One of the largest-ever bank robberies exposed a crucial flaw in security systems: a lack of CQ Knowledge. Over 6 days in 2016, hackers stole just under $1 billion from the Bangladesh Central Bank by taking advantage of cultural differences.
๐๐๐ฒ ๐๐๐๐. Four bank accounts were opened at a local bank in the Philippines and would not be touched for 9 months.
๐๐ก๐ฎ๐ซ๐ฌ๐๐๐ฒ ๐ง๐ข๐ ๐ก๐ญ, ๐ ๐๐๐ซ๐ฎ๐๐ซ๐ฒ ๐๐ญ๐ก, ๐๐๐๐. The automated transaction report printer at the Bangladesh Central Bank went out of order and would be down for days. Everyone had already left as the bank was shutting down for the weekend, which in Muslim-majority countries typically lands on Friday and Saturday.
This wasnโt a random error. The bank employees had been the victims of a phishing attack, and hackers were now inside their systems. With no one in the Bangladesh office, almost a billion in funds were transferred to the Central Bankโs account in New York.
๐ ๐ซ๐ข๐๐๐ฒ, ๐ ๐๐๐ซ๐ฎ๐๐ซ๐ฒ ๐๐ญ๐ก, ๐๐๐๐. Since the hackers had access to the internal workings of the Central Bank, the Federal Reserve Bank of New York had no reason not to believe the transfers. The transfers, totaling $951 million, were processed. Across 35 different payments, the almost one billion dollars was rerouted to various accounts in Asia.
๐๐ฎ๐ง๐๐๐ฒ, ๐ ๐๐๐ซ๐ฎ๐๐ซ๐ฒ ๐๐ญ๐ก, ๐๐๐๐. Employees in Bangladesh returned to work with an annoying issue: their printer was broken. After a couple of hours of troubleshooting, the printer came back to life and started printing the backlog of reports. As each report slid into the tray, worries arose. There were many more major transactions than expected. This included the 35 unauthorized payments, all of which were going out of Bangladesh.
The bank employees scrambled to cancel the hacked transfers, but there was a problem. It was the weekend in the USA, and no one was working at the Federal Reserve Bank of New York!
๐๐จ๐ง๐๐๐ฒ, ๐ ๐๐๐ซ๐ฎ๐๐ซ๐ฒ ๐๐ญ๐ก, ๐๐๐๐. Over 81 million dollars had now entered those 4 dormant bank accounts in the Philippines. Workers were now back to work in both Bangladesh and the United States. They were frantically sending notices and stop-payment orders on the hacked transactions. While the large amount should have raised red flags, there was a problem: no one was working in the Philippines! It was the Chinese New Year, a non-working holiday across many countries in Asia.
The thieves quickly laundered the money out of the Philippines’ accounts and fled the country before they could be apprehended.
The hackers had taken advantage of cultural differences. Each step was planned around dates when employees who could have stopped the transactions from going through would not be working. Luckily, plenty of the transactions were ultimately rejected by an automated system, as 31 had a spelling error or a red flag due to a keyword that matched a separate, unrelated sanctions program against Iran.
The heist showed that when working globally, we have to consider cultural differences. This includes different schedules and holidays of each region we work with. Building that CQ Knowledge would have prevented the gaps that arose here, allowing hackers to act unnoticed.