Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

Carbanak: What Really Happened in the 2015 “$1 Billion” Bank Heist

By TheFinanceBase Team5 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

In February 2015, Kaspersky Lab said a criminal campaign it called Carbanak had targeted up to 100 financial institutions in about 30 countries, with potential losses of as much as $1 billion. Those were upper-bound estimates—not an independently audited total or proof that exactly 100 banks lost money. The attackers’ defining tactic was to spend months learning how bank employees and systems worked, then use that knowledge to divert funds or trigger cash withdrawals.

What the headline means

Kaspersky announced its findings on February 16, 2015. Its account described attacks against banks, electronic payment systems and other financial institutions—not exactly 100 banks—and said losses could have reached $1 billion. Kaspersky’s more detailed investigation put reported losses at roughly $2.5 million to $10 million per affected institution, and said at least half of the institutions it investigated had suffered direct losses. These figures were the security company’s assessment, not a public, audited accounting of every victim’s losses. Kaspersky’s announcement and technical investigation are the sources for those estimates.

“Hit” also covers different stages: an institution could have been targeted or compromised without suffering a confirmed theft. So the most careful summary is that Kaspersky attributed a large, international campaign to Carbanak and estimated that its potential losses could total up to $1 billion.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How Carbanak got into banks

Carbanak referred both to a backdoor program and, by extension, to the criminal operation associated with it. Kaspersky described the backdoor as based on the earlier Carberp code. The campaign used a patient, multi-stage approach:

  1. Target employees. Attackers sent spear-phishing emails to selected bank staff, with malicious attachments that could include Office documents or CPL files.
  2. Establish access. If a recipient opened a malicious file, the attackers could install the backdoor and retain access to that computer. Contemporaneous reporting described exploitation of known Microsoft Office flaws, including CVE-2012-0158, CVE-2013-3906 and CVE-2014-1761. Those are details of the 2015 reporting, not a statement that those flaws are current risks on a patched system.
  3. Move through the network. From the initial foothold, attackers sought computers and staff with access to administration, accounting, payment systems and ATMs.
  4. Watch how the bank operated. Kaspersky reported screen captures and video monitoring that helped the intruders learn how employees authorized transactions and used financial software.
  5. Exploit the routine. With that knowledge, the attackers could imitate legitimate activity and manipulate trusted processes rather than relying only on conspicuously abnormal transactions.

Kaspersky estimated that an individual operation typically took two to four months from infection to cash extraction. That time gave attackers an opportunity to learn workflows and operate in ways less likely to raise an immediate alarm. The central weakness was not simply an unpatched computer: it was the combination of compromised access, excessive opportunity and procedures that attackers had studied.

How the money was taken

Kaspersky described several ways the group could turn access into money:

  • ATM cash-outs: Attackers manipulated ATM systems so machines dispensed cash at a set time, in some reported cases without a customer card transaction. Cash collectors or money mules could then retrieve it.
  • Unauthorized transfers: Intruders initiated transfers through online banking or international payment processes, including SWIFT-related workflows.
  • Fraudulent accounts and internal movements: They created or manipulated accounts, moved funds and used mule networks to collect proceeds.

These were not all the same kind of theft, and the available reporting does not establish that every institution faced every method. The important point is that criminals could abuse a bank’s own systems and processes to steal from the institution directly. This differs from a conventional account-takeover story in which a criminal steals from an individual customer.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How certain are the numbers and geography?

Claim What can safely be said
100 banks Kaspersky said up to 100 financial institutions were targeted or affected. The category included payment systems and other organizations, and “up to” is an upper bound, not an exact count of confirmed theft victims.
$1 billion Kaspersky estimated potential losses of as much as $1 billion. It was not a publicly audited final total.
About 30 countries Kaspersky reported a campaign spanning roughly 30 countries and listed organizations in countries including Russia, the United States, Germany, India, the United Kingdom, Canada, China and Brazil. That list should not be read as proof of a confirmed loss in every country.
U.S. banks Kaspersky’s assessment included U.S. targets, but contemporaneous reporting said the American Bankers Association had no evidence that a U.S. bank was affected by this specific campaign. Public confirmation was therefore contested or absent; it is too strong to say U.S. banks were definitively robbed.
Who was behind it? Kaspersky described a multinational gang and floated possible origins among several countries. Public reporting did not establish a definitive nationality.

Geographic claims can vary with the meaning of “targeted,” “infected” and “victim.” A lack of a public victim announcement does not prove that no compromise occurred, but it does not justify presenting a suspected target as a confirmed loss either.

Carbanak and Anunak: related names, different estimates

Before Kaspersky’s February 2015 announcement, Group-IB and Fox-IT had published a report on a campaign they called Anunak. Subsequent reporting linked Anunak with Carbanak, describing the operations as the same or closely related. The labels are not interchangeable proof that every incident or estimate belongs to one precisely bounded campaign: “Anunak” was used in the earlier investigation, while “Carbanak” became the widely used name for the malware and associated operation.

The earlier report presented a narrower picture of victims and losses than Kaspersky’s later estimate. That difference is another reason not to treat the $1 billion figure as a settled ledger total. The Group-IB/Fox-IT report provides the earlier account; KrebsOnSecurity’s contemporaneous analysis discusses differences in the reporting.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What it meant for bank customers

Carbanak was reported as a theft from financial institutions, not a campaign that simply emptied the accounts of millions of customers. That distinction matters: a bank loss does not automatically mean a customer’s deposit was stolen. Customers could still experience indirect effects such as service disruption, investigations, tighter controls or follow-on fraud attempts, but the campaign’s defining claim was direct theft from institutions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For personal-finance readers, sensible account safeguards remain useful even when a breach targets a bank internally: use unique passwords, enable multifactor authentication where offered, turn on transaction alerts, and contact the bank promptly about unfamiliar activity. These steps cannot prevent a bank’s internal compromise, but they can help customers spot account misuse and report it quickly.

Why the case mattered to banks

The campaign illustrated how a technically capable intruder could exploit identity and business process as much as software. Defensive lessons include phishing-resistant authentication, tightly controlled administrator access, separation of duties for high-value payments, independent verification of unusual transfers, and monitoring for abnormal administrator behavior. Banks also need to detect unusual ATM commands and payment activity, limit lateral movement between network segments, and preserve evidence for rapid incident response.

Kaspersky later discussed Carbanak 2.0 alongside other APT-style bank-robbery groups such as Metel and GCMAN. That later activity shows that the broader pattern continued to concern researchers; it does not establish that every subsequent bank attack came from the original Carbanak group. Kaspersky’s 2016 follow-up covers that later reporting.

Quick Recap

Bestseller No. 1
Bestseller No. 2
Bestseller No. 3
Bestseller No. 4
Bestseller No. 5

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.