Chinese security head pulls a practical joke and steals from his own bank

Date:

Share post:

This may seem like a scene straight out of a heist movie, but a Chinese programmer did something as spectacular. Qin Qisheng, a former manager in Huaxia Bank’s technology development centre, stole $1 million in free cash by exploiting a loophole in the bank’s core operating system. In the Huaxia Bank, the withdrawals made in midnight were not recorded. After discovering the flaw way back in 2016, he inserted a few scripts into the system where he could make transactions without triggering an alert.

For nearly a year, made transactions of between 5000 and 20,000 yuan, until by 2018 where he amassed nearly seven million yuan without the knowledge of anyone. Most of the money stayed in the dummy account while a few were invested in stock market.

Even though his bank accept his explanation of testing the security of the bank and that the money was  simply resting on a dummy account he had created, the authorities did not buy it and have sentenced Qin for theft.

“Qin Qisheng said that the matter was complicated and involved lots of work … he believed the bank would not pay attention even if he reported it,” a bank representative told the trial. “We think this reason for not reporting is legitimate,” he added.

“The core business system of Hua Xia Bank was bought from overseas supplier, it was designed without considering the problem of night trading,” Qin said during his trial. “The customer generally would not report to the bank, [so] we were not informed about this situation. The problem was definitely there, the bank just couldn’t find the reason.”

Subscribe

Name(Required)
Privacy(Required)

Upcoming Events

Related articles

Atlanta Set to Host Hacker Halted and Global CISO Forum 2026, Uniting Practitioners and C-Suite Leaders

The Westin Peachtree Plaza will anchor a week of hands-on training, offensive security research, and closed-door executive dialogue...

From Awareness to Relevance: Rethinking How We Teach Cybersecurity

Cybersecurity lessons have a better chance to endure when people first understand how the same risks affect their...

CyberSec Delhi Conference 2026

Securing India’s Power, Defence, Manufacturing & Industrial Ecosystems The CyberSec Delhi Conference 2026 will bring together policymakers, government stakeholders,...

SBOM, VEX, and AI: Dr. Allan Friedman on the Future of Software Supply Chain Security

A conversation on why software transparency is no longer optional, and how AI is about to make it...