<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/hackers-arrested-over-30m-bank-fraud-exploiting-service-provider-flaw-nm6xjctxm" -->

---
title: Hackers arrested over €30M bank fraud exploiting service...
description: Four suspects were arrested in Brazil and three more charged in Spain and Bulgaria over a €30 million fraud scheme that exploited a software vulnerability at a...
canonical: https://daily.dev/posts/hackers-arrested-over-30m-bank-fraud-exploiting-service-provider-flaw-nm6xjctxm
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Hackers arrested over €30M bank fraud exploiting service provider flaw | daily.dev
og:description: Four suspects were arrested in Brazil and three more charged in Spain and Bulgaria over a €30 million fraud scheme that exploited a software vulnerability at a...
og:url: https://daily.dev/posts/hackers-arrested-over-30m-bank-fraud-exploiting-service-provider-flaw-nm6xjctxm
og:image: https://api.daily.dev/og/posts/Nm6xjCtxm.png
og:image:alt: Hackers arrested over €30M bank fraud exploiting service provider flaw
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Hackers arrested over €30M bank fraud exploiting service provider flaw

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 0 comments

## Summary

Four suspects were arrested in Brazil and three more charged in Spain and Bulgaria over a €30 million fraud scheme that exploited a software vulnerability at a payment-processing service provider used by a German bank, later identified by Brazilian media as Commerzbank. Attackers exploited a flaw introduced by a faulty software update in November 2023 to make unauthorized direct debits from customer accounts, laundering the funds through pass-through accounts, shell companies, and crypto platforms routed to Brazil. Commerzbank confirmed the incident but said customers suffered no financial losses. Brazil's Federal Police executed 21 search warrants in 'Operation Klonen' and seized assets worth roughly $22.4 million; one suspect reportedly used stolen funds to finance a 2024 political campaign.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/hackers-arrested-over-30m-bank-fraud-exploiting-service-provider-flaw>

## Questions this post answers

### How did hackers steal €30 million from a German bank's customers in 2023?

Attackers exploited a software vulnerability introduced by a faulty update at a payment and transaction-processing service provider used by a German financial institution, later identified as Commerzbank. Over four days in November 2023, they made numerous unauthorized direct debit withdrawals from online banking accounts and laundered roughly €30 million through pass-through accounts, shell companies, and virtual-asset platforms routed largely to Brazil.

_Security teams tracking third-party vendor risk in banking follow incidents like this on daily.dev._

### Did Commerzbank customers lose money in the 2023 fraud case involving a service provider flaw?

No, Commerzbank confirmed that although clients were affected by the fraudulent direct debits, customers suffered no financial losses. The bank stated the fraud stemmed from technical issues at a service provider that led to unauthorized withdrawals, and it cooperated extensively with German and Brazilian authorities investigating the case.

_Anyone evaluating third-party service provider risk in banking can follow coverage like this on daily.dev._

## Similar posts on daily.dev

- [Police arrests dozens of suspects in global cybercrime crackdown](https://daily.dev/posts/police-arrests-dozens-of-suspects-in-global-cybercrime-crackdown-gm7wtkr6c) · BleepingComputer · 0 upvotes · 0 comments

---

Tags: [#fintech](https://daily.dev/tags/fintech)

[View this post on daily.dev](https://daily.dev/posts/hackers-arrested-over-30m-bank-fraud-exploiting-service-provider-flaw-nm6xjctxm)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Hackers arrested over €30M bank fraud exploiting service provider flaw","url":"https://daily.dev/posts/hackers-arrested-over-30m-bank-fraud-exploiting-service-provider-flaw-nm6xjctxm","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/hackers-arrested-over-30m-bank-fraud-exploiting-service-provider-flaw-nm6xjctxm"},"datePublished":"2026-08-14T18:07:18.982Z","dateModified":"2026-08-14T18:07:41.703Z","description":"Four suspects were arrested in Brazil and three more charged in Spain and Bulgaria over a €30 million fraud scheme that exploited a software vulnerability at a...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/a784df6cd5e30174ced41beab67aebbb?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/a784df6cd5e30174ced41beab67aebbb?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/hackers-arrested-over-30m-bank-fraud-exploiting-service-provider-flaw-nm6xjctxm","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"fintech","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Hackers arrested over €30M bank fraud exploiting service provider flaw"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/hackers-arrested-over-30m-bank-fraud-exploiting-service-provider-flaw-nm6xjctxm#faq","mainEntity":[{"@type":"Question","name":"How did hackers steal €30 million from a German bank's customers in 2023?","acceptedAnswer":{"@type":"Answer","text":"Attackers exploited a software vulnerability introduced by a faulty update at a payment and transaction-processing service provider used by a German financial institution, later identified as Commerzbank. Over four days in November 2023, they made numerous unauthorized direct debit withdrawals from online banking accounts and laundered roughly €30 million through pass-through accounts, shell companies, and virtual-asset platforms routed largely to Brazil. Security teams tracking third-party vendor risk in banking follow incidents like this on daily.dev."}},{"@type":"Question","name":"Did Commerzbank customers lose money in the 2023 fraud case involving a service provider flaw?","acceptedAnswer":{"@type":"Answer","text":"No, Commerzbank confirmed that although clients were affected by the fraudulent direct debits, customers suffered no financial losses. The bank stated the fraud stemmed from technical issues at a service provider that led to unauthorized withdrawals, and it cooperated extensively with German and Brazilian authorities investigating the case. Anyone evaluating third-party service provider risk in banking can follow coverage like this on daily.dev."}}]}
```

