Curriculum·G604 Cross-Border Settlement and Corridor Economics·about 33 min

A cross-border payment is a chain of trust

By the end of this lesson you can

  • Explain that a cross-border payment moves through institutions trusting each other's messages
  • Describe how forged SWIFT instructions moved 81 million dollars out of Bangladesh Bank
  • Reason that the security of the corridor is the controls at each link, not the message itself
  • Locate where a cross-border payment can be attacked: at any institution that acts on a message

Graduate · enrolled learners

This lesson opens with The Bangladesh Bank heist, February 2016.

What happened
A cross-border payment is not one transfer; it is a chain of institutions passing instructions, and Bangladesh Bank kept its US dollar reserves in an account at the Federal Reserve Bank of New York. In February 2016 attackers who had penetrated the central bank's systems sent fraudulent payment instructions over SWIFT, the messaging network banks trust to move money across borders, asking the New York Fed to transfer nearly a billion dollars from that account to accounts in the Philippines and Sri Lanka. The New York Fed acted on the messages because they were properly authenticated; the messages were genuine in form and fraudulent in origin. About 81 million dollars reached the Philippines and was largely lost through casinos; most of the rest was stopped, part of it only because a misspelling in one instruction, fandation for foundation, triggered a manual review at a correspondent bank. No system was broken at the New York Fed; it did exactly what a trusted, authenticated SWIFT instruction told it to do. The attack was on the chain of trust, at the one link where the messages could be forged and every link downstream would honor them.
The decision point
Money does not teleport across a border; it moves along a chain of institutions, each acting on a message from the last and trusting that the message is genuine. SWIFT is that trusted messaging layer: a properly authenticated instruction is honored by the receiving institution because the whole system depends on trusting authenticated messages. The security of a cross-border payment is therefore not in the message, which is just data that can be forged at its source, but in the controls at each link: whether the sending institution's ability to originate messages is protected, and whether receiving institutions have any check beyond authentication. Bangladesh Bank is the case where the message layer worked perfectly and the chain of trust was attacked at the origin, so authenticated-but-fraudulent instructions flowed downstream and were honored, and only a typo and a manual review stopped most of the theft. So the decision anyone moving money across borders makes is to see the payment as a chain of trust and to ask where that trust could be abused, at which institution a forged or compromised instruction would be honored, because the corridor is only as secure as the weakest control on the chain, not as secure as the network that carries the messages.
Recorded loss
$81,000,000

What you will be able to answer

  • How did the Bangladesh Bank heist (2016) work?
  • What is a cross-border payment, structurally?
  • Where does a cross-border payment's security live?
  • What to ask when moving money across borders?

Orientation and Year One are open: anyone can read them without an account. From Year Two onward the lessons are for enrolled learners, because progress through the later years only means anything if it is tracked against a record.

It is free. We do not sell the list and there is nothing to buy at the end of it.

Sources and review

Confidence high·Volatility low·Reviewed 2026-09-16·Owner unassigned

Contested

The roughly 81 million dollar figure is the amount that reached the Philippines and was largely lost; attackers attempted nearly a billion dollars, and about 20 million sent to Sri Lanka was recovered after a misspelling triggered review. Some Philippine funds were later recovered. The lesson turns on the chain-of-trust attack, which the figures illustrate.

Attribution of the attack to a state-linked group was made by investigators later; the chain-of-trust and authenticated-but-forged-message points do not depend on the attribution, only on the fact that the origin was compromised and downstream links honored the instructions.