That said, things are changing significantly with SWIFT gpi payments and the much more automated nature of the new system may actually make techniques such as fake sends more, rather than less, effective until solid mitigation strategies are attached.
That doesn't sound impressive at all by modern standards. At the very least they should have some kind of challenge-response scheme.
The bigger point I should have made is that most send fraud doesn't actually occur on SWIFT and is conducted using falsified documents to give the impression of a correct send, typically to get funds released before the fraud is revealed. It relies much more on social engineering than any kind of actual systems hacking skill.
There are some additional hardware/special componentes one has to use to connect to SWIFT, those boxes arrive pre-configured at your datacenter.
For sure, the typical HN-mentality is: "there is no security and since this a dumb bank/financial-service, they are just trolling and they dont know what they are doing" - no, let me tell you that you are wrong with this assumption: SWIFT is pretty secure and there haven't been any larger (successful) attacks on the network itself (hint Central Bank of Bangladesh losing 90m in a CEO-scam is not a problem of SWIFT, same for similar cases)
Perhaps it was not in SWIFT's domain of responsibility. But it was for sure a problem for them and it's why they started CSP.
However, as the other reply said to you... I've really not seen any evidence the SWIFT system isn't decently well constructed. When attacks (such as Bangladesh) have happened it has been due to not following best practices as established by SWIFT and other institutions.
Yes.
More common is to hack any bank connected to SWIFT, and send messages on the SWIFT network over that bank's SWIFT terminal.