More than 400 cyberattacks are being carried out on Bangladesh’s banking sector every day, with most originating from China, North Korea, and Russia. Research by the Bangladesh Institute of Bank Management (BIBM) shows that half of all cyberattacks targeting the country’s banks come from these three countries, with China alone accounting for one-fourth. The findings were presented in a study titled “Cyber Security in Financial Sector of Bangladesh: Securing the Digital Future.”
According to the institute, which leads research and training on banking in Bangladesh, the country’s banks have spent BDT 534.13 billion over the past two decades (from 2000 to 2024) on information technology (IT) development. While annual investments in this area previously averaged around BDT 20 billion, that figure now exceeds BDT 30 billion. However, about 95 percent of this spending goes toward hardware and software purchases, networking, training, auditing, and other related expenses. Only 5 percent is allocated to cybersecurity measures, even as banks face rising digital threats.
Experts say Bangladesh’s banks have made significant technological progress over the past two decades, with 95 percent of all transactions now conducted digitally. Most banks have also launched mobile applications for their customers. However, limited investment in digital security has left the banking system increasingly vulnerable to cyberattacks.
Bangladesh’s banking sector is in a “dire state” when it comes to cybersecurity, according to fintech entrepreneur Dr. Shahadat Khan. The top executive of TallyKhata and TallyPay told Bonik Barta, “The country’s banking sector is becoming digital, but its cybersecurity system is not keeping up. We are poorly prepared to prevent large-scale cyberattacks. The same situation exists across both public and private institutions. Hackers have been taking control of databases and demanding ransom, and in some cases, officials are paying them. Bangladesh cannot move forward with such fragile cybersecurity.”
Dr. Khan believes that many chairmen and managing directors of banks and other institutions lack adequate knowledge of cybersecurity or information technology. “Research by BIBM and other organizations shows that more than half of the country’s banks are incapable of defending against cyberattacks,” he said. “Yet no effective measures are being taken to overcome this weakness. IT officials are even afraid to meet with their chairmen or managing directors to present proposals. To improve cybersecurity, we must overcome this culture of fear and ensure proper financial investment.”
At a seminar in August, Professor Md Mahbubur Rahman Alam of BIBM presented a paper titled “Cyber Security in Financial Sector of Bangladesh: Securing the Digital Future.” It revealed that between 2023 and 2024, the banking sector experienced between 145 and 630 cyberattacks per day. Of these, 24 percent originated from China, the world’s most populous country. North Korea accounted for 13 percent, followed by Russia at 12 percent. The United States and Pakistan each accounted for 7 percent, while Romania and Turkey each accounted for 5 percent. Bulgaria was the source of 4 percent of the attacks. Neighboring countries India, Taiwan, and Hungary each accounted for 3 percent. The study also found that 2 percent of cyberattacks originated within Bangladesh itself. Other attacks came from Brazil and several other countries.
The research paper also detailed the types of cyberattacks targeting Bangladesh’s banking sector. It found that between 2023 and 2024, at least 13 forms of organized cyberattacks were detected. These attacks were carried out either by exploiting security weaknesses or breaching existing defense systems.
The most common among them were Advanced Persistent Threats (APTs), or stealth attacks. These were followed by attacks exploiting known vulnerabilities, malware intrusions, malicious terminals, cross-site scripting (XSS), and SQL injections. Other forms included backdoor installations, spear phishing, ransomware, rootkits, clickjacking, and Distributed Denial of Service (DDoS) attacks.
According to the study, cyberattacks have the greatest impact on employees. In 85 percent of cases, they undermine staff morale, and in 53 percent of cases, they disrupt regular operations. The research also found that insiders, particularly vendors or IT service providers, were responsible for a large portion of cyber incidents. Around 27 percent of cybercrimes in the banking sector were linked to vendors. Unidentified hackers accounted for 24 percent of attacks, while 16 percent involved internal employees. Hacktivists were behind another 16 percent. The remaining incidents included 11 percent attributed to competitors, 7 percent backed by foreign states, and 6 percent carried out by customers.
The study identified bank employees as the weakest link in cybersecurity. A survey of employees showed that only 4 percent demonstrated excellent awareness of cybersecurity. About 10 percent were rated “very good,” 16 percent “good,” and 20 percent “average.” Another 22 percent showed poor awareness, while 28 percent were found to be in a “very poor” state of cyber awareness.
A parallel survey among bank customers revealed similar vulnerabilities. Only 7 percent had excellent awareness of cyber risks, 11 percent were “very good,” 13 percent “good,” and 15 percent “average.” Meanwhile, 23 percent of customers showed poor awareness, and 31 percent were found to be in a “very poor” category.
Alongside expanding digital banking services, the central bank is also emphasizing the need to strengthen cybersecurity, said Bangladesh Bank spokesperson and Executive Director Md Arif Hossain Khan. Speaking to Bonik Barta, he said, “In recent years, the central bank has issued several policies on IT and cybersecurity. It is also monitoring whether banks are following these guidelines. However, it is true that the nature of cyberattacks is constantly evolving worldwide. While most attacks are being prevented, some still manage to get through. Therefore, banks need more skilled professionals in the technology sector. The central bank is working on that as well.”
According to data cited in a research paper by BIBM, there were 5,875 IT professionals in the banking sector in 2019. By 2024, the number had increased to 8,250. The average skill level of these IT professionals was assessed at 3.2 on a scale of 5. The country’s banking sector employs roughly 200,000 people overall.
An analysis of recent online fraud incidents in Bangladesh’s banking sector shows that 72 percent of such crimes were carried out through the SWIFT system. Another 20 percent involved manipulation of bank software. Three percent of the frauds were committed using ATMs and plastic cards, 2 percent through mobile banking and check settlements, and 1 percent via internet banking.
As of March 2025, there were 165.7 million deposit accounts and 13.44 million loan accounts in the banking sector. To serve these customers, banks operate 11,381 branches, 12,925 ATMs, and 7,345 cash recycling machines (CRMs). In addition, 133,150 point-of-sale (POS) machines have been installed in shops and restaurants for bill payments. Excluding “Nagad,” there are 1.43 million mobile financial service (MFS) agents in the country, with 145 million MFS account holders. Agent banking outlets number 21,080.
Combined, the total number of bank, agent, and MFS accounts in Bangladesh stands at around 500 million. Of these, debit cards have been issued against 43.45 million accounts, while 2.94 million credit cards and 7 million prepaid cards are in circulation. In addition, around 11.36 million customers currently use various internet-based financial services.