SWIFT and Cross-Border Payment Fraud
SWIFT carries messages, not money. A properly authenticated message from inside a bank gets obeyed.
SWIFT (the Society for Worldwide Interbank Financial Telecommunication) is the secure messaging network banks use to send each other payment instructions across borders. It does not hold or move money. When a bank sends a SWIFT payment message, the money moves through accounts that banks keep with each other: a nostro account is 'our account with you', a vostro account is 'your account with us'.
That design is why SWIFT fraud is so damaging. A correctly formatted, correctly authenticated message is treated as a genuine instruction from the sending bank. If an attacker can send messages from inside a bank, the receiving bank has no reason to doubt them.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
The Case Every Banker Should Know
In February 2016 attackers stole $81 million from Bangladesh Bank. According to the US Department of Justice, they first compromised the bank's network with spear-phishing emails, then reached the computers that connected to SWIFT, and sent fraudulently authenticated SWIFT messages instructing the Federal Reserve Bank of New York to transfer the bank's funds to accounts in other Asian countries. The same group tried similar methods on other banks from 2015 to 2018, attempting to steal at least $1 billion.
Nothing in SWIFT's own network was broken. The weakness was inside the sending bank: an ordinary phishing email, then access to a payment terminal, then messages nobody matched against the bank's own books in time.
Cross-Border Payment Fraud Patterns
Compromised SWIFT terminal
How it works
Attackers inside the bank's network send payment messages with stolen operator credentials
Control that breaks it
Network segregation of the payment zone, strong operator authentication, maker-checker
Messages outside core banking
How it works
SWIFT messages are created without a matching entry in the core banking system, so the books never show the liability
Control that breaks it
Straight-through link between SWIFT and core banking; daily reconciliation of every message to an entry
Business email compromise
How it works
A fraudster impersonates a supplier or the customer by email and asks for remittance to a 'new' account abroad
Control that breaks it
Call-back on a known number before acting on any beneficiary change
Insider misuse
How it works
An employee with SWIFT access sends or approves unauthorised messages
Control that breaks it
Role separation, access reviews, logs reviewed by someone independent
Time-zone timing
How it works
Messages are sent before a long weekend or holiday so the fraud is found only after the money is gone
Control that breaks it
Alerts on out-of-hours activity and on unusual counterparties or amounts
| Pattern | How it works | Control that breaks it |
|---|---|---|
| Compromised SWIFT terminal | Attackers inside the bank's network send payment messages with stolen operator credentials | Network segregation of the payment zone, strong operator authentication, maker-checker |
| Messages outside core banking | SWIFT messages are created without a matching entry in the core banking system, so the books never show the liability | Straight-through link between SWIFT and core banking; daily reconciliation of every message to an entry |
| Business email compromise | A fraudster impersonates a supplier or the customer by email and asks for remittance to a 'new' account abroad | Call-back on a known number before acting on any beneficiary change |
| Insider misuse | An employee with SWIFT access sends or approves unauthorised messages | Role separation, access reviews, logs reviewed by someone independent |
| Time-zone timing | Messages are sent before a long weekend or holiday so the fraud is found only after the money is gone | Alerts on out-of-hours activity and on unusual counterparties or amounts |
Controls a Bank's SWIFT Operation Should Show
- checkSWIFT infrastructure in a separate, restricted network zone, not reachable from ordinary office PCs
- checkSeparate maker and checker for every outgoing message, with neither able to do both
- checkEvery outgoing message matched to an entry in core banking, with breaks investigated the same day
- checkOperator access reviewed regularly, and removed immediately on transfer or exit
- checkIndependent review of message logs, including activity outside working hours
- checkBeneficiary or account changes confirmed by a call to a number already on record, never one given in the request
- checkAttestation against SWIFT's Customer Security Programme controls, which SWIFT requires of its users
Quick practice on banking operations. No signup.
When the Victim Is a Retail Customer
Cross-border fraud also hits individuals, mostly through cards used on overseas websites and remittances sent on a fraudster's instructions. RBI's revised customer protection rules give banks up to 60 calendar days to decide complaints about cross-border fraudulent electronic transactions made from 1 January 2027, against 45 days for domestic ones.
How the IIBF Exam Tests This
Expect conceptual questions: does SWIFT transfer funds? (No, it carries messages; settlement happens through correspondent accounts.) Which control would have caught an unrecorded SWIFT message? (Reconciliation of SWIFT messages with core banking.) The trap is answering 'encryption' to every SWIFT question: the messages in famous cases were properly authenticated, which is exactly why they were obeyed.
FAQs
What is SWIFT in banking?expand_more
A global secure messaging network that banks use to send payment and other financial instructions to each other. It carries the instruction; the money itself moves between the banks' accounts with each other.
What happened in the Bangladesh Bank SWIFT heist?expand_more
In February 2016 attackers who had entered Bangladesh Bank's network through spear-phishing sent fraudulent SWIFT messages to the Federal Reserve Bank of New York and stole $81 million, according to the US Department of Justice.
What is a nostro account?expand_more
An account a bank holds with a correspondent bank abroad, in that country's currency, used to settle its cross-border payments. From the correspondent's side the same account is a vostro account.
How do banks prevent SWIFT fraud?expand_more
By isolating SWIFT systems, enforcing maker-checker on every message, reconciling every message with core banking entries, reviewing access and logs independently, and complying with SWIFT's customer security controls.
Next steps
- Payment Processingarrow_forward
- Insider Threatarrow_forward
- Fraud Controlsarrow_forward
- Phishing, Vishing, Smishingarrow_forward
120 questions, 2 hours, scored instantly.
