Hackers arrested over €30M bank fraud exploiting service provider flaw

by · BleepingComputer

Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers’ bank accounts.

The theft, investigated by the Brazilian and German federal police agencies, occurred over four days in November 2023 and caused losses of around €30 million ($34.6 million).

While neither the Brazilian Federal Police nor Germany's BKA named the affected German financial institution, Brazilian media identified it as Commerzbank, a major European financial institution that generates more than €11.1 billion ($12.8 billion) in annual revenue.

In a statement for BleepingComputer, the bank confirmed that its clients were impacted by the fraudulent activity but customers suffered no financial losses.

"The fraud case is known and dates back to 2023. Due to technical issues at a service provider, unauthorized direct debits were made from customer accounts. There was no financial loss to customers. We cooperated closely and extensively with the authorities," a Commerzbank spokesperson told Bleeping Computer.

German authorities say that the hackers exploited a software vulnerability introduced by a faulty software update at the payment and transaction-processing system of a financial institution.

In November 2023, the attackers initiated numerous unauthorized withdrawals from various German online banking accounts and routed the stolen funds to Brazil through a larger network designed to conceal their origin.

According to the authorities, the largest portion of the funds was withdrawn in Brazil, while a smaller share was cashed out in four European countries.

The police identified another three suspects in Europe, who will be prosecuted in Spain and Bulgaria by law enforcement authorities in the two countries.

Investigators found that the attackers moved and concealed the proceeds through pass-through accounts, companies, payment institutions, virtual-asset platforms, and payment cards issued without the beneficiaries’ consent.

Yesterday, Brazil’s Federal Police launched “Operation Klonen,” with support from Germany’s BKA, and executed 21 search-and-seizure warrants across seven cities in Brazil.

The action resulted in the arrest of four suspects under preventive detention warrants in Rio de Janeiro, Guarulhos, Goiânia, and Carapicuíba.

Brazilian authorities found that one of the suspects ran for elected office in 2024 and used some of the illicit funds to back their political campaign.

A Brazilian federal court also ordered the seizure of financial assets, vehicles, and real estate worth up to R$106 million ($22.4M).

The arrested suspects face various charges, including aggravated theft through electronic fraud, participation in a criminal organization, and money laundering.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report