thefts in the investigations it described were USD-based, while individual attempted transaction values reportedly shifted from more than US$10 million to US$250,000–US$2 million. Those findings illustrate why fixed rules based only on business hours, familiar destinations or large amounts can become less effective as attackers change tactics.

Group-IB’s research describes Cobalt targeting ATMs and then systems associated with Swift, card processing and payment gateways. The vendor also said Cobalt and Anunak/Carbanak had cooperated on some Swift thefts, and estimated that Cobalt operations stole approximately US$1 billion from more than 100 banks in 40 countries. This is Group-IB’s estimate of that group’s operations, not a total for all bank attacks; the report page does not state a publication date.

A World Bank paper discusses weak local defenses and similar reported incidents at banks in several countries, but cautions that its Bangladesh incident description draws mainly on news accounts and contains uncorroborated details. Specific forensic claims beyond the better-attributed account should therefore be treated cautiously.

Rank #3
DOEMTYAT 1pcs Camera k9
  • 1pcs camera k9
  • 1pcs camera
  • 1pcs camera
  • 1pcs camera
  • 1pcs camera
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How banks can reduce the risk

Swift lists its Customer Security Controls Framework (CSCF) v2026 as the current framework in its document centre, updated 11 July 2025. Its controls are organized around three aims: secure the environment; know and limit access; and detect and respond. Which controls apply depends on the institution’s Swift architecture.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Secure the local environment

  • Restrict internet access to critical systems and separate those systems from general IT where the architecture permits.
  • Reduce vulnerabilities and protect credentials against compromise.

Limit access and privilege

  • Manage identities and permissions so that access to payment-related systems is controlled and limited to what users and services need.
  • Review the access paths that connect general IT environments with systems used for payment instructions and confirmations.

Detect and respond

  • Look for anomalous system activity as well as unusual transaction patterns; monitoring payments alone may miss signs of intrusion, while monitoring technology alone may miss a suspicious beneficiary or corridor.
  • Prepare incident-response arrangements and share relevant threat information with appropriate industry participants.

Swift’s 2019 guidance also emphasized timely threat-intelligence sharing, robust standards, payment-pattern monitoring and considering counterparties’ security information in risk management. These are layered risk-reduction measures, not a guarantee that any one control will prevent a theft. Swift’s 2019 report said attackers changed timing and corridors, and emphasized information sharing and stronger controls as part of adapting to that behavior.

Why payment monitoring must adapt

Rules that only flag an unusually large payment or a transaction outside business hours can miss attempts designed to resemble ordinary activity. Swift’s historical findings show attackers changing both: some acted during business hours, and examined transactions increasingly used corridors not seen in the prior 24 months. Banks therefore need to assess transactions in context and combine fraud signals with security and customer-risk information. A pattern reported in 2019 is a reason to avoid static assumptions, not evidence that a particular corridor or time is inherently suspicious today.

The takeaway for readers

Bank thefts described as APT-style attacks can exploit the bank’s own technology and processes to create fraudulent payments, then rely on further financial activity to move the proceeds. In Bangladesh, Swift said its core service was not compromised; the bank’s environment was. Understanding that distinction—and keeping attempted amounts separate from amounts paid and traced—makes the incidents clearer and helps explain why defenses must join system security, payment monitoring and AML response.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.