CONTINENTAL DRIFT: How a New York Bank Heist Became Filipino Paperwork
By Dr. BJ Enverga
A few weeks ago, my bank asked me to update my personal information.
I thought it would be simple. Perhaps I would confirm my address, phone number, email, and signature. Instead, I found myself answering a longer version of an already lengthy form.
The questions were no longer limited to identity and contact details. They asked about my employment, the nature of my work, the source of my funds, and whether I was connected to a politically exposed person. Some questions were understandable. Others felt intrusive. A few made me wonder why an ordinary bank client now had to disclose so much just to keep an account updated.
At first, I experienced it as many people probably do: as paperwork.
But then it reminded me of something I had read in Geoff White’s The Lazarus Heist: From Hollywood to High Finance: Inside North Korea’s Global Cyber War. The book tells the story of the Lazarus Group, a hacking collective widely associated with North Korea, and one of the most audacious cyber heists in modern financial history: the 2016 theft from Bangladesh Bank’s account at the Federal Reserve Bank of New York.
The more I thought about it, the more I wondered whether there was a connection between that spectacular crime and the ordinary forms now placed in front of Filipino bank clients.

There was.
Not in the simple sense that one heist single-handedly created all the questions banks now ask. Anti-money laundering rules had existed before 2016, and Philippine banks were already part of a global regulatory system that required customer due diligence. But the Bangladesh Bank heist exposed weaknesses in that system with unusual force. It showed how stolen money could move from a central bank’s account in New York, through accounts in the Philippines, into Manila casinos, and then onward through illicit networks.
In doing so, it helped accelerate a stricter compliance culture.
That is what makes the story worth revisiting. A cyber operation allegedly linked to North Korea, directed at the reserves of Bangladesh, held in New York, helped change how ordinary Filipinos experience banking. It is a reminder that global events do not always arrive in our lives as headlines, wars, summits, or diplomatic crises. Sometimes they arrive as forms asking where your money came from, or a tick box where you declare if you or someone close to you is politically exposed.
This is how a bank heist becomes paperwork.
In February 2016, Bangladesh Bank, the central bank of Bangladesh, became the target of one of the most audacious cyber heists in modern financial history. The operation has been reconstructed in detail by investigative journalist Geoff White in The Lazarus Heist: From Hollywood to High Finance: Inside North Korea’s Global Cyber War, which traces how North Korea-linked hackers moved from Hollywood cyberattacks to high-stakes financial theft.
The attackers did not enter a physical vault, tunnel underground, or load cash into getaway vehicles. Instead, they used credentials, malware, timing, and the global banking system itself.
The timing was important to the scheme. The hackers moved on the night of Thursday, 4 February, in Bangladesh. In the eastern United States, however, it was still Thursday morning. As such, the Federal Reserve Bank of New York, where Bangladesh’s Central Bank kept its dollar account, was still open for business. Bangladesh, meanwhile, was heading into its weekend, which runs from Friday to Saturday.
The attackers had turned the calendar into part of the crime.
By the time Bangladesh Bank began discovering that something was wrong, New York had entered its own weekend. Messages from the Federal Reserve had not been seen immediately because the hackers had disabled the printer that produced hard-copy records of transactions. Digital traces had also been manipulated. When the printer was finally restarted, urgent messages began to spill out. The Fed had received instructions, apparently from the Bangladesh Central Bank, to drain almost the entire account.
The hackers had attempted to move nearly one billion dollars.
Investigators and cybersecurity firms later linked the attack to the Lazarus Group, a hacking collective widely associated with North Korea. The North Korean government has denied involvement, but the case has become one of the most cited examples of state-linked cybercrime. Through fraudulent SWIFT messages, the attackers sent payment instructions from Bangladesh Bank’s systems. SWIFT is a secure messaging system used by financial institutions to send payment instructions. In ordinary terms, it is part of the plumbing of global finance. It is invisible to most of us, but essential to the movement of money across borders.
The Lazarus Group understood this system well. They had reportedly entered the Bangladesh Central Bank’s systems long before the actual theft. They studied the environment, gained access, learned the routines, and prepared the operation carefully. When they finally moved, they did so at a moment when the gaps between countries would work in their favor: Bangladesh was entering a weekend, New York would soon be closed, and the Philippines was approaching the Lunar New Year holiday.
Nobody would be able to disrupt the fraudulent transaction for several days. The hackers timed their attack so there would be enough delay for the money to move before anyone could stop it. A missed message in Dhaka, a closed office in New York, and a holiday in Manila each gave the money more time to escape.
Most of the transfers failed, however. Some were blocked after alarms were triggered. One famous transfer intended for a Sri Lankan organization raised suspicion because “Foundation” had been misspelled as “Fundation.” Another problem emerged because the receiving bank branch in Manila was on Jupiter Street, and the word “Jupiter” triggered checks connected to an unrelated sanctions concern. These small details reduced the amount of money that was successfully transferred.
Some of it still got through, though. Around $101 million left Bangladesh Bank’s account. About $20 million went toward Sri Lanka and was recovered. The larger portion, $81 million, made its way to the Philippines.
That is where the story becomes uncomfortably local. The money was routed through accounts at a Makati branch of a major commercial bank. From there, it moved quickly through a series of transactions that would later become the subject of investigations, hearings, lawsuits, and public controversy. Funds were shifted between accounts, exchanged into local currency, withdrawn in cash, and eventually moved toward casinos.
In 2016, casinos were not yet covered by the Philippines’ anti-money laundering framework in the same way that banks were. Once stolen funds were converted into casino chips, played through gaming tables, and changed back into cash, the trail became harder to follow. The money could move from a digital instruction in New York, to bank accounts in Makati, to casinos in Manila, and then onward through networks of middlemen.
From there, the trail appears to have moved further outward. Investigators later traced links between the Manila casino operation and Macau, another major gambling hub with long-standing connections to regional money flows. Several of the people and companies involved in the gambling junkets were reportedly connected to Macau. This mattered because, by that point, the money had already begun to leave the ordinary banking system.
For a time, the Philippines found itself at the center of a global financial scandal. The incident exposed not only weaknesses in cybersecurity, but also weaknesses in anti-money laundering rules, enforcement, and cross-border cooperation. Philippine lawmakers and regulators faced uncomfortable questions about how the funds had entered the country, how they had moved so quickly, and why casinos were not sufficiently covered by anti-money laundering rules.
The response to this was the promulgation of Republic Act No. 10927, which amended the Anti-Money Laundering Act to include casinos as covered persons. This meant that casinos now had legal obligations to report suspicious transactions and comply with anti-money laundering requirements. It also resulted in more intense scrutiny of real estate transactions, and compelled banks to monitor their clients more diligently.
This is the part of the story that many Filipinos may recognize. When a bank asks where your money came from, it is practicing what is commonly called Know Your Customer, or KYC. When it asks what you do for a living, it is trying to understand whether your transactions are consistent with your profile. When it asks whether you are connected to a public official, it is trying to identify political exposure, which may indicate higher corruption or money laundering risk. When it asks for supporting documents for a large transaction, it is trying to create a paper trail.
To the customer, these questions may feel intrusive. To the bank, they are part of risk management. To regulators, they are part of the architecture that prevents the financial system from being used to move stolen funds, drug money, corruption proceeds, terrorist financing, cybercrime revenues, or sanctions-evading capital.
However, the frustration of paperwork should not obscure why it exists. Money laundering depends on anonymity. It depends on confusion. It depends on institutions failing to ask enough questions at the right moment. A suspicious account that is not examined, a large transfer that is not challenged, a casino transaction that is not reported, or a customer profile that is never updated can become part of a much larger chain.
The Bangladesh Central Bank heist revealed this brutally. The Lazarus Group relied on inefficient institutions to succeed. They needed compromised systems, receiving accounts, intermediaries, and places where money could be transformed, obscured, and moved onward. In this case, the Philippines was the place that the hackers took advantage of.
That is what makes the story so striking. It connects activities in Pyongyang, Dhaka, New York, and Macau with forms filled out by ordinary Filipino clients.
This is the deeper lesson of the heist.
Globalization does not only bring products, culture, migrants, tourists, and ideas. It also brings risk. Money moves across borders, but so do crimes and regulations. When financial systems are connected, the failure of one institution can expose another. A vulnerability in one country can become a scandal in another. A cyber operation planned far away can change the way banks behave at home.
We often imagine global affairs as something that happens elsewhere: summits, sanctions, wars, or elections. However, global affairs also appear in quieter forms. They appear in the remittance counter, real estate due diligence, account-opening forms, and the extra question a bank officer asks before approving a transaction.
A bank heist aimed at Bangladesh’s reserves exposed weaknesses in Philippine regulation, and helped reshape the compliance culture that ordinary Filipinos now encounter in banks and other financial transactions.
That is the strange geography of modern finance. The money moved quickly, the law eventually followed, and somewhere between, the rest of us had to provide more personal information to our banks.

No comments: