Payment transactions of KfW

What has happened?

In the afternoon of 20 February 2017, a mistake in configuration works performed by an experienced IT programmer of KfW caused a temporary system bug in a payment transaction software. This led to multiple payments being made by KfW to four banks. The bug was detected immediately by internal services and corrected the same day. The banks instantly paid back the amounts that had been overpaid. KfW has immediately informed the supervisory authorities about the incident. KfW has also immediately started comprehensive internal and external audits, in order to clarify the causes of the incident in detail. Based on the results of the analysis, necessary further measures will be implemented. KfW has created a special task force for that purpose.

What was the trigger?

For its payment transactions KfW uses several systems and software customary in banking business (standard software, SWIFT). After internal review and release, these systems are transferring payments to KfW's business partners through KfW's Bundesbank account. On 20 February 2017, works were performed in one of the payment systems (SWIFT) used by KfW. Due to a mistake in configuration works of an experienced KfW IT programmer, an incorrect IT configuration in KfW's internal SWIFT system was set. This incorrect configuration coupled with the features of another standard software used by KfW for payment transactions caused an unknown system behaviour. An automatic cycle was triggered which sent out payments repeatedly without any active participation of KfW. The error was rapidly detected and immediately resolved by KfW.

Assessment of KfW

KfW has detected the system's incorrect behaviour very early in the process, immediately mitigated the unwanted action and started the necessary process of analysing the causes. In so doing, the mistake was rapidly identified and eliminated, and the amounts overpaid were successfully demanded back. We regret that during works on the systems, this incident could happen due to human error owing to a configuration mistake. KfW has immediately started comprehensive internal and external audits, in order to clarify the causes of the incident in detail and to draw the corresponding conclusions.

Contact