Breaking
Cyber CrimeDeveloping Story

Bank fraud arrests expose service provider risk

Arrests in Brazil and Europe follow a €30M bank fraud exploiting a service provider's software flaw.

··2 hours ago·3 min read
silver and gold round coins
Photo by Kanchanara on Unsplash

When a service provider's faulty software update opened a door to German bank accounts in late 2023, the attackers moved fast—and the money moved to Brazil. This week, that trail ended in arrests.

Four days, €30 million

According to the Brazilian and German federal police, the theft unfolded over four days in November 2023 and caused losses of about €30 million ($34.6 million). The attackers initiated numerous unauthorized withdrawals from German online banking accounts and routed the stolen funds to Brazil through a network designed to hide their origin.

The largest share of the money was withdrawn in Brazil, while a smaller portion was cashed out in four European countries, authorities said. The operation was handled jointly by Germany's BKA and Brazil's Federal Police, though neither agency named the affected bank in their public statements.

Faulty update at a service provider

German investigators said the hackers exploited a software vulnerability introduced by a faulty software update at the payment and transaction-processing system of a financial institution. The breach was not a failure of the bank's own systems but a lapse at an external service provider—a distinction that matters for how responsibility is assigned.

While the police statements did not name the bank, Brazilian media identified it as Commerzbank, a major European financial institution that generates more than €11.1 billion ($12.8 billion) in annual revenue.

Commerzbank confirms, customers unharmed

In a statement to BleepingComputer, the bank acknowledged that its clients were affected but said they did not lose any money.

"The fraud case is known and dates back to 2023. Due to technical issues at a service provider, unauthorized direct debits were made from customer accounts. There was no financial loss to customers. We cooperated closely and extensively with the authorities."

— Commerzbank spokesperson, as told to BleepingComputer

That the customers were made whole does not diminish the scale of the heist. The attackers used a mix of pass-through accounts, companies, payment institutions, virtual-asset platforms, and payment cards issued without the beneficiaries' consent to move and hide the proceeds, according to investigators.

Operation Klonen: arrests and warrants

Yesterday, Brazil's Federal Police launched “Operation Klonen,” with support from Germany's BKA, executing 21 search-and-seizure warrants across seven Brazilian cities. The action led to the arrest of four suspects under preventive detention warrants in Rio de Janeiro, Guarulhos, Goiânia, and Carapicuíba.

The suspects face charges including aggravated theft through electronic fraud, participation in a criminal organization, and money laundering. A Brazilian federal court ordered the seizure of financial assets, vehicles, and real estate worth up to R$106 million.

Political ambitions financed by fraud

Brazilian authorities found that one of the suspects ran for elected office in 2024 and used some of the illicit funds to back their political campaign. The detail underscores how cybercrime proceeds can seep into everyday institutions—even electoral politics.

European suspects charged

Separately, three other suspects were identified in Europe and will be prosecuted in Spain and Bulgaria by law enforcement authorities in those countries. The arrests in Brazil and the charges in Europe suggest a coordinated international response, though the full extent of the network's reach has not been disclosed.

Why it matters

This case is a reminder that financial institutions depend on a chain of third-party providers, and a single faulty update at one link can expose hundreds of thousands of customers. For banks, the lesson is to scrutinize the security of every vendor that touches their payment systems—not just their own infrastructure.

The fact that the fraudsters were able to withdraw funds through an external service provider also suggests that credential compromise and transaction monitoring remain weak points. If attackers can exploit a provider's flaw to initiate unauthorized direct debits, then the traditional security perimeter may be less relevant than the integrity of the entire ecosystem.

For consumers, the reassuring part is that Commerzbank covered the losses. But not every bank will do the same, and the next attack could just as easily target a smaller institution with less capacity to absorb the blow.

#bank fraud#brazil#germany#commerzbank#arrests#service provider

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories