All scenarios
Banking & Finance

SWIFT compromise & data exfiltration

Fraudulent transfers and customer-data theft under a DORA clock. Handle regulators, customer notification, fraud investigation and market exposure at once.

Free to use for your own tabletop, no email gate.

Scenario brief

SWIFT compromise & data exfiltration, Banking & Finance

The threat

Anomalous SWIFT messages and a spike in card-not-present fraud reveal a deep intrusion. The DORA major-incident clock starts, the supervisor expects an initial report, and the market is watching the share price.

Key injects

  • 01Treasury flags outbound transfers that no one authorised.
  • 02The supervisor opens the DORA initial-notification window.
  • 03A journalist has a screenshot of an internal incident channel.
  • 04Fraud volumes climb as customers report drained accounts.

What's assessed

  • DORA notification timing and content quality
  • Fraud containment vs. service continuity trade-offs
  • Customer-notification and market-disclosure judgement
  • Coordination across fraud, legal and comms

Exercise objectives

  • Classify the incident under DORA and have the initial report drafted inside the exercise window: due 4 hours after classification as major, at the latest 24 hours after awareness.
  • Stop fraudulent outflows without unilaterally taking core payment services down.
  • Run fraud, legal, treasury and communications on one decision cadence with a single log.
  • Prepare customer notification and market communication that survive next-morning scrutiny.

Roles at the table

  • Crisis team lead · Runs the cadence across fraud, IT, legal and comms; arbitrates when clocks collide.
  • IT / SOC forensics · Traces the intrusion behind the SWIFT anomalies; protects evidence while systems stay up.
  • Fraud & payments operations · Freezes suspicious flows and coordinates with correspondent banks and card schemes.
  • Communications / investor relations · Customer lines, press response and the market's reading of every word.
  • Legal & compliance · Owns the DORA reporting clock (4 h / 24 h, 72 h, 1 month) and the GDPR duties running in parallel.
  • Executive board member · Approves service shutdowns, disclosure and spending; answers to the supervisor.

Discussion prompts

  • 01The DORA clock starts at classification, not at certainty. When do you call the incident 'major', and who signs that call?
  • 02Do you cut SWIFT connectivity while transfers are still moving? Price an hour of downtime against one more fraudulent batch.
  • 03Customers post screenshots of drained accounts. Confirm, deny or stay silent, and for how long?
  • 04A journalist quotes your internal incident channel. What changes in the next thirty minutes?
  • 05In the 72-hour intermediate report, what matters more: completeness, or candour about what you still don't know?
  • 06DORA and GDPR notifications run in parallel. Who makes sure the supervisor and the data-protection authority hear the same story?

Suggested timeline

  • 00:00–00:20Anomalous SWIFT messages and fraud spike: triage, first freezes
  • 00:20–01:00Classification call: DORA major-incident decision starts the clock (4 h / 24 h)
  • 01:00–01:50Containment vs. continuity: payment services, correspondent banks, schemes
  • 01:50–02:35Initial report drafted; customer and market lines aligned
  • 02:35–03:00Hot wash: report quality, decision latency, 72-hour and 1-month follow-ups

Run this scenario with your team.