The Cosmos Bank ₹94 Crore Cyber Heist
Hackers built a parallel payment switch mimicking the national card network, approved thousands of fake ATM withdrawals across 28 countries, then routed more funds abroad through the bank's SWIFT system — draining ₹94 crore from a Pune cooperative bank in two days.
The Promise
“Customer transactions processed through the bank's card and payment systems are protected by bank-grade security controls consistent with RBI's cybersecurity framework for banks.”
— Cosmos Co-operative Bank Ltd, Pune, Urban cooperative bank regulated by the Reserve Bank of India · 1 January 2016
This reflects the general regulatory expectation under RBI's 2016 Cyber Security Framework for banks, applicable to cooperative banks like Cosmos, rather than a specific quoted commitment from the bank itself, which this entry has not reviewed directly.
The Standard
That Cosmos Bank's core banking, ATM switch, and SWIFT messaging systems would be secured against unauthorised access and fraudulent transaction approval, consistent with RBI's cybersecurity framework requirements for regulated banks.
Reserve Bank of India's Cyber Security Framework for Banks (2016), which mandates baseline cybersecurity controls, incident reporting, and board-level oversight of cyber risk for all RBI-regulated banks including urban cooperative banks.
In force from 2 June 2016
The Reality
On 11 and 13 August 2018, attackers who had compromised Cosmos Bank's systems with malware built a proxy payment-switch system that mimicked the National Payment Corporation of India's (NPCI) card-approval infrastructure. This let them approve roughly 14,000 fraudulent transactions on about 450 cloned Cosmos debit/RuPay cards, withdrawing an estimated ₹78–80.5 crore through ATMs across 28 countries within a few hours, plus about ₹2.5 crore domestically. On 13 August, attackers separately used a proxy SWIFT server to fraudulently transfer ₹13.92 crore to a Hong Kong-based account, of which police later recovered roughly ₹5.72 crore. The Maharashtra government formed a Special Investigation Team, and Pune Police and the CBI pursued the case across multiple states. In April 2023, a Pune court convicted 11 people involved in withdrawing and laundering the stolen funds through the ATM leg of the fraud.
As of 23 April 2023
The Gap
Bars share a single zero-based scale. No axis truncation is used to exaggerate or minimize the gap between the two figures.
Money
Breakdown per available reporting: ~₹78–80.5 crore via cloned-card ATM withdrawals internationally, ~₹2.5 crore domestically, and ₹13.92 crore via a fraudulent SWIFT transfer to Hong Kong.
Timeline
- MilestoneAttackers begin cloned-card ATM withdrawal spree
A proxy switch approves roughly 14,000 fraudulent transactions on ~450 cloned cards, draining funds via ATMs in 28 countries.
- MilestoneFraudulent SWIFT transfer to Hong Kong
Attackers use a proxy SWIFT server to transfer ₹13.92 crore to a Hong Kong bank account.
- StatusBank discloses the breach; NPCI disputes liability
Cosmos Bank goes public with the attack; NPCI states its own systems were not compromised and points to the bank's own switch.
- MilestoneMaharashtra forms Special Investigation Team
State SIT and CBI begin pursuing suspects and money-mule networks across multiple states.
- MilestonePune court convicts 11 accused
Court convicts 11 people involved in withdrawing and laundering funds from the ATM-withdrawal leg of the fraud.
Legal Status
Eleven individuals were convicted in April 2023 by a Pune court for their role in the cash-withdrawal and money-laundering leg of the fraud. This entry has not confirmed whether the original attackers who breached the bank's systems and built the proxy switch/SWIFT infrastructure — as opposed to the mules who withdrew and moved the cash domestically — have been separately identified, charged, or convicted.
Verdict
This is a real, well-documented cyberattack on a regulated Indian cooperative bank that exploited weaknesses in its card-switch and SWIFT infrastructure to steal ₹94 crore in two days — one of the largest bank cyber heists reported in India. Convictions were obtained for the domestic money-laundering leg of the operation in 2023, but recovery of the stolen funds appears partial, and this entry has not established the fate of the international attackers believed to have orchestrated the technical intrusion.
The attack mechanics, financial figures, and 2023 conviction are corroborated across multiple independent news outlets (Business Standard, The Tribune, Deccan Herald) reporting on court and police statements, though this entry has not reviewed the court judgment or RBI's own post-incident findings directly.
What remains incomplete
- This entry has not reviewed the Pune court's 2023 judgment directly, nor any RBI supervisory or penalty action against Cosmos Bank specifically for this incident.
- Recovery status for the larger ~₹80 crore ATM-withdrawal leg of the theft (as opposed to the ₹13.92 crore SWIFT leg) has not been confirmed in available reporting.
- The identity, nationality, and legal status of the individuals believed to have carried out the core technical intrusion (malware deployment and proxy-switch construction), as distinct from the domestic mules convicted in 2023, is not established here.
Sources
Related investigations
The Mahadev Betting App Scam
An illegal online betting platform allegedly built a ₹6,000 crore empire with political protection in Chhattisgarh. Its promoter is now the subject of an Interpol Red Notice, detained abroad as India seeks his extradition.
The Sahara–SEBI Case
A conglomerate raised tens of thousands of crores from small investors through bonds regulators later ruled illegal. Its chairman spent years in custody over the refund dispute and died before it was fully resolved.
The Satyam Computers Scam
The chairman of one of India's biggest IT companies confessed, in a letter to his own board, to inflating profits and fabricating a cash balance for years — a confession that instantly became India's best-known corporate accounting fraud.