Brazilian and German authorities have disrupted a cyber-enabled bank fraud operation that allegedly stole about €30 million from German bank accounts by exploiting a vulnerability introduced through a faulty software update at a payment and transaction processing provider. Investigators said the attackers used the flaw over four days in November 2023 to trigger unauthorized direct debits and withdrawals from German online banking customers, with media reports identifying Commerzbank as the affected institution. The bank confirmed that clients were impacted but said customers did not ultimately suffer financial losses.
The joint investigation, conducted by Brazil’s Federal Police with support from Germany’s BKA under Operation Klonen, led to arrests in both Brazil and Europe. Authorities said four suspects were arrested in Brazil and three more were identified or detained in Europe for prosecution in Spain and Bulgaria, while police also carried out 21 search-and-seizure warrants. Investigators said much of the stolen money was withdrawn in Brazil, with additional cash-outs in four European countries, and that the laundering scheme involved cloned payment cards; seized assets were reported at up to R$106 million (more than $20 million).

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Brazilian investigators found that one suspect had run for elected office in 2024 and that part of the illicit proceeds was used to support that campaign. Local media reported the person had been a city council candidate in Rio de Janeiro.
Over four days in November 2023, attackers exploited a vulnerability introduced by a faulty software update at a payment and transaction-processing service provider and initiated numerous unauthorized direct debits or withdrawals from German online banking accounts. Authorities said the fraud caused losses of about €30 million and routed much of the stolen money to Brazil, with some cashed out in four European countries.
German and Brazilian media identified Commerzbank as the affected institution, and the bank said its clients were impacted by unauthorized debits tied to technical issues at a service provider. Commerzbank stated that customers would not suffer financial losses from the incident.
Brazilian authorities executed 21 search-and-seizure warrants across seven cities, arrested four suspects in Brazil under preventive detention warrants, and identified or arrested three additional suspects in Europe for prosecution in Spain and Bulgaria. A Brazilian federal court also ordered the seizure of financial assets, vehicles, and real estate worth up to R$106 million, and police seized items including a 3-D printer used to make weapons.
Brazil’s Federal Police, supported by Germany’s BKA and assisted by authorities in Spain, Bulgaria, and the Frankfurt public prosecutor’s office, opened a joint investigation into the bank fraud scheme under Operation Klonen. Investigators traced laundering through pass-through accounts, companies, payment institutions, virtual-asset platforms, and cloned or unauthorized payment cards.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
heise.de
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourcegov.br
Open sourcebka.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.