Video summary

The Most Genius Bank Heist EVER in India

Main summary

Key takeaways

News and Commentary

Overview

An auto-rickshaw driver and other “mules” were tricked into participating in a “Bollywood film shoot” in locations such as Kolhapur, Maharashtra. In reality, they were positioned at ATMs to carry out a coordinated global attack.

Across multiple countries, stolen card data—combined with acceptance of random PINs—was used to withdraw cash. The operation has been described as a highly sophisticated “bank heist” targeting India’s Cosmos Cooperative Bank.

Key Mechanics of the Heist

  • Malicious entry via phishing

    • An employee (“Rahul”) received what appeared to be an internal compliance email.
    • He clicked it and unknowingly granted access to the attackers.
  • Weeks of system mapping to find the critical weakness

    • Attackers mapped Cosmos Bank’s systems to locate a key vulnerability: the ATM switch (the intermediary between ATMs and the bank’s core banking system).
  • A “shadow/proxy switch” to intercept approvals

    • The hackers created a shadow/proxy switch that silently intercepted withdrawal requests.
    • It forced approvals without proper verification by Cosmos’s core banking system—effectively turning ATMs into an “infinite money glitch.”
  • Scaling the theft using cloned cards and international recruitment

    • Hundreds of cards were cloned (450 mentioned).
    • A multi-layer recruitment structure operated across 28 countries:
      • Big Boss (dark-web figure)
        • Ran the operation and had tools/equipment and network access to convert stolen data into working cards and recruit internationally.
      • Handlers
        • Coordinated regionally and monitored withdrawals in real time.
      • Mules
        • Mostly ordinary workers who physically withdrew cash, believing they were doing legitimate short-term “film” work.
  • Synchronized timing to exploit monitoring blind spots

    • The attack targeted a narrow window: Saturday, August 11, 2018, when banks had skeleton staffing and overlapping time zones (e.g., India vs. the U.S.) created gaps in monitoring.

Timeline and Impact

  • 3:00 p.m. IST

    • The proxy switch went live, and ATMs worldwide began approving withdrawals.
  • Fraud detection alerts

    • Visa fraud detection systems reportedly triggered alerts as thousands of withdrawal requests flooded in.
  • Shutdown

    • Cosmos and Visa reportedly took 2 hours and 13 minutes to stop the operation.
  • Reported immediate losses (ATM phase)

    • 80.5 crore INR stolen via ATMs, including:
      • International withdrawals using Visa
      • Domestic transactions using RuPay
  • Second phase using SWIFT

    • After the ATM withdrawals, attackers allegedly struck again using SWIFT (banking messaging used for large transfers):
      • Aug. 13, 2018 (Monday):
        • Three fraudulent wire transfers totaling 13.92 crore INR were sent to an account at Hang Seng Bank in Hong Kong
        • The funds were reportedly moved through shell companies and crypto exchanges.
  • Total reported damage

    • About 94 crore INR (roughly $13.5 million) in less than 72 hours.

Investigation and Arrests

  • Cosmos filed a cybercrime complaint.
  • Inspector General Brijesh Singh led the investigation.
  • Investigators reportedly tracked:

    • burner phones
    • cell-tower data
    • CCTV footage
    • ATM-incident evidence across India.
  • 18 suspects arrested

    • Included both handlers and mules.
    • Many reportedly believed they were participating in a film set.

Attribution and Later Identification

  • 2019 (U.S. arrest of Big Boss)

    • Big Boss was arrested in the U.S.
    • He pleaded guilty and received a sentence of 11 years and 8 months
    • Restitution ordered: $30 million
    • His real name is identified in the account as Ghaleb al-Amri.
  • Feb. 2021 (U.S. agencies announce North Korean involvement)

    • The FBI, Secret Service, and DOJ stated the operation involved three North Korean hackers associated with Lazarus Group:
      • Park Jin Hyok
      • Jon Chang Hyok
      • Kim Il
  • The segment argues Lazarus Group—linked to North Korea’s military intelligence—uses financial theft to bypass sanctions and fund the nuclear program.

  • The charged individuals were described as still at large, implying extradition/prosecution may be difficult.

Presenters/Contributors

  • No explicit presenters or contributors are named in the provided subtitles (the narration appears as an untitled documentary-style voiceover).

Original video