GoFirm
Back to Blog
Case Studies·2 min read

The Heist That Should Have Been Impossible

By GoFirm

On the night of 4 February 2016, hackers sent 35 transfer instructions through the SWIFT network on behalf of Bangladesh Bank. The Federal Reserve Bank of New York processed five of them. $81 million left the building. Most of it never came back.

What made this possible was not a flaw in SWIFT, a misconfigured firewall, or a software vulnerability. The attackers had compromised Bangladesh Bank's SWIFT credentials through malware planted months earlier. They used those credentials to send transfer instructions that looked, to every system in the chain, entirely legitimate. The malware had also disabled the printer used to generate transaction records, buying enough time for the money to move before anyone noticed.

The credentials were valid. The instructions were correctly formatted. Every technical control passed them through. What was missing was something no technical control was designed to provide — confirmation from a named human authority that those specific transfers had been sanctioned.

That gap has never been closed. The FBI's 2025 Internet Crime Report recorded over $3 billion in Business Email Compromise losses, with 86% of funds moving via wire transfer or ACH. The same essential attack — fraudulent transfer instructions riding valid or compromised credentials — is still producing catastrophic losses a decade later. The industry has added monitoring layers, improved MFA deployment, and tightened SWIFT controls. None of it asks the one question that would stop these attacks: has the named authority actually confirmed this transfer?

GoFirm asks that question, and enforces the answer.

Before any configured high-consequence action executes, GoFirm sends a confirmation request to the designated authority's registered personal device. They see the full context — what is being transferred, to whom, for how much — and confirm with their biometric or decline. The action does not execute until that confirmation is received. An attacker holding valid SWIFT credentials, or any other form of compromised authentication, cannot produce it.

The Bangladesh Bank heist was not a technology failure. It was the consequence of an authority confirmation gap that the industry still has not filled. GoFirm fills it.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto’s AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in minutes, not months.

References

1. BAE Systems Applied Intelligence, SWIFT Attackers' Malware Linked to More Financial Attacks, April 2016

2. Krebs on Security, SWIFT Hackers Targeted Vietnam Bank, May 2016

3. ISACA Journal, Lessons Learned From the Bangladesh Bank Heist, Volume 6, 2023

4. FBI Internet Crime Complaint Center, 2025 Internet Crime Report, April 2026

GoFirm
No confirmation, no execution.

Share this article