Four alleged cybercriminals have been arrested in Brazil, while three additional suspects have been charged in Europe for allegedly exploiting a software vulnerability at a financial service provider to steal money from Commerzbank customer accounts.
The cybercrime investigation, led by Brazilian and German federal police, found that the bank fraud took place over four days in November 2023. Authorities estimate that the attack caused losses of approximately 30 million euros ($34.6 million).
Brazil’s Federal Police and Germany’s Federal Criminal Police Office (BKA) have not officially identified the targeted German financial institution. However, Brazilian media reports named it as Commerzbank, one of Europe’s largest financial institutions, which generates more than 11.1 billion euros ($12.8 billion) in annual revenue.
In a statement to BleepingComputer, Commerzbank confirmed that its customers were affected by the incident but said they did not suffer any financial losses.
A Commerzbank spokesperson told BleepingComputer: “This fraud incident is known and dates back to 2023. A technical issue with the service provider resulted in an unauthorized direct debit from the customer’s account. There was no financial loss to the customer. We cooperated closely and extensively with the authorities.”
German authorities said the suspects allegedly exploited a software vulnerability caused by an incomplete update to the financial institution’s payment and transaction processing systems.
During the November 2023 attack, the criminals allegedly initiated numerous fraudulent withdrawals from online banking accounts in Germany. The stolen funds were then transferred to Brazil through an extensive network designed to conceal their origin.
Authorities said most of the money was withdrawn in Brazil, while smaller amounts were cashed out in four other European countries.
Investigators identified three additional suspects in Europe. Authorities in Spain and Bulgaria are expected to prosecute them as part of the international cybercrime investigation.
According to investigators, the alleged criminal network moved and concealed the proceeds through pass-through accounts, companies, payment institutions, virtual asset platforms, and payment cards issued without the beneficiaries’ consent.
On August 13, Brazilian Federal Police, supported by Germany’s BKA, launched Operation Kronen and executed 21 search and seizure warrants across seven Brazilian cities.
Brazilian authorities said one suspect was preparing to run for office in 2024 and allegedly used some of the stolen money to support political activities.
A Brazilian federal court also ordered the seizure of financial assets, vehicles, and real estate valued at up to 106 million reais ($22.4 million).
The suspects face multiple charges, including aggravated theft involving electronic fraud, participation in a criminal organization, and money laundering.
Security prevention scores can conceal what happens after an attacker gains initial access. When cybercriminals use valid credentials, defensive controls can become significantly less effective.
Blue Report 2026 evaluates defense techniques across different technologies using 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com




