Four suspects were arrested in Brazil and three more charged in Spain and Bulgaria over a €30 million fraud scheme that exploited a software vulnerability at a payment-processing service provider used by a German bank, later identified by Brazilian media as Commerzbank. Attackers exploited a flaw introduced by a faulty software update in November 2023 to make unauthorized direct debits from customer accounts, laundering the funds through pass-through accounts, shell companies, and crypto platforms routed to Brazil. Commerzbank confirmed the incident but said customers suffered no financial losses. Brazil's Federal Police executed 21 search warrants in 'Operation Klonen' and seized assets worth roughly $22.4 million; one suspect reportedly used stolen funds to finance a 2024 political campaign.
Table of contents
Related Articles:Questions this post answers
How did hackers steal €30 million from a German bank's customers in 2023?
Attackers exploited a software vulnerability introduced by a faulty update at a payment and transaction-processing service provider used by a German financial institution, later identified as Commerzbank. Over four days in November 2023, they made numerous unauthorized direct debit withdrawals from online banking accounts and laundered roughly €30 million through pass-through accounts, shell companies, and virtual-asset platforms routed largely to Brazil. Security teams tracking third-party vendor risk in banking follow incidents like this on daily.dev.
Did Commerzbank customers lose money in the 2023 fraud case involving a service provider flaw?
No, Commerzbank confirmed that although clients were affected by the fraudulent direct debits, customers suffered no financial losses. The bank stated the fraud stemmed from technical issues at a service provider that led to unauthorized withdrawals, and it cooperated extensively with German and Brazilian authorities investigating the case. Anyone evaluating third-party service provider risk in banking can follow coverage like this on daily.dev.