Bank fraud arrests expose service provider risk
Arrests in Brazil and Europe follow a €30M bank fraud exploiting a service provider's software flaw.
When a service provider's faulty software update opened a door to German bank accounts in late 2023, the attackers moved fast—and the money moved to Brazil. This week, that trail ended in arrests.
Four days, €30 million
According to the Brazilian and German federal police, the theft unfolded over four days in November 2023 and caused losses of about €30 million ($34.6 million). The attackers initiated numerous unauthorized withdrawals from German online banking accounts and routed the stolen funds to Brazil through a network designed to hide their origin.
The largest share of the money was withdrawn in Brazil, while a smaller portion was cashed out in four European countries, authorities said. The operation was handled jointly by Germany's BKA and Brazil's Federal Police, though neither agency named the affected bank in their public statements.
Faulty update at a service provider
German investigators said the hackers exploited a software vulnerability introduced by a faulty software update at the payment and transaction-processing system of a financial institution. The breach was not a failure of the bank's own systems but a lapse at an external service provider—a distinction that matters for how responsibility is assigned.
While the police statements did not name the bank, Brazilian media identified it as Commerzbank, a major European financial institution that generates more than €11.1 billion ($12.8 billion) in annual revenue.
Commerzbank confirms, customers unharmed
In a statement to BleepingComputer, the bank acknowledged that its clients were affected but said they did not lose any money.
"The fraud case is known and dates back to 2023. Due to technical issues at a service provider, unauthorized direct debits were made from customer accounts. There was no financial loss to customers. We cooperated closely and extensively with the authorities."
— Commerzbank spokesperson, as told to BleepingComputer
That the customers were made whole does not diminish the scale of the heist. The attackers used a mix of pass-through accounts, companies, payment institutions, virtual-asset platforms, and payment cards issued without the beneficiaries' consent to move and hide the proceeds, according to investigators.
Operation Klonen: arrests and warrants
Yesterday, Brazil's Federal Police launched “Operation Klonen,” with support from Germany's BKA, executing 21 search-and-seizure warrants across seven Brazilian cities. The action led to the arrest of four suspects under preventive detention warrants in Rio de Janeiro, Guarulhos, Goiânia, and Carapicuíba.
The suspects face charges including aggravated theft through electronic fraud, participation in a criminal organization, and money laundering. A Brazilian federal court ordered the seizure of financial assets, vehicles, and real estate worth up to R$106 million.
Political ambitions financed by fraud
Brazilian authorities found that one of the suspects ran for elected office in 2024 and used some of the illicit funds to back their political campaign. The detail underscores how cybercrime proceeds can seep into everyday institutions—even electoral politics.
European suspects charged
Separately, three other suspects were identified in Europe and will be prosecuted in Spain and Bulgaria by law enforcement authorities in those countries. The arrests in Brazil and the charges in Europe suggest a coordinated international response, though the full extent of the network's reach has not been disclosed.
Why it matters
This case is a reminder that financial institutions depend on a chain of third-party providers, and a single faulty update at one link can expose hundreds of thousands of customers. For banks, the lesson is to scrutinize the security of every vendor that touches their payment systems—not just their own infrastructure.
The fact that the fraudsters were able to withdraw funds through an external service provider also suggests that credential compromise and transaction monitoring remain weak points. If attackers can exploit a provider's flaw to initiate unauthorized direct debits, then the traditional security perimeter may be less relevant than the integrity of the entire ecosystem.
For consumers, the reassuring part is that Commerzbank covered the losses. But not every bank will do the same, and the next attack could just as easily target a smaller institution with less capacity to absorb the blow.
Sources
- BleepingComputer Original source
Continue Reading
ExfilSquad Leak Analysis Confirms 13 Victims
Fortra researchers verified ExfilSquad's access to sensitive data from 13 organizations, likely via misconfigured Power Pages portals.
Scammers exploit Shopify's app to fake refunds
Fraudsters abuse Shopify's notification system, embedding contact info in shipping addresses to trick victims into sending money.
RingCentral Breach Exposes 1.6M Accounts
ShinyHunters leaks data from 1.6 million RingCentral accounts after July hack.