
MT103 Messages and Financial Crime: Understanding Fraud, Money Laundering, and SWIFT Abuse
The Coalition of Cyber Investigators explore the abuse of SWIFT message MT103 by criminals, explaining how they exploit it and what investigators should look for
Introduction
Every day, banks exchange millions of SWIFT payment messages worth trillions of dollars. Among the most common is the MT103 customer credit transfer. Although entirely legitimate, criminals increasingly exploit the trust surrounding MT103 messages to facilitate fraud, money laundering, investment scams and cyber-enabled financial crime.
Sometimes it is very mistaken.
This article explores how MT103 messages have been used in criminal schemes, including fake MT103 fraud, forged MT103 confirmation scams, money laundering operations, cyber-enabled banking thefts, and the growing problem of exposed financial records appearing in credential dumps and cybercriminal collections. The distinction is important because the MT103 itself is not criminal. The abuse of it is.
The Rise of Fabricated MT103 Fraud
The SWIFT network has been in use since the 1970s and uses a rigid and very specific framework to tag or label information. For example, a tag like :32A: tells a bank that the numbers following it represent the currency and the amount.
However, when looking for indicators that a SWIFT message may be fabricated, it is important to understand that one of the standard characteristics of the modern internet is the use of JSON (JavaScript Object Notation). It is how almost every app and website on your phone or computer organizes and moves information. You can see the official rules for it in RFC 8259. Because JSON is so common, it makes up a huge part of the data used to train AI models. However, investigators know that the SWIFT network does not use JSON and this can be crucial when detecting fabricated messages.
JSON escapes
One major error occurs when you see JSON "escape characters" in a SWIFT message. In the world of JSON, to ensure a computer does not get confused by certain symbols like forward slashes, the system automatically adds a backslash \ before them. This is called "escaping" a character, as explained in section 7 of the JSON standard.
For example, if a document shows text like INV\/2024\/001 instead of a regular INV/2024/001, you are looking at a JSON escape. A real bank terminal would never accept that backslash. Seeing it in a SWIFT message is like finding a digital fingerprint. It suggests the document was likely generated by an AI or pulled from a modern web database rather than a real banking terminal. You can compare this to the official SWIFT MT103 formatting rules, which show no such characters.
Currency codes
Beyond these code-based errors, there are other inconsistencies to watch for. A genuine SWIFT message uses three-letter codes for currency, never symbols like $ or £. Furthermore, while British and American systems use a period “.” for decimals, the ISO 15022 standard used by SWIFT requires a comma, as the decimal separator.
For instance, a real message would show USD1000000,00 rather than $1,000,000.00.
UETR code
Every modern payment includes a UETR (Unique End-to-end Transaction Reference) - a 36-character tracking code built on the UUID v4 standard (RFC 9562) that allows banks to follow a payment in real time. In a SWIFT message, this code is always found in a section labelled "Field 121." It must consist only of hexadecimal characters - numbers and the letters a through f, separated by hyphens into five specific groups (e.g. eb6305c9-1f7f-4de-aed0-16487c27b42d). Many fakes contain random letters like z or x, or use codes that lack the correct structure, immediately proving the document has been fabricated.
One of the most common schemes encountered by investigators involves fabricated SWIFT documentation. In a typical MT103 advance-fee fraud, victims are presented with what appears to be an authentic MT103 confirmation indicating that millions of dollars have supposedly been transferred to their account.
The document often looks convincing. SWIFT references, bank logos, transaction fields, compliance language. Everything appears legitimate, at least at first glance.
Then comes the catch.
The victim is told that a release fee, tax payment, anti-money-laundering charge, insurance premium, or other administrative cost must be paid before the funds can be accessed. The promised payment never arrives because, quite simply, it never existed.
A notable example appears in Lex Foundation Ltd v Citibank, where purported MT103 messages were examined and subsequently identified as fraudulent. Correspondence referenced within the case records indicated that Deutsche Bank confirmed the messages had not been issued through its systems.
There is something strangely fascinating about these scams. Like a stage magician waving one hand while hiding the trick with the other. Victims focus on the impressive-looking payment confirmation while the real question - whether any money actually exists - fades into the background.
Fabricated MT103 Confirmation Documents
The fabricated MT103 confirmation has become especially common in high-value investment fraud and advance-fee schemes.
In many cases, fraudsters distribute documents stating that large sums of money have been transferred under ‘MT103 Direct Transfer’ arrangements. The schemes often present fictitious investment opportunities, sovereign wealth programs or alleged private banking facilities.
Investigators reviewing these documents often encounter recurring warning signs, including:
- Inconsistent SWIFT formatting;
- Incorrect bank identifiers;
- Missing authentication details;
- References to non-existent banking procedures;
- Unverifiable transaction references.
Oddly enough, some fraudulent MT103 documents are so poorly constructed that a trained analyst can identify them within seconds. Others are remarkably sophisticated and can mislead experienced professionals. It depends. Criminal capability varies enormously.
MT103 Money Laundering Red Flags
While fabricated documents attract attention, genuine MT103 messages can also be used in financial crime.
The payment message itself may be authentic, while the underlying transaction conceals criminal activity.
Financial institutions increasingly analyse transaction data for MT103 money laundering red flags, including:
- Payment patterns that are inconsistent with the customer’s known business profile;
- Sudden changes in beneficiary details;
- Transfers involving high-risk jurisdictions;
- Layered payments moving through multiple correspondent banks;
- Repeated transfers lacking clear economic purpose;
- Unusual transaction patterns connected to trade finance activity.
A useful analogy might be a shipping container. The container itself is perfectly lawful. The question is what has been placed inside it.
The same principle applies to payment messaging.
Trade-Based Money Laundering and MT103 Payments
The relationship between trade-based money laundering, MT103 activity and international payments provide opportunities for organised crime syndicates and has become an increasing focus for regulators and investigators.
Trade-based money laundering typically involves manipulating commercial transactions through:
- Over-invoicing;
- Under-invoicing;
- Multiple invoicing;
- False descriptions of goods;
- Phantom shipments that never occur.
Associated payments may then be transmitted through legitimate banking channels using MT103 messages.
The paperwork appears clean. The payments appear ordinary. Yet beneath the surface, criminal proceeds may be moving across borders disguised as commercial activity.
A single piece of evidence, such as an MT103, rarely tells the full story and, on its own, is unlikely to provide enough detail to confirm the outcome of a transaction. Often, a reliable conclusion is only possible when multiple data points are examined together.
Correspondent Banking and AML Surveillance
Monitoring of correspondent banking MT103 messages is now an integral part of financial crime compliance in global banking.
Correspondent banking relationships enable institutions in different countries to provide payment services on behalf of each other. This interconnected structure creates tremendous efficiencies but also carries significant risk, resulting in a requirement for compliance teams to analyse MT103 message fields to identify:
- Sanctions evasion indicators;
- Suspicious routing patterns;
- Unusual beneficiary relationships;
- Rapid movement of funds through intermediary institutions;
- Potential terrorist financing concerns.
The challenge is scale.
Millions upon millions of transactions move through the system. Compliance analysts are searching for anomalies that may be only slightly different from legitimate activity.
Given the volumes and complexity of international banking data, these subtle irregularities are easily obscured, making it difficult to isolate suspicious transactions without rigorous cross-referencing and technical analysis.
Not impossible, but certainly not easy.
Emerging Exposure Risks: Leaked MT103 Messages and Credential Dumps

A less discussed but increasingly important threat involves the exposure of genuine banking documents through credential dumps, misconfigured storage locations, data leaks, and criminal collections traded online.
The Coalition Exposure Tool – Banking & Financial Services module has identified a growing number of financial institutions appearing within exposed datasets. More and more banks are appearing in documents containing credential dumps they probably do not know about. Some exposures appear to have remained publicly accessible for months, and in certain cases, more than a year, suggesting that external threat monitoring and attack-surface visibility controls may not always be identifying these risks quickly enough.
Among the exposed documents were SWIFT MT103 cash transfer messages. In several instances, transaction values exceeded €1 billion.
That figure is eye-catching. But the amount is not necessarily the most important aspect.
These exposed MT103 messages contained information including:
- Sender and recipient bank details;
- Account numbers;
- SWIFT/BIC identifiers;
- Beneficiary information;
- Regulatory and compliance-related data;
- Confidential transaction commentary;
- Payment-routing information.
At first glance, an old payment message may not seem particularly dangerous. Yet cybercriminals rarely rely on a single data source. Information gathered from leaked MT103 records can be combined with credential dumps, phishing intelligence, business email compromise data, identity documents, open-source intelligence (OSINT), and previously breached information to build highly detailed intelligence profiles. Whether the data these messages contain is genuine, fabricated or a mixture of both, the fact that they remain undetected and publicly accessible for extended periods of time, without being subject to investigation and takedown procedures, is worrying and exposes the companies whose details are on the documents to reputational, as well as financial crime risk.
The consequences can be significant.
Threat actors may use exposed MT103 information to support social engineering operations, create forged MT103 confirmations, identify high-value targets, map correspondent banking relationships, conduct account takeover attacks, or strengthen investment fraud narratives. In some cases, historical payment information may provide criminals with insights into transaction flows and operational procedures that would otherwise remain confidential.
The danger is often delayed rather than immediate.
An exposed document discovered today may not be weaponised for months. Attackers conducting reconnaissance are patient. Information collected from one source is often most valuable when combined with information from another.
This issue is especially relevant in the context of correspondent banking. Detailed payment-routing information contained within MT103 messages can reveal institutional relationships and transaction paths, helping criminals craft more believable phishing emails and more convincing fraud documentation.
For banks and financial institutions, the lesson is straightforward. You cannot remediate exposures you do not know exist.
Security teams should therefore consider regular reviews of publicly accessible data sources, OSINT, credential dumps, leaked document repositories, and criminal intelligence collections to determine whether sensitive banking information has become exposed.
If you work for a bank, financial institution, payment processor, or regulated financial services organisation, it may be worthwhile searching for your organisation in the Coalition Exposure Tool.
A proactive search may identify exposures before criminals discover them.
Verifying an MT103 Message
A professionally presented MT103 should never be accepted as proof that a payment has occurred. Investigators should assess both the technical integrity of the message and the wider context of the transaction before reaching any conclusions.
Key verification steps include:
- Review the message structure – Confirm that mandatory MT103 fields are present, correctly formatted, and consistent with SWIFT standards.
- Validate bank identifiers – Check that the sender and recipient BICs are genuine and correspond to the stated financial institutions.
- Examine the UETR – Modern MT103 messages are required to include a Unique End-to-End Transaction Reference (UETR) in Field 121. An invalid UUID format may indicate fabrication.
- Look for technical anomalies – Indicators such as JSON escape characters (e.g. \/), invalid currency codes, incorrect field formats, or non-standard banking terminology can suggest the document was not generated by a genuine SWIFT system.
- Assess the commercial context – Compare the payment with invoices, contracts, customer activity and the stated business purpose. A technically valid MT103 may still facilitate money laundering or fraud.
- Seek independent confirmation – Where appropriate, verify the transaction directly with the issuing financial institution rather than relying solely on documentation supplied by the parties involved.
Ultimately, an MT103 demonstrates that a payment instruction was created or transmitted - it does not, by itself, prove that funds were received, that the underlying transaction was legitimate, or that the payment was properly authorised. Effective verification requires technical validation, independent confirmation, and consideration of the broader investigative picture.
The Bangladesh Bank Fraud Case SWIFT Attack: A SWIFT Message Study
Perhaps the most famous SWIFT message fraud case study remains the Bangladesh Bank SWIFT attack.
In 2015 and 2016, attackers compromised systems connected to the SWIFT network and transmitted fraudulent payment instructions using legitimate banking credentials.
This distinction is crucial.
Unlike fake MT103 fraud schemes that rely on forged documents, the Bangladesh Bank incident involved the use of authentic messaging capabilities. The attackers effectively gained access to trusted infrastructure and used it to issue unauthorised payment orders.
The resulting losses reached tens of millions of dollars and triggered extensive reforms across the international banking sector.
Even today, years later, the case continues to be referenced during cybercrime training programmes and financial investigations. The attack demonstrated that the greatest threat was not necessarily a weakness in SWIFT itself, but weaknesses surrounding the systems that connect to it.
A lock can be exceptionally strong. If someone steals the key, however, the outcome may be the same.
Recent Developments

Recent anti-money laundering initiatives and enhanced transaction-monitoring technologies have improved the detection of suspicious payment activity. Banks increasingly deploy behavioural analytics, machine learning models, and network analysis tools to identify anomalous MT103 transactions before losses occur.
Yet fraud continues to evolve.
Artificial intelligence (AI) and OSINT have made document forgery more accessible. Synthetic identities, sophisticated phishing campaigns, and business email compromise schemes increasingly interfere with payment fraud investigations. Technology changes. Human greed, unfortunately, does not.
Sources of MT103 documents
Another emerging trend is the prolific use of publicly accessible locations including file-sharing platforms, cloud storage services, document repositories, and temporary hosting sites to distribute both genuine and fabricated SWIFT MT103 messages. Investigators are increasingly encountering exposed MT103 records hosted on platforms that were never intended to store sensitive financial information, alongside fabricated MT103 confirmations deliberately uploaded to add an appearance of legitimacy. In some cases, genuine documents appear to have originated from data breaches, compromised email accounts, insider leaks, or poorly secured cloud environments. In others, fraudsters upload fabricated MT103 messages and simply provide victims with a download link, knowing that the existence of a document on a seemingly reputable platform can create a false sense of trust. The distinction between authentic and fraudulent records is becoming increasingly blurred.
A genuine MT103 exposed through a security failure may be repurposed as a template for future frauds, while a fake MT103 hosted on a legitimate platform can appear convincing enough to deceive investors, compliance teams, or even experienced business professionals. It is a curious paradox of modern cybercrime: the platform itself is often trusted, while the document hosted upon it may be entirely untrustworthy. As file-sharing services continue to proliferate, and as attackers become more adept at blending authentic leaked documents with fabricated content, financial institutions face growing challenges in monitoring, validating, and responding to the misuse of payment messaging records across the wider digital ecosystem.

Conclusion
The MT103 message remains one of the most trusted and widely used payment instructions in international banking. It is neither inherently suspicious nor inherently criminal. However, that very trust makes it an attractive tool for fraudsters, money launderers and cybercriminals seeking to exploit the credibility of the global financial system.
Whether investigators are examining a suspected advance-fee fraud, a fabricated MT103 confirmation, trade-based money laundering, an unauthorised payment instruction, or a genuine message exposed through a data breach, the same principle applies: no MT103 should be assessed in isolation. Technical validation, independent verification, and consideration of the wider commercial and investigative context are all essential before conclusions are reached.
As financial crime continues to evolve, so too do the methods used to detect it. Advances in artificial intelligence, open-source intelligence (OSINT) and cyber-enabled fraud have made it easier to create convincing fraudulent documentation and exploit exposed financial information. At the same time, these technologies provide investigators and compliance professionals with new opportunities to identify deception, detect anomalies and strengthen financial crime investigations.
Ultimately, the MT103 is simply a payment message. The real challenge lies in determining whether the transaction it represents is genuine, authorised and legitimate. That requires more than reviewing a document - it requires critical analysis, independent verification and an understanding of the broader financial and intelligence picture.
---
Authored by:
The Coalition of Cyber Investigators, Paul Wright (United Kingdom) & Neal Ysart (Philippines).
©2026 The Coalition of Cyber Investigators. All rights reserved.
The Coalition of Cyber Investigators is a collaboration between Paul Wright (United Kingdom) - Experienced Cybercrime, Intelligence (OSINT & HUMINT) and Digital Forensics Investigator;
Neal Ysart (Philippines) - Elite Investigator & Strategic Risk Advisor, Ex-Big 4 Forensic Leader; and
Lajos Antal (Hungary) - Highly experienced expert in cyberforensics, investigations, and cybercrime.
The Coalition unites leading experts to deliver cutting-edge research, OSINT, Investigations, & Cybercrime Advisory Services worldwide.
Our co-founders, Paul Wright and Neal Ysart, offer over 80 years of combined professional experience. Their careers span law enforcement, cyber investigations, open source intelligence, risk management, and strategic risk advisory roles across multiple continents. They have been instrumental in setting formative legal precedents and stated cases in cybercrime investigations and contributing to the development of globally accepted guidance and standards for handling digital evidence. Their leadership and expertise form the foundation of the Coalition’s commitment to excellence and ethical practice.
Alongside them, Lajos Antal, a founding member of our Boiler Room Investment Fraud Practice, brings deep expertise in cybercrime investigations, digital forensics, and cyber response, further strengthening our team’s capabilities and reach.
The Coalition of Cyber Investigators, with decades of hands-on experience in cyber investigations and OSINT, is uniquely positioned to support organisations facing complex or high-risk investigations.
Our team’s expertise is not just theoretical - it’s built on years of real-world investigations, a deep understanding of the dynamic nature of digital intelligence, and a commitment to the highest evidential standards.