File-borne breach events · South Asia
India: documented file-borne breach events
India's clearest documented file-borne intrusion is the 2016 Union Bank of India heist attempt, where an email attachment spoofing the Reserve Bank of India delivered malware that reached the bank's SWIFT access.
Overview
What the record shows
India's public record on breach vectors is thin: headline incidents are typically confirmed as events, but the initial vector goes undocumented. The exception is the 2016 Union Bank of India incident, investigated in detail by the press with named confirmation from the bank's chairman, where the record documents an employee opening an email attachment made to look as if it came from the Reserve Bank of India.
That single event carries a lot of signal for the sector: the same playbook as the Bangladesh Bank heist, opening with a document rather than an exploit, against a state-owned bank's payment infrastructure.
Documented events
File-borne incidents in India
Most recent first. Every entry cites the public record it is drawn from.
-
Union Bank of India: 171 million dollar SWIFT heist attempt began with an RBI-lookalike email attachment
In July 2016 attackers used malware delivered via an RBI-lookalike email attachment to steal Union Bank of India's SWIFT access and issue transfer instructions of about 171 million US dollars through the bank's overseas nostro account, closely mirroring the Bangladesh Bank heist. The bank traced the funds across several jurisdictions and blocked or recovered the money within days; chairman Arun Tiwari publicly confirmed the incident and the recovery, and the Central Bureau of Investigation later took over the case.
The documented vector. Malicious email attachment styled as Reserve Bank of India correspondence, dropping malware. A bank employee opened an email attachment which looked as if it had been sent by the Reserve Bank of India, as documented in The Wall Street Journal's investigation of the incident. The attachment dropped malware through which the attackers obtained the bank's SWIFT access codes.
How this class of vector is removed
This class of vector, a document attachment impersonating a trusted institution to drop malware, is removed by deterministic CDR rebuild: the attachment is rebuilt to its format's known-good specification and stripped of active content before delivery, so the dropper does not reach the employee regardless of how credible the sender appears. The Email CDR Relay puts that rebuild on the mail path, and Foresight can score the file's structure ahead of the pipeline to flag likely-malicious construction for the security team.
Content Disarm and ReconstructionEmail CDR RelayForesight predictive file triageGlasswall Halo / Glasswall Meteor / Glasswall Embedded Engine / Glasswall Foresight
- banking
Scope
How to read this page
Every event on this page meets three tests before it is published. It is documented by reliable public sources: a regulator, an official inquiry, the affected organisation's own disclosure, or reputable press with named confirmation, and each entry links to those sources. The initial access or payload delivery travelled as a file, as the public record states it. An email is itself a file, so malicious code in a message and deceptive-hyperlink phishing carried by a message both count; credential attacks and pure network exploits are excluded. And the prevention analysis is conditional: where we say a capability removes a class of vector, that is a statement about how the control treats that class of content, not a claim about what any organisation ran, and not a judgement on the people who dealt with the incident.
This page is a working reference, not an incident report or legal advice. Details reflect the public record on the review date and organisations named here are cited from that record alone.
Elsewhere in the region

