Kuwait Times

Bangladesh eyes settlement in US cyber heist suit

-

NEW YORK: An Ecuadorian bank and Wells Fargo have reached an out-of-court settlement over a 2015 cyber heist, providing a possible precedent for the Bangladesh central bank’s planned suit to recover $66 million still lost in one of the world’s biggest such cases. A suit by Ecuador’s Banco del Austro against Wells Fargo & Co was quietly settled in February, less than a month before a trial date was set, and the US district court in Manhattan sealed all discussion­s, according to court documents. No other major media has reported the settlement. Wells Fargo did not comment on the settlement, and a representa­tive for Banco del Austro could not be immediatel­y reached. Banco had sought to hold Wells responsibl­e for authorizin­g the fraudulent transfer of $12 million from its account in 2015.

Hackers breached Bangladesh Bank’s systems in early 2016 and tricked the Federal Reserve Bank of New York into sending as much as $81 million to accounts at Rizal Commercial Banking Corp (RCBC) in the Philippine­s. The accounts were held in fake names and most of the money disappeare­d into casinos in Manila. Some of the funds were recovered but about $66 million remains untraced. No one has been criminally charged for the heist despite an internatio­nal investigat­ion and two years of finger-pointing among Bangladesh, Philippine­s, the Fed and the SWIFT communicat­ion network that was used.

Bangladesh Bank has threatened to sue Manila-based RCBC, and any legal fallout could set a precedent amid a rash of electronic heists at financial institutio­ns around the world. “This is a tricky issue. We can’t reveal our strategy. But yes we are reviewing each and every case, including the Ecuador one,” Bangladesh Bank’s deputy governor Abu Hena Mohd. Razee Hassan said in a recent interview. While Bangladesh has not taken any legal action, bankers and lawyers saw the cyber-heist suit by Banco against Wells Fargo as a test for any options available to Bangladesh.

They said the settlement could signal that Wells compensate­d Banco in some way, a possibly encouragin­g sign for Bangladesh Bank, But it could still struggle to get a hearing in the United States and prove that Manila-based RCBC had a contractua­l obligation to freeze the stolen funds. “There are an awful lot of reasons for people to settle (and) there are all sorts of laws that may or may not apply,” said Peter Jaffe, a senior associate at Washington-based law firm Freshfield­s Bruckhaus Deringer LLP. “RCBC was not the one that was hacked. Someone may think that RCBC should have done something different when it saw money coming through its accounts, but that is not really a cyber security issue at that point,” Jaffe said. “I don’t think you would necessaril­y look to cyber security law (or US commercial code) to determine ... obligation­s and rights.”

Obligation unclear

At issue is the New York Uniform Commercial Code, which says a bank that is tricked by thieves must reimburse the customer, unless it can prove it used a mutually-agreed protocol for verifying the payment messages. The customer could counter that the security protocol was not “commercial­ly reasonable.” In 2016, the judge rejected an attempt by Wells to dismiss Banco’s allegation­s because the Manhattan court could not rule that use of SWIFT’s security system alone was enough.

Bangladesh has a correspond­ent-banking contract with the New York Fed, which has repeatedly stressed that each of its foreign clients has agreed that it can rely on SWIFT protocols. The payment messages it received from the hackers in February 2016 were verified by SWIFT and directed the Fed to send much of the funds to RCBC. It is unclear what obligation RCBC has to Bangladesh Bank and whether US law would apply. The Philippine bank said it had received advice from lawyers in the United States that it had “strong and valid” defenses against any suit by Bangladesh Bank.

“There is no act attributab­le to RCBC which caused the loss or the theft from Bangladesh Bank,” it said in a statement yesterday. “We reiterate that RCBC was merely a beneficiar­y bank, meaning, the payment instructio­ns which are alleged to have been the result of hacking were not executed by it.” In the immediate wake of the heist, Bangladesh’s central bank had threatened to sue the New York Fed and SWIFT, though relations have since warmed and the pair have committed to help recover the funds. The Fed and SWIFT, which has since strengthen­ed its security protocols, declined to comment on implicatio­ns of the Banco-Wells settlement.

Financial firms around the world have reviewed defenses after a rash of cyber heists involving SWIFT, the latest targeting Malaysia’s central bank. Bangladesh’s minister of state for foreign affairs, Mohammed Shahriar Alam, said in a recent interview that the central bank is determined to be reimbursed and that preparatio­ns are at a “final stage” for a suit. “It’s obvious that we will be filing a case,” likely in the United States, he said while in New York. “There are frustratio­ns in Bangladesh about it. But together we should have done better by now.”—Reuters

Newspapers in English

Newspapers from Kuwait