The Bangladesh Bank Heist
FREE on Kindle Unlimited
Cybersecurity History

The Bangladesh Bank Heist

How North Korea Nearly Stole a Billion Dollars

By Shane Larson

$4.99

About This Book

On the morning of Friday, February 5, 2016, an employee at Bangladesh Bank in Dhaka noticed that a printer wasn't working. It was the kind of thing that happens in every office in the world — a tray that won't feed, a queue that won't clear, a machine that has simply decided to be difficult. The printer in question sat in the bank's SWIFT room, and its job was to automatically print out confirmations of the international money transfers the bank sent and received. When it went quiet, the staff did what anyone would do. They tried to fix it, shrugged, and moved on to other things.

That printer was not broken. It had been silenced deliberately, by malware, because the confirmations it would have printed were the one thing that could have revealed, in real time, that nearly a billion dollars was in the process of being stolen. For a crucial stretch of hours, a mundane office annoyance was the visible tip of the most audacious bank robbery ever attempted — and almost nobody in the building knew it.

This is the story of what was really happening while that printer stayed silent.

The Biggest Bank Robbery You Can't Picture

We know how to imagine a bank robbery. Masks, a vault, a getaway car — the money is a physical thing in a physical place, and the crime is about overcoming the walls around it. The heist that hit Bangladesh Bank had none of that, and it is far larger than any robbery you can picture, precisely because it threw away the whole physical dimension of the crime.

The bank's dollars weren't in a vault in Dhaka. Like the reserves of most countries, they existed as a balance in an account at the Federal Reserve Bank of New York. To steal them, the attackers didn't need to reach New York or Dhaka. They needed to send messages — instructions through SWIFT, the network the world's banks use to tell each other to move money, a system that works because everyone agrees to treat an authenticated message from a member bank as genuine. The thieves got inside Bangladesh Bank, learned to operate its systems like a trusted employee, and sent thirty-five genuine-looking transfer requests worth $951 million. From the network's point of view, nothing was wrong. The messages were valid. The money should move.

What makes the story unforgettable is how close it came to total success, and how it was blunted. Not by sophisticated defenses, but by luck so small it's almost comic. A single transfer misspelled "Foundation" as "Fandation," and a clerk in the routing chain paused. Another batch was frozen because it was headed to a bank on Jupiter Street in Manila, and "Jupiter" happened to match the name of a sanctioned ship on an unrelated watchlist. Between a typo and a coincidence, roughly $850 million was saved. The rest — $81 million — reached Manila and disappeared into the city's casinos, which were then legally exempt from anti-money-laundering rules, and most of it was never seen again. And when investigators finally traced the crime, it led not to a criminal syndicate but to a government: North Korea, robbing the global financial system through its seams to fund a sanctioned regime.

What's Inside

  • How you rob a bank with no vault, no gun, and no getaway — and why the money's digital nature removed every limit on the size of the theft
  • A plain-language tour of SWIFT and correspondent banking: the plumbing the whole world trusts and almost no one understands
  • The patient year Lazarus spent living inside the bank's network, learning to impersonate a legitimate operator
  • The malware that blinded the bank to its own robbery by silencing its confirmations — an attack on perception itself
  • The weekend engineered across Dhaka, New York, and Manila so that no two watchers were awake at once
  • The typo and the street name that accidentally saved $850 million
  • The Manila casino laundromat, the RCBC scandal, and the $81 million that vanished
  • The forensic hunt that tied it to North Korea's Lazarus Group and a programmer charged by the U.S. Department of Justice

Why I Wrote This

I spent my career as an engineer building enterprise and banking systems — the API-driven financial rails that messages like these travel on. So when the Bangladesh Bank heist broke, I read it differently than most people did. The headlines focused on the casinos and the typo, which are genuinely great story material. But the part that most accounts skipped or fumbled was the machinery: how SWIFT actually works, why a central bank keeps its dollars at the Fed, and why a fraudulent-but-authenticated message sails straight through a system designed by very smart people. That's the part I can explain from the inside, and it's the part that makes the heist make sense.

I wanted to write the account I wished existed — one that treats the reader as smart enough to understand the plumbing, explains it without a wall of jargon, and then uses that understanding to tell the true-crime story properly. Because once you grasp that the whole system runs on trusting a message, the heist stops being a baffling technical event and becomes something clearer and more unsettling: a robbery of trust itself, carried out by a nation-state, against a system we all depend on and mostly never think about.

Frequently Asked Questions

Is this a technical book? Will I be lost if I'm not in tech or finance?

No. Everything technical or financial is explained in plain language for a smart general reader — that's a core promise of the book. If you've ever wondered how money actually moves between countries, this will finally make it clear, and you'll enjoy the heist more for understanding it.

Is it a how-to for hacking or money laundering?

Absolutely not. It's a journalistic true-crime account. It explains what happened and why it mattered at the level a good newspaper or documentary would — never a reusable technical recipe, no attack code, no laundering manual. It's about understanding the crime, not committing one.

How do we know North Korea did it?

Investigators tied the malware and infrastructure to the Lazarus Group through code reuse and other technical fingerprints, and in 2018 the U.S. Department of Justice filed a criminal complaint naming a North Korean programmer, laying out the evidence publicly. The book explains how cyber attribution works — and is honest about its limits.

Did they get the money back?

Mostly, the $850 million that was frozen, yes — saved by the typo and the Jupiter coincidence. The $81 million that reached Manila's casinos largely vanished; only a fraction was recovered, through years of legal effort. The book follows both the recovered and the unrecovered money.

How does this connect to your other cybersecurity books?

It's the middle panel of a Lazarus Group trio: the same North Korean actor behind the Sony Pictures attack and the WannaCry ransomware outbreak. If you've read those stories in the Digital Outlaws series, this is the heist chapter of the same larger arc.

If You Liked This, You Might Like

  • Stuxnet — The benchmark nation-state cyber story: code deployed as a weapon of states, and this book's closest sibling.
  • The Sony Hack — The same actor, North Korea's Lazarus Group, in the attack that first put it on the world's radar.
  • Operation Aurora — State-sponsored digital espionage and the blurring of the line between spy and hacker.
  • Dark Web — The hidden economy where stolen money and stolen data go to disappear.

The heist's forward sequel in the Lazarus arc is WannaCry, the ransomware outbreak that shut down hospitals a year later.

For all of human history, a robbery was limited by how much the thieves could carry. When money became information, that limit vanished — and the vault became a message that can lie. This is the story of the day the world found out.

Part of the Digital Outlaws series.

More in This Genre

View all
New
Kevin Mitnick
Kevin Mitnick
The Most Wanted Hacker in the World
Dark Web
Dark Web
Inside the Hidden Internet
$3.99KU🎧
The Sony Hack
The Sony Hack
North Korea vs. Hollywood
$3.99KU🎧
The Mt. Gox Collapse
The Mt. Gox Collapse
Bitcoin's First Crisis
$3.99KU🎧