Video summary
The Most Genius Bank Heist EVER in India
Main summary
Key takeaways
Overview
An auto-rickshaw driver and other “mules” were tricked into participating in a “Bollywood film shoot” in locations such as Kolhapur, Maharashtra. In reality, they were positioned at ATMs to carry out a coordinated global attack.
Across multiple countries, stolen card data—combined with acceptance of random PINs—was used to withdraw cash. The operation has been described as a highly sophisticated “bank heist” targeting India’s Cosmos Cooperative Bank.
Key Mechanics of the Heist
-
Malicious entry via phishing
- An employee (“Rahul”) received what appeared to be an internal compliance email.
- He clicked it and unknowingly granted access to the attackers.
-
Weeks of system mapping to find the critical weakness
- Attackers mapped Cosmos Bank’s systems to locate a key vulnerability: the ATM switch (the intermediary between ATMs and the bank’s core banking system).
-
A “shadow/proxy switch” to intercept approvals
- The hackers created a shadow/proxy switch that silently intercepted withdrawal requests.
- It forced approvals without proper verification by Cosmos’s core banking system—effectively turning ATMs into an “infinite money glitch.”
-
Scaling the theft using cloned cards and international recruitment
- Hundreds of cards were cloned (450 mentioned).
- A multi-layer recruitment structure operated across 28 countries:
- Big Boss (dark-web figure)
- Ran the operation and had tools/equipment and network access to convert stolen data into working cards and recruit internationally.
- Handlers
- Coordinated regionally and monitored withdrawals in real time.
- Mules
- Mostly ordinary workers who physically withdrew cash, believing they were doing legitimate short-term “film” work.
- Big Boss (dark-web figure)
-
Synchronized timing to exploit monitoring blind spots
- The attack targeted a narrow window: Saturday, August 11, 2018, when banks had skeleton staffing and overlapping time zones (e.g., India vs. the U.S.) created gaps in monitoring.
Timeline and Impact
-
3:00 p.m. IST
- The proxy switch went live, and ATMs worldwide began approving withdrawals.
-
Fraud detection alerts
- Visa fraud detection systems reportedly triggered alerts as thousands of withdrawal requests flooded in.
-
Shutdown
- Cosmos and Visa reportedly took 2 hours and 13 minutes to stop the operation.
-
Reported immediate losses (ATM phase)
- 80.5 crore INR stolen via ATMs, including:
- International withdrawals using Visa
- Domestic transactions using RuPay
- 80.5 crore INR stolen via ATMs, including:
-
Second phase using SWIFT
- After the ATM withdrawals, attackers allegedly struck again using SWIFT (banking messaging used for large transfers):
- Aug. 13, 2018 (Monday):
- Three fraudulent wire transfers totaling 13.92 crore INR were sent to an account at Hang Seng Bank in Hong Kong
- The funds were reportedly moved through shell companies and crypto exchanges.
- Aug. 13, 2018 (Monday):
- After the ATM withdrawals, attackers allegedly struck again using SWIFT (banking messaging used for large transfers):
-
Total reported damage
- About 94 crore INR (roughly $13.5 million) in less than 72 hours.
Investigation and Arrests
- Cosmos filed a cybercrime complaint.
- Inspector General Brijesh Singh led the investigation.
-
Investigators reportedly tracked:
- burner phones
- cell-tower data
- CCTV footage
- ATM-incident evidence across India.
-
18 suspects arrested
- Included both handlers and mules.
- Many reportedly believed they were participating in a film set.
Attribution and Later Identification
-
2019 (U.S. arrest of Big Boss)
- Big Boss was arrested in the U.S.
- He pleaded guilty and received a sentence of 11 years and 8 months
- Restitution ordered: $30 million
- His real name is identified in the account as Ghaleb al-Amri.
-
Feb. 2021 (U.S. agencies announce North Korean involvement)
- The FBI, Secret Service, and DOJ stated the operation involved three North Korean hackers associated with Lazarus Group:
- Park Jin Hyok
- Jon Chang Hyok
- Kim Il
- The FBI, Secret Service, and DOJ stated the operation involved three North Korean hackers associated with Lazarus Group:
-
The segment argues Lazarus Group—linked to North Korea’s military intelligence—uses financial theft to bypass sanctions and fund the nuclear program.
- The charged individuals were described as still at large, implying extradition/prosecution may be difficult.
Presenters/Contributors
- No explicit presenters or contributors are named in the provided subtitles (the narration appears as an untitled documentary-style voiceover).