A decade after the Bangladesh Bank reserve heist, the Criminal Investigation Department (CID) of police is set to implicate 10 Bangladeshis, including then-governor Atiur Rahman, and 54 foreign individuals.
Among other nine Bangladeshis, eight are former and current Bangladesh Bank officials – KM Abdul Wadud, Subhankar Saha, Rezaul Karim, Zubair Bin Huda, AFM Asaduzzaman, Mezbaul Haque, Abul Kashem, and Md Sultan Masud Ahmed. The rest is Anis A Khan, who was then managing director of Mutual Trust Bank.
Of the BB officials, Zubair Bin Huda is still serving the central bank as an additional director. Huda filed a case with Motijhel Police Station after 39 days of heist on behalf of the central bank. Others went to retirement.
The foreigners include 36 from the Philippines, eight from Sri Lanka, four from India, three from China, two from North Korea, and one from Japan.
Following a 10-year investigation, the nearly 10,000-page charge sheet has been sent to the Attorney General for legal review.
While the document contains extensive forensic evidence, the CID has declined to disclose the specific roles played by the accused at this stage.
In February 2016, hackers used fraudulent SWIFT messages attempting to steal $1 billion from Bangladesh Bank’s account at the Federal Reserve Bank of New York. While a spelling error (“Fandation”) flagged suspicions and blocked $850 million, $101 million slipped through.
Sri Lanka recovered $20 million, but $81 million was successfully routed to Philippine casinos. The Philippine government later recovered and returned $15 million from a casino owner, but the remaining $66.4 million remains missing.
After infiltrating the bank’s network via phishing emails containing Dridex malware, the hackers spent a year studying its operational procedures. Exploiting time zone differences and weekend closures, they used stolen credentials to send 35 fraudulent SWIFT messages and circumvent the security system.
A CID inspector involved in the investigation told TIMES of Bangladesh that the heist had been carried out over an extended period by compromising the bank’s SWIFT system through its IT department and Indian nationals had been involved in the operation from the outset.
To recover the stolen funds, Bangladesh Bank filed a lawsuit against the Rizal Commercial Banking Corporation (RCBC) in the Manhattan Southern District Court in 2019. RCBC moved to dismiss the case, and in April 2022, the New York court dismissed the suit on the grounds of insufficient jurisdiction. In response, the central bank announced it would pursue legal action within a New York state court jurisdiction.
Cybersecurity analyst and digital forensics researcher Tanvir Hassan Zoha was the first to bring the reserve theft to light. He told TIMES, “Since the investigation has found evidence of the involvement of nine bank officials, it is clear that the incident was not hacking. The hacking drama was planned and orchestrated with internal collusion.”
Opining that the ongoing case in New York will no longer have any importance, he said, “The trial will continue within the country.”
Investigators held Atiur Rahman responsible for indulging in utter negligence and suppressing the incident for 39 days, allowing an unauthorised foreign IT firm and a local unauthorised person to enter the bank’s network.
Long investigation time
Thirty-nine days after the heist, Bangladesh Bank filed a money laundering case with Motijheel Police Station, which the CID has since been investigating.
While the probe stalled for eight years under the Awami League government, it was recently completed under a six-member review committee formed on 11 March last year, headed by interim government law adviser Asif Nazrul. A draft charge sheet was prepared on 1 April and sent to the Attorney General for legal advice.
The current investigation officer, Additional Special Police Superintendent Al Mamun, told TIMES, “Next steps will be taken after receiving legal advice”, adding that “The names of 60 to 70 people will be in the charge sheet.”
Mamun noted that the first investigator completed 80% of the work, while subsequent officers gathered remaining details.
His predecessor, Md Farhad Kabir (May-December 2025), secured vital forensic evidence and identified the main culprits. Talking to TIMES, Kabir said, “Although almost all the work in the investigation was completed, the main culprit could not be identified based on the evidence.
After reviewing a forensic report, he said North Korean hacker Park Jeon Hyok and the Lazarus group led by him were identified. “Later, with the cooperation of the investigation officer, Additional DIG Raihan Uddin Khan, the report was collected from FBI (US agency) Special Agent Nathan P Shields and the main accused was included in the case. In addition, $81 million was confiscated from RCBC Bank.”
Prior to Kabir, Abdullah Yasin led the probe from August 2023 to May 2025. During his tenure, an attempt to transfer the case to the Anti-Corruption Commission (ACC) failed following the July uprising.
Additional DIG Raihan Uddin Khan conducted the foundational investigation from March 2016 to August 2023. Through Mutual Legal Assistance Requests (MLR), he uncovered the involvement of 64 domestic and foreign entities and helped recover $34.6 million of the stolen funds.
Reflecting on early challenges, Raihan Uddin said, “There were many obstacles in the beginning. Especially after 39 days of the theft, the case was filed. Before we went to the crime scene, an unauthorised foreign IT firm and a local unauthorised person entered the crime scene.”
Despite these hurdles, Khan secured forensic reports and a statement from RCBC branch manager Maya Diguti, who admitted the involvement of multiple foreigners.
Md Sibgat Ullah, then-head of the CID, said, “The draft charge sheet clearly mentions the nature of the crime and the responsibilities of all the accused, both domestic and foreign. Necessary forensic evidence has been collected for the sake of investigation and significant progress has been made in the investigation of the case by analysing the documents received from different countries through MLAR.”
The interim government’s review committee included Faiz Ahmad Taiyeb, former special assistant to the Chief Adviser at the Ministry of Posts, Telecommunications, and Information Technology. Reflecting on the process, he said, “We inspected the central bank, talked to the officials, looked at the technical issues, then talked to the investigation officers.”





