The $1 Billion Spelling Mistake | Bangladesh Bank Heist
$1 Billion Spelling Mistake

Hackers created such a perfect plan to steal billions of dollars from Bangladesh’s national bank that even the strongest security system in the world couldn’t stop them.
For an entire year, they used invisible malware to spy on the bank’s network. They used three different time zones and national holidays as their shield.
But despite such detailed planning, they made a tiny mistake—one that even a second-grade child wouldn’t make. Just a single spelling mistake ruined their billion-dollar dream.
In January 2015, Bangladesh Bank received an email on its server. It came with a ZIP file. This was a phishing email containing a fake job applicant’s CV.
Three bank employees not only opened the email but also downloaded the file—without realizing that this action would lead to the biggest robbery in Bangladesh’s history.
The virus inside the ZIP file created a backdoor in one of the computers. The hackers successfully activated malware on that infected system.
This was no ordinary virus. It had three parts:
The first part created a loophole in the bank’s private network—a hidden entry point.
The second part ensured that any stolen information remained hidden using encrypted channels.
The third and most dangerous part continuously scanned the network and recorded all activity.
It tracked everything:
Who was doing what
How money was transferred
Which computers were active during holidays
For an entire year, the hackers stayed undetected and learned more about the bank’s system than even its employees.
During this time, they discovered that Bangladesh Bank’s foreign currency reserves were held in the Federal Reserve Bank of New York.
The Federal Reserve, also known as the Fed, is the central bank of the United States. Most countries store their dollar reserves there. It acts like a “bank for banks.”
To transfer money internationally, banks use a system called SWIFT. It’s like WhatsApp—but only for central banks—used to send billions of dollars worldwide every day.
The hackers realized that to steal money, they needed access to the computer that operated the SWIFT system.
They didn’t hack SWIFT directly. Instead, they focused on human error.
They monitored how employees logged in, entered transactions, and verified them. Over time, they learned how to mimic them perfectly.
But that wasn’t enough. They also studied past transaction records to make their fake transfers look completely normal.
Now they had full control and a solid plan.
Instead of transferring $1 billion at once—which might raise suspicion—they decided to split the amount into smaller transactions.
In May 2015, about a year before the heist, five bank accounts were opened in Manila, Philippines, at RCBC Bank. Each account had only $500 and remained inactive for a year.
More accounts were opened in the Philippines and one in Sri Lanka, all under fake names.
By February 2016, everything was ready.
On the night of February 4, 2016 (Thursday), after bank employees had left, the hackers entered the system one last time.
They accessed Bangladesh Bank’s account at the New York Federal Reserve and sent 36 transfer requests totaling $951 million.
The timing was their masterstroke:
In Bangladesh, it was the weekend (Friday holiday)
In New York, it was Friday morning (working day)
In the Philippines, a holiday (Chinese New Year) was coming on Monday
This gave them nearly four days of silence.
Money started flowing into the hackers’ accounts.
One of the transactions was $20 million meant for a Sri Lankan charity.
But then—everything changed.
The hackers made a spelling mistake.
They wrote “Shalika Foundation” incorrectly.
This mistake wasn’t caught by the Federal Reserve—but by a German bank through which the transaction was routed.
The German bank raised suspicion.
That’s when chaos began.
The Federal Reserve realized something was wrong and tried to contact Bangladesh Bank—but it was Friday, and the bank was closed.
By then, $81 million had already been transferred.
The remaining transactions—worth about $850 million—were stopped.
Meanwhile, the hackers had already logged out, and their malware began deleting evidence.
You might wonder—was there no system to detect this?
There was.
In Bangladesh Bank’s office, an HP LaserJet printer was supposed to print all SWIFT transactions—even on holidays.
But the hackers had hacked the printer too. It printed only blank pages.
The employee responsible assumed it was just a glitch and delayed checking it.
On Saturday morning, the truth came out.
The system showed multiple warnings and red flags—but by then, it was too late.
Out of 35 requests, only 5 were processed.
And that one spelling mistake helped stop the remaining $850 million.
But what happened to the $81 million?
As expected, Bangladesh Bank sent a stop-payment message to the Philippines.
But it was a holiday there (Chinese New Year), so no one responded.
On Tuesday morning, as soon as banks opened, the money was withdrawn from those accounts.
Suspicion fell on an RCBC bank manager who allowed the withdrawals even before checking the SWIFT messages.
The money was then laundered through casinos in Manila and eventually moved to Hong Kong.
This robbery shocked the entire world.
After years of investigations and court cases, the bank manager was found guilty in multiple money laundering cases and sentenced to several years in prison.
Even after 10 years:
The hackers have not been identified
Most of the $81 million has not been recovered
This incident left Bangladesh in a strange situation:
On one hand, they lost $81 million…
On the other hand, a simple spelling mistake saved $850 million.
About the Creator
Imran Ali Shah
🌍 Vical Midea | Imran
🎥 Turning ideas into viral content
✨ Watch • Share • Enjoy
Enjoyed the story? Support the Creator.
Subscribe for free to receive all their stories in your feed.
Comments
There are no comments for this story
Be the first to respond and start the conversation.