Read More: Bangladesh officials to meet Fed, US investigators over heist
Accounts of the attack on Bangladesh Bank suggest that weak security procedures there made it easier to hack into computers used to send SWIFT messages requesting large money transfers. The bank lacked a firewall and used second-hand, $10 electronic switches to network those computers, according to the Bangladesh police. SWIFT has repeatedly pushed banks to implement new security measures rolled out after the Bangladesh heist, including stronger systems for authenticating users and updates to its software for sending and receiving messages. But it has been difficult for SWIFT to force banks to comply because the nonprofit cooperative lacks regulatory authority over its members. [youtube id="t_lPPxUwdM0"] SWIFT told banks Tuesday that it might report them to regulators and banking partners if they failed to meet a November 19 deadline for installing the latest version of its software, which includes new security features designed to thwart the type of attacks described in its letter. The security features include technology for verifying credentials of people accessing a bank's SWIFT system; stronger rules for password management; and better tools for identifying attempts to hack the software. SWIFT is trying coerce members into prioritising cyber-security by threatening to share confidential information about security lapses that banks want to keep private, said Shane Shook, an independent security consultant who advises central banks. [youtube id="HBP4meBn4OE"] "That type of information sharing is something that no bank likes to see happen without their direct approval and involvement, because it can affect market confidence," Shook said. SWIFT disclosed the new hacks after reports of previous incidents prompted regulators in Europe and the United States to urge banks to bolster cyber-security. Other cases involving fraudulent transfer requests include the theft of more than $12m from Ecuador's Banco del Austro and a failed attempt later in 2015 to steal money from Vietnam's Tien Phong Bank.
Read More: US attorney in Manhattan starts BB heist probe
The attacks have prompted regulators globally to press banks to bolster defences. The Bank of England in April ordered UK firms to detail actions to secure computers connected to the SWIFT system, while the European Banking Authority in May said domestic authorities should stress test banks for cyber risks. The Federal Reserve and other US agencies told banks in June to review protections against fraudulent money transfers. Six US senators on Monday urged the G20 nations to agree when they meet at a summit this weekend on a "coordinated strategy to combat cyber-crime at critical financial institutions."