Heist Timing Masterclass
Here’s how timing supercharged their plan
Aug 18, 2020 · 37 min · 20 segments
A bank robbery with the objective to steal 1 billion dollars. This is the story of the largest bank robbery in history. And it was all done over a computer. Our guest this episode was Geoff White…
They're pretty good hackers, so their plan isn't to bust down the door, draw their weapons, and shout, "Everyone on the floor.
Instead, the plan was to hack into the Bangladesh Bank and transfer out as much money as they could before anyone could catch them.
Uh, I think it was January 2015, the first email started popping up inside Bangladesh Bank.
It contains a CV for somebody who looks like a job applicant, opens the zip file, has a look at the CV, or perhaps doesn't ever get the CV, but nonetheless, they get infected.
Three people opened the email in Bangladesh Bank, and at least one of them got infected.
Okay, so the hackers, or in this case, the bank robbers, infiltrate the network.
Now, when they get in using a phishing email like this, they only get into one person's computer, whoever that person was who opened the email, and that's it.
And once they get in, they use three types of malware to set up for the next part.
And as far as I'm aware, one of them, um, created the backdoor into Bangladesh Bank.
Another of them, uh, created the encrypted channel so that you could pull stuff out of that backdoor without being spotted, and the third piece of software was used to scan and navigate across the network.
So they spend some time mapping out the network of the Bangladesh Bank, moving around, establishing persistence, and learning about how to transfer money around.
One of the first things to do is they work out where Bangladesh Bank's got its money.
Bangladesh Bank has a, a foreign currency reserve account in New York at the New York Fed, and so there's a billion dollars sitting there.
There, there's an international bank version of the hub which transfers millions, billions of dollars around the world.
They're pretty good hackers, so their plan isn't to bust down the door, draw their weapons, and shout, "Everyone on the floor.
Instead, the plan was to hack into the Bangladesh Bank and transfer out as much money as they could before anyone could catch them.
Uh, I think it was January 2015, the first email started popping up inside Bangladesh Bank.
It contains a CV for somebody who looks like a job applicant, opens the zip file, has a look at the CV, or perhaps doesn't ever get the CV, but nonetheless, they get infected.
Three people opened the email in Bangladesh Bank, and at least one of them got infected.
Okay, so the hackers, or in this case, the bank robbers, infiltrate the network.
Now, when they get in using a phishing email like this, they only get into one person's computer, whoever that person was who opened the email, and that's it.
And once they get in, they use three types of malware to set up for the next part.
And as far as I'm aware, one of them, um, created the backdoor into Bangladesh Bank.
Another of them, uh, created the encrypted channel so that you could pull stuff out of that backdoor without being spotted, and the third piece of software was used to scan and navigate across the network.
So they spend some time mapping out the network of the Bangladesh Bank, moving around, establishing persistence, and learning about how to transfer money around.
One of the first things to do is they work out where Bangladesh Bank's got its money.
Bangladesh Bank has a, a foreign currency reserve account in New York at the New York Fed, and so there's a billion dollars sitting there.
There, there's an international bank version of the hub which transfers millions, billions of dollars around the world.
Every episode on Radar is fully transcribed, speaker-labeled, and rich with metadata. Here is a taste of this one. Try Radar for free to see the rest.
3 of 8
Heist Timing Masterclass
Here’s how timing supercharged their plan
They Hacked The Printer
A simple safeguard becomes their vulnerability
Insider-Level SWIFT Knowledge
Why their transactions looked so normal
+5 more clips · 6 min 17 sec of audio in all
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
All 8 clips — the highlight moments, each cut as its own audio, with a title and a speaker
All 20 segments — the transcript broken into labeled sections, every ad read marked
All 25 topics — jump to every other episode discussing the same subject
Every related episode — other shows Radar links to this one
No account is needed to search Radar.