Hackers arrested over €30M bank fraud exploiting service provider flaw

A massive bank heist involving a service provider flaw has come to an end, with four cybercriminals arrested in Brazil and three more charged in Europe. The brazen theft, which occurred over four days in November 2023, resulted in losses of around €30 million ($34.6 million) for Commerzbank customers.

According to investigators, the hackers exploited a vulnerability introduced by a faulty software update at the payment and transaction-processing system of a financial institution. This allowed them to initiate numerous unauthorized withdrawals from various German online banking accounts, routing the stolen funds to Brazil through a complex network designed to conceal their origin.

The authorities have revealed that the attackers used pass-through accounts, companies, payment institutions, virtual-asset platforms, and payment cards issued without the beneficiaries’ consent to move and conceal the proceeds. In some cases, the illicit funds were even used to support the political campaigns of one of the suspects, who ran for elected office in 2024.

The investigation was a joint effort between Brazil’s Federal Police and Germany’s BKA, with support from law enforcement authorities in Spain and Bulgaria. Yesterday, Brazilian authorities launched “Operation Klonen,” executing 21 search-and-seizure warrants across seven cities in Brazil and arresting four suspects under preventive detention warrants.

One of the most disturbing aspects of this case is how easily the attackers were able to move large sums of money through a network of shell companies and payment platforms. This highlights the need for banks and financial institutions to work closely with service providers to ensure that vulnerabilities are identified and patched quickly, before they can be exploited by cybercriminals.

The Commerzbank has confirmed that its clients were impacted by the fraudulent activity, but fortunately, no customers suffered any financial losses due to their swift cooperation with the authorities. The bank’s spokesperson stated that the fraud case dates back to 2023 and was caused by technical issues at a service provider, which led to unauthorized direct debits from customer accounts.

The arrests and charges in this case are a significant blow to cybercrime groups, but it’s essential for individuals and businesses to remain vigilant. To avoid falling victim to similar attacks, it’s crucial to stay informed about the latest threats and vulnerabilities, as well as to implement robust security measures, such as multi-factor authentication and regular software updates.

As we’ve seen in this case, even with valid credentials, prevention scores can drop sharply once attackers gain access. This emphasizes the importance of continuous monitoring and improvement of security controls to prevent lateral movement and minimize damage after initial access.


Source: Bleeping Computer — 2026-08-14