{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-bangladesh-bank-swift-heist-preceded-by-fake-job-applicant-spear-phishin"},"incident":{"title":"Bangladesh Bank SWIFT heist preceded by fake job-applicant spear phishing emails","date":"2016-02","date_precision":"month","victim_org":"Bangladesh Bank (central bank of Bangladesh)","sector":"Financial Services","country":"Bangladesh","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Fake Job Offer / Recruitment Lure"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Wire Fraud / Financial Loss","Service Disruption"],"loss_usd":81000000,"loss_note":"$101 million in fraudulent SWIFT transfers were executed, of which $81 million reached accounts in the Philippines and about $20 million sent to Sri Lanka was blocked; a portion of the Philippine funds was later recovered, leaving roughly $65 million outstanding.","records_affected":null,"threat_actor":"Lazarus Group (North Korea); US DOJ charged Park Jin Hyok in 2018","summary":"In February 2016 attackers used Bangladesh Bank's SWIFT credentials to issue $951 million in fraudulent payment instructions to the Federal Reserve Bank of New York, of which $101 million was released before the scheme was noticed. The FBI and the US criminal complaint against Park Jin Hyok describe the intruders gaining their initial foothold roughly a year earlier via spear phishing emails sent to bank staff by a persona posing as a job applicant, with malicious links or attachments.","how_it_worked":"Emails from a fabricated job-seeker persona were sent to Bangladesh Bank employees with a link to a résumé hosted externally; retrieving it delivered malware that established remote access. The attackers dwelled for about a year, mapping the bank's network and the workstation used for SWIFT Alliance Access. They then deployed custom malware that manipulated the SWIFT client's database and print output so fraudulent messages would not appear on the confirmation printer, issued transfer instructions to the New York Fed over a weekend, and routed proceeds through Philippine bank accounts and casino junkets to launder them.","lessons":"Isolating the SWIFT terminal on its own segment with application allow-listing, and independent reconciliation of outbound payment messages, would have caught both the intrusion path and the tampered confirmations.","confidence":"Reported","sources":[{"title":"Hackers took years before stealing $81m from Bangladesh Bank: FBI","url":"https://www.newagebd.net/print/article/141463","publisher":"New Age Bangladesh"},{"title":"When North Korean hackers almost pulled off a billion-dollar heist from Bangladesh Bank","url":"https://www.thedailystar.net/tech-startup/news/when-north-korean-hackers-almost-pulled-billion-dollar-heist-bangladesh-bank-2115317","publisher":"The Daily Star"},{"title":"Lessons Learned From the Bangladesh Bank Heist","url":"https://www.isaca.org/resources/isaca-journal/issues/2023/volume-6/lessons-learned-from-the-bangladesh-bank-heist","publisher":"ISACA Journal"}],"entry_type":"incident","slug":"2016-bangladesh-bank-swift-heist-preceded-by-fake-job-applicant-spear-phishin","year":2016,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-bangladesh-bank-swift-heist-preceded-by-fake-job-applicant-spear-phishin"}}