KNOWBASE
KB-2403Under Trial

The Cosmos Bank ₹94 Crore Cyber Heist

Hackers built a parallel payment switch mimicking the national card network, approved thousands of fake ATM withdrawals across 28 countries, then routed more funds abroad through the bank's SWIFT system — draining ₹94 crore from a Pune cooperative bank in two days.

Banking & FinancePublished 8 September 2026Updated 8 September 2026
₹94 cr
stolen from Cosmos Cooperative Bank, Pune, in a two-day malware and payment-switch attack in August 2018
Share on XShare on WhatsApp
01

The Promise

Customer transactions processed through the bank's card and payment systems are protected by bank-grade security controls consistent with RBI's cybersecurity framework for banks.

Cosmos Co-operative Bank Ltd, Pune, Urban cooperative bank regulated by the Reserve Bank of India · 1 January 2016

This reflects the general regulatory expectation under RBI's 2016 Cyber Security Framework for banks, applicable to cooperative banks like Cosmos, rather than a specific quoted commitment from the bank itself, which this entry has not reviewed directly.

02

The Standard

That Cosmos Bank's core banking, ATM switch, and SWIFT messaging systems would be secured against unauthorised access and fraudulent transaction approval, consistent with RBI's cybersecurity framework requirements for regulated banks.

Reserve Bank of India's Cyber Security Framework for Banks (2016), which mandates baseline cybersecurity controls, incident reporting, and board-level oversight of cyber risk for all RBI-regulated banks including urban cooperative banks.

In force from 2 June 2016

03

The Reality

On 11 and 13 August 2018, attackers who had compromised Cosmos Bank's systems with malware built a proxy payment-switch system that mimicked the National Payment Corporation of India's (NPCI) card-approval infrastructure. This let them approve roughly 14,000 fraudulent transactions on about 450 cloned Cosmos debit/RuPay cards, withdrawing an estimated ₹78–80.5 crore through ATMs across 28 countries within a few hours, plus about ₹2.5 crore domestically. On 13 August, attackers separately used a proxy SWIFT server to fraudulently transfer ₹13.92 crore to a Hong Kong-based account, of which police later recovered roughly ₹5.72 crore. The Maharashtra government formed a Special Investigation Team, and Pune Police and the CBI pursued the case across multiple states. In April 2023, a Pune court convicted 11 people involved in withdrawing and laundering the stolen funds through the ATM leg of the fraud.

As of 23 April 2023

04

The Gap

05

Money

Allocated
Not disclosed
Released
Not disclosed
₹94 crore total funds stolen across the ATM and SWIFT legs of the attack
₹ 94 crore

Breakdown per available reporting: ~₹78–80.5 crore via cloned-card ATM withdrawals internationally, ~₹2.5 crore domestically, and ₹13.92 crore via a fraudulent SWIFT transfer to Hong Kong.

06

Timeline

  1. Milestone
    Attackers begin cloned-card ATM withdrawal spree

    A proxy switch approves roughly 14,000 fraudulent transactions on ~450 cloned cards, draining funds via ATMs in 28 countries.

  2. Milestone
    Fraudulent SWIFT transfer to Hong Kong

    Attackers use a proxy SWIFT server to transfer ₹13.92 crore to a Hong Kong bank account.

  3. Status
    Bank discloses the breach; NPCI disputes liability

    Cosmos Bank goes public with the attack; NPCI states its own systems were not compromised and points to the bank's own switch.

  4. Milestone
    Maharashtra forms Special Investigation Team

    State SIT and CBI begin pursuing suspects and money-mule networks across multiple states.

  5. Milestone
    Pune court convicts 11 accused

    Court convicts 11 people involved in withdrawing and laundering funds from the ATM-withdrawal leg of the fraud.

07

Legal Status

Eleven individuals were convicted in April 2023 by a Pune court for their role in the cash-withdrawal and money-laundering leg of the fraud. This entry has not confirmed whether the original attackers who breached the bank's systems and built the proxy switch/SWIFT infrastructure — as opposed to the mules who withdrew and moved the cash domestically — have been separately identified, charged, or convicted.

08

Verdict

Under TrialHigh confidence

This is a real, well-documented cyberattack on a regulated Indian cooperative bank that exploited weaknesses in its card-switch and SWIFT infrastructure to steal ₹94 crore in two days — one of the largest bank cyber heists reported in India. Convictions were obtained for the domestic money-laundering leg of the operation in 2023, but recovery of the stolen funds appears partial, and this entry has not established the fate of the international attackers believed to have orchestrated the technical intrusion.

The attack mechanics, financial figures, and 2023 conviction are corroborated across multiple independent news outlets (Business Standard, The Tribune, Deccan Herald) reporting on court and police statements, though this entry has not reviewed the court judgment or RBI's own post-incident findings directly.

09

What remains incomplete

  • This entry has not reviewed the Pune court's 2023 judgment directly, nor any RBI supervisory or penalty action against Cosmos Bank specifically for this incident.
  • Recovery status for the larger ~₹80 crore ATM-withdrawal leg of the theft (as opposed to the ₹13.92 crore SWIFT leg) has not been confirmed in available reporting.
  • The identity, nationality, and legal status of the individuals believed to have carried out the core technical intrusion (malware deployment and proxy-switch construction), as distinct from the domestic mules convicted in 2023, is not established here.
10

Sources

Independent source23 April 2023
Pune court convicts 11 accused in Cosmos Bank's Rs 94 cr cyber fraud case
Business Standard
View source
Independent source15 August 2018
Hackers siphon off Rs 94 crore from Pune bank via ATMs in 21 countries
The Tribune
View source
Independent source16 August 2018
NPCI blames Cosmos Bank
Deccan Herald
View source