Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

How Hackers Steal Money from Banks in APT-Style Attacks

APT-style bank attacks can begin with quiet access to a bank’s systems and end with fraudulent payments routed through intermediaries. The Bangladesh case shows why attempted, paid, and traced amounts—and Swift’s network versus a bank’s own environment—must be distinguished.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In an APT-style bank attack, intruders can quietly compromise a bank’s own technology, learn how staff and payment systems operate, and then try to send fraudulent payment instructions that look legitimate. The theft may continue after the transfer as criminals move the money through intermediaries. In the Bangladesh Bank case, Swift said the attackers compromised the bank’s IT environment—not Swift’s network or core messaging services.

What “APT-style” means in a bank attack

Here, “APT-style” describes a persistent, targeted pattern: attackers establish access, stay quiet while learning about a particular institution, and act when they believe they can avoid detection. It does not prove that an attack was state-sponsored, or that all such thefts were carried out by one group. The sources describe criminal operations and named groups, but do not establish a single actor behind every bank attack.

Swift’s 10 April 2019 threat report said attackers in its investigations sometimes spent weeks or months inside a target environment before attempting fraud. Group-IB’s research into the Cobalt group reported about three weeks of studying victim networks. Those are observations from particular investigations, not a standard timeline for every intrusion.

How an attack can turn access into a fraudulent payment

The broad pattern is a progression from intrusion to payment fraud, not simply a criminal breaking into a payment network and transferring money directly. The details vary by bank and architecture; the following describes the stages at a high level rather than a recipe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Gain a foothold in the bank’s environment. Attackers compromise local systems or accounts and seek a route toward the technology and staff involved in payment operations.
  2. Observe normal work. They study processes, timing, system behavior, and payment patterns so that a later instruction is less likely to stand out.
  3. Reach payment-related systems. The objective may be systems used to generate payment instructions or receive confirmations, rather than the messaging service itself.
  4. Attempt fraudulent instructions. The attackers try to make unauthorized payments appear consistent with legitimate activity. A bank may block some attempts while others are accepted.
  5. Move the proceeds. After a transfer, criminals may use intermediaries and other methods to obscure the path of the money.

Group-IB’s Cobalt research described a group that studied victim networks and targeted ATMs, followed by SWIFT, card-processing, and payment-gateway systems. Group-IB also reported cooperation between Cobalt and Anunak/Carbanak on some SWIFT thefts. These are vendor-reported findings about particular operations, not a description of every bank intrusion. Group-IB estimated that Cobalt operations stole approximately US$1 billion from more than 100 banks in 40 countries.

#1 Best Overall
Sale
2K Security Camera System, 5GHz&2.4GHz WiFi Solar Wireless Cameras for Home Security, Wire-free Installation, AI Detection, Two-way Audio, Mobile alerts, SD/Cloud Storage, Color Night Vision, 4 Packs
  • 100% Wireless Solar & Battery Powered: Enjoy true wireless installation with no outlets or messy cables. The detachable solar panel keeps your outdoor camera charged daily, 2 hours of daily sunlight to maintain 24/7 operation. while the built-in backup battery ensures reliable protection during cloudy days or bad weather.
  • 2K Color Night Vision with Smart Spotlight: Capture clear details day and night with crisp 2K resolution. The built-in spotlight enables full-color night vision when motion is detected, helping you clearly see people, packages, and activity even in low-light conditions.
  • 360° Pan-Tilt Coverage & IP65 Weatherproof: Remotely pan, tilt, and zoom through the app to monitor every corner of your property. Built with an IP65 waterproof rating, this wireless outdoor camera performs reliably in rain, snow, dust, and extreme temperatures year-round.
  • Smart Human Detection & Real-Time Two-Way Talk: Advanced PIR + AI human detection accurately identifies people—not just motion—reducing false alerts from animals or moving objects. Receive instant notifications and speak directly through two-way audio to greet visitors or deter unwanted activity from anywhere.
  • Flexible Storage Options & Alexa Compatible: Choose local 15x11x1mm MicroSD card recording (card not included) or optional cloud storage with no forced subscription. Easily view live feeds or play back recordings using Alexa voice commands for hands-free home monitoring.

Was SWIFT hacked?

In the Bangladesh Bank case, Swift said its network, software, and core messaging services were not compromised. The attackers had penetrated the bank’s IT environment and reached systems used to generate Swift instructions and receive confirmations. As then-Swift chief executive Gottfried Leibbrandt put it, “In Bangladesh and the other cases, the thieves compromised the IT environment and worked their way to the bank systems where the Swift instructions are generated and the confirmations received.”

The distinction matters: Swift is a financial messaging service, while a bank’s local environment includes the institution’s own systems and controls. Saying “hackers hacked Swift” blurs that distinction and misstates Swift’s account of the Bangladesh incident.

How much money was taken in the Bangladesh Bank heist?

The figures refer to different stages of the incident and should not be treated as interchangeable. ISACA’s 2023 account says attackers sent 35 payment instructions in February 2016.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Stage or outcome Amount What the figure means
Attempted Close to US$1 billion The approximate total the attackers tried to take.
Authorized and paid US$101 million The amount ISACA says was authorized and paid across five transactions.
Traced to the Philippines US$81 million The portion ISACA says was traced to the Philippines.
Stopped and later retrieved US$20 million A transaction to Sri Lanka that was stopped and later retrieved, according to ISACA.

So the near-US$1 billion figure describes the attempted theft, not the amount that went through. The World Bank’s account notes that its incident description relied mainly on news reports and included details that were not corroborated; finer-grained claims from that account should therefore be treated cautiously.

Rank #2
ANNKE 3K Lite Wired Security Camera System Outdoor, 8X 2MP Cameras, 1TB HDD
  • AI Motion Detection 2.0 – Driving AI to the next level, human&vehicle detection and flexible detection area are more accurate than before. For quicker locating in crucial moments, human&vehicle smart searching in recordings offers you great help.
  • Tried-and-True Safe Guard – This one-stop security solution can work with TVI, AHD, CVI, CVBS & IP cameras, the kit includes 1080P cams. The 8CH 3K lite DVR can hook up with 1080P@30fps or 3K/5MP@20fps cams. Therefore, you can also DIY it with other cameras in your home.
  • Reliable 24/7 Continuous Recording – With a pre-installed 1TB HDD(Support up to 10TB HDD), providing 24/7 surveillance recording for you. Upgraded H.265+ saves more storage space and uses less bandwidth, recording videos longer and smoother viewing.
  • Smart Dual-Light Effectively Guard Your Home – This newly upgraded security system offers you a crisp full color night vision, IR mode and color night vision switch flexibly. Once detect intruders, immediate pushes pop up on your phone, securing your peace of mind day&night.
  • Color Night Vision & IP67 Weatherproof – Built-in IR lights and white lights, these cameras can see up to 100ft in B&W night vision, full-color night vision up to 66ft. Rated IP67, these wired cameras can brave all weather, and stand from cold to hot.

Why payment fraud may evade simple rules

Attackers can adapt the timing and destination patterns that a payment-monitoring system might otherwise flag. In its 2019 report, Swift said actors shifted from issuing fraudulent payments outside business hours to acting during business hours to blend in with legitimate traffic. It also reported that most fraudulent transactions examined over the preceding 15 months used payment corridors not seen in the previous 24 months.

Swift’s report described several historical findings from its investigations, not current global prevalence:

  • Four out of five investigated fraudulent transactions were sent to beneficiary accounts in East and South East Asia.
  • Approximately 70 per cent of attempted thefts were USD-based.
  • The value of individual attempted fraudulent transactions had shifted from more than US$10 million to between US$250,000 and US$2 million.

These findings help explain why a control that looks only for a familiar hour, corridor, or transaction size can be insufficient. Swift’s 2019 guidance emphasized monitoring payment patterns, sharing timely threat intelligence, applying robust standards, and considering counterparties’ security information in risk management. None of those measures, by itself, guarantees prevention.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What happens after the payment is sent?

A fraudulent transfer is not necessarily the end of the operation. Swift and BAE Systems’ 2 September 2020 report described cash-out methods including money mules, front companies, and cryptocurrency. It also noted that criminals may exploit insiders or weak due diligence, and may convert proceeds into assets such as property and jewellery. The joint report describes possible methods, not steps used in every case.

Rank #3
DOEMTYAT 1pcs Camera k9
  • 1pcs camera k9
  • 1pcs camera
  • 1pcs camera
  • 1pcs camera
  • 1pcs camera

This is why payment security cannot be isolated from the rest of a bank’s risk operations. The report’s central implication is that cybersecurity, fraud, and anti-money-laundering teams need to connect their monitoring and response processes so that signals about an intrusion, a suspicious payment, and movement of funds can be considered together.

What banks can do to reduce the risk

Swift lists its Customer Security Controls Framework (CSCF) v2026 as the current framework; its document centre gives an update date of 11 July 2025. It groups controls around three aims: secure the environment, know and limit access, and detect and respond. Which controls apply depends on the institution’s Swift architecture.

  • Secure the environment: restrict internet access where appropriate, separate critical systems from general IT, reduce vulnerabilities, and guard against credential compromise.
  • Know and limit access: manage identities and privileges so people and systems have only the access they need.
  • Detect and respond: look for anomalous system or transaction activity, prepare incident-response plans, and support information sharing.

These are layered institutional safeguards, not a guarantee that an attack will be stopped. The Bangladesh case illustrates why protecting local systems involved in payment creation and confirmation matters alongside controls on the messaging infrastructure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.