Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
In February 2015, Kaspersky Lab said a criminal campaign it called Carbanak had targeted up to 100 financial institutions in about 30 countries, with potential losses of as much as $1 billion. Those were upper-bound estimates—not an independently audited total or proof that exactly 100 banks lost money. The attackers’ defining tactic was to spend months learning how bank employees and systems worked, then use that knowledge to divert funds or trigger cash withdrawals.
What the headline means
Kaspersky announced its findings on February 16, 2015. Its account described attacks against banks, electronic payment systems and other financial institutions—not exactly 100 banks—and said losses could have reached $1 billion. Kaspersky’s more detailed investigation put reported losses at roughly $2.5 million to $10 million per affected institution, and said at least half of the institutions it investigated had suffered direct losses. These figures were the security company’s assessment, not a public, audited accounting of every victim’s losses. Kaspersky’s announcement and technical investigation are the sources for those estimates.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
The War Wagon | Buy on Amazon | |
| 2 |
|
Point Break | Buy on Amazon | |
| 3 |
|
The Mask | Buy on Amazon | |
| 4 |
|
Tough Guys | Buy on Amazon | |
| 5 |
|
Ocean's 8 | Buy on Amazon |
“Hit” also covers different stages: an institution could have been targeted or compromised without suffering a confirmed theft. So the most careful summary is that Kaspersky attributed a large, international campaign to Carbanak and estimated that its potential losses could total up to $1 billion.
How Carbanak got into banks
Carbanak referred both to a backdoor program and, by extension, to the criminal operation associated with it. Kaspersky described the backdoor as based on the earlier Carberp code. The campaign used a patient, multi-stage approach:
#1 Best Overall
- Target employees. Attackers sent spear-phishing emails to selected bank staff, with malicious attachments that could include Office documents or CPL files.
- Establish access. If a recipient opened a malicious file, the attackers could install the backdoor and retain access to that computer. Contemporaneous reporting described exploitation of known Microsoft Office flaws, including CVE-2012-0158, CVE-2013-3906 and CVE-2014-1761. Those are details of the 2015 reporting, not a statement that those flaws are current risks on a patched system.
- Move through the network. From the initial foothold, attackers sought computers and staff with access to administration, accounting, payment systems and ATMs.
- Watch how the bank operated. Kaspersky reported screen captures and video monitoring that helped the intruders learn how employees authorized transactions and used financial software.
- Exploit the routine. With that knowledge, the attackers could imitate legitimate activity and manipulate trusted processes rather than relying only on conspicuously abnormal transactions.
Kaspersky estimated that an individual operation typically took two to four months from infection to cash extraction. That time gave attackers an opportunity to learn workflows and operate in ways less likely to raise an immediate alarm. The central weakness was not simply an unpatched computer: it was the combination of compromised access, excessive opportunity and procedures that attackers had studied.
How the money was taken
Kaspersky described several ways the group could turn access into money:
Rank #2
- ATM cash-outs: Attackers manipulated ATM systems so machines dispensed cash at a set time, in some reported cases without a customer card transaction. Cash collectors or money mules could then retrieve it.
- Unauthorized transfers: Intruders initiated transfers through online banking or international payment processes, including SWIFT-related workflows.
- Fraudulent accounts and internal movements: They created or manipulated accounts, moved funds and used mule networks to collect proceeds.
These were not all the same kind of theft, and the available reporting does not establish that every institution faced every method. The important point is that criminals could abuse a bank’s own systems and processes to steal from the institution directly. This differs from a conventional account-takeover story in which a criminal steals from an individual customer.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →How certain are the numbers and geography?
| Claim | What can safely be said |
|---|---|
| 100 banks | Kaspersky said up to 100 financial institutions were targeted or affected. The category included payment systems and other organizations, and “up to” is an upper bound, not an exact count of confirmed theft victims. |
| $1 billion | Kaspersky estimated potential losses of as much as $1 billion. It was not a publicly audited final total. |
| About 30 countries | Kaspersky reported a campaign spanning roughly 30 countries and listed organizations in countries including Russia, the United States, Germany, India, the United Kingdom, Canada, China and Brazil. That list should not be read as proof of a confirmed loss in every country. |
| U.S. banks | Kaspersky’s assessment included U.S. targets, but contemporaneous reporting said the American Bankers Association had no evidence that a U.S. bank was affected by this specific campaign. Public confirmation was therefore contested or absent; it is too strong to say U.S. banks were definitively robbed. |
| Who was behind it? | Kaspersky described a multinational gang and floated possible origins among several countries. Public reporting did not establish a definitive nationality. |
Geographic claims can vary with the meaning of “targeted,” “infected” and “victim.” A lack of a public victim announcement does not prove that no compromise occurred, but it does not justify presenting a suspected target as a confirmed loss either.
Rank #3
Carbanak and Anunak: related names, different estimates
Before Kaspersky’s February 2015 announcement, Group-IB and Fox-IT had published a report on a campaign they called Anunak. Subsequent reporting linked Anunak with Carbanak, describing the operations as the same or closely related. The labels are not interchangeable proof that every incident or estimate belongs to one precisely bounded campaign: “Anunak” was used in the earlier investigation, while “Carbanak” became the widely used name for the malware and associated operation.
The earlier report presented a narrower picture of victims and losses than Kaspersky’s later estimate. That difference is another reason not to treat the $1 billion figure as a settled ledger total. The Group-IB/Fox-IT report provides the earlier account; KrebsOnSecurity’s contemporaneous analysis discusses differences in the reporting.
Rank #4
What it meant for bank customers
Carbanak was reported as a theft from financial institutions, not a campaign that simply emptied the accounts of millions of customers. That distinction matters: a bank loss does not automatically mean a customer’s deposit was stolen. Customers could still experience indirect effects such as service disruption, investigations, tighter controls or follow-on fraud attempts, but the campaign’s defining claim was direct theft from institutions.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchFor personal-finance readers, sensible account safeguards remain useful even when a breach targets a bank internally: use unique passwords, enable multifactor authentication where offered, turn on transaction alerts, and contact the bank promptly about unfamiliar activity. These steps cannot prevent a bank’s internal compromise, but they can help customers spot account misuse and report it quickly.
Best Value
Why the case mattered to banks
The campaign illustrated how a technically capable intruder could exploit identity and business process as much as software. Defensive lessons include phishing-resistant authentication, tightly controlled administrator access, separation of duties for high-value payments, independent verification of unusual transfers, and monitoring for abnormal administrator behavior. Banks also need to detect unusual ATM commands and payment activity, limit lateral movement between network segments, and preserve evidence for rapid incident response.
Kaspersky later discussed Carbanak 2.0 alongside other APT-style bank-robbery groups such as Metel and GCMAN. That later activity shows that the broader pattern continued to concern researchers; it does not establish that every subsequent bank attack came from the original Carbanak group. Kaspersky’s 2016 follow-up covers that later reporting.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

