Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2368+ Articles
158+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Hackers Arrested Over €30M Bank Fraud Exploiting Service Provider Flaw
Hackers Arrested Over €30M Bank Fraud Exploiting Service Provider Flaw
NEWS

Hackers Arrested Over €30M Bank Fraud Exploiting Service Provider Flaw

Operation Klonen: Brazilian and German authorities arrest 7 suspects behind a €30M bank fraud exploiting a third-party payment processor vulnerability at Commerzbank.

Dylan H.

News Desk

August 15, 2026
4 min read

Overview

Brazilian and German authorities have announced the results of Operação Klonen (Operation Clone) — a joint investigation between Brazil's Federal Police and Germany's Federal Criminal Police Office (BKA) that led to the arrest of 7 suspects linked to a €30 million (~$34.6M USD) bank fraud targeting German online banking customers. The fraud exploited a vulnerability in a third-party payment and transaction-processing system — not the bank's own infrastructure — underscoring the supply chain risk posed by technology service providers in financial services.

The Attack: What Happened

In November 2023, over a period of four days, the criminal group exploited a flaw introduced by a faulty software update in a third-party payment processor to initiate unauthorized direct debits from German online banking customer accounts. Brazilian authorities reported that the scheme also involved the use of cloned payment cards as part of the fraud mechanics.

Stolen funds were laundered through pass-through accounts, shell companies, and payment platforms spanning Brazil and four European countries. The affected bank — identified by Brazilian media as Commerzbank — confirmed that unauthorized debits were made from customer accounts but stated that customers suffered no direct financial losses, with the bank absorbing all losses directly.

Official Commerzbank statement: "Due to technical issues at a service provider, unauthorized direct debits were made from customer accounts. There was no financial loss to customers. We cooperated closely and extensively with the authorities."

Arrests and Charges

Brazil (4 arrests):

  • Suspects apprehended in Rio de Janeiro, Guarulhos, Goiânia, and Carapicuíba under preventive detention warrants
  • Brazilian federal courts ordered seizure of financial assets, vehicles, and real estate valued up to R$106 million (~$22.4M USD)
  • 21 search and seizure warrants executed nationwide

Europe (3 charged):

  • Suspects charged in Spain and Bulgaria

Charges across both jurisdictions:

  • Aggravated theft via electronic fraud
  • Participation in a criminal organization
  • Money laundering

One suspect is alleged to have used proceeds from the fraud to fund a political campaign after running for elected office in Brazil in 2024.

Root Cause: Third-Party Software Update Failure

The vulnerability that enabled this fraud did not originate within the bank's own systems. A faulty update deployed by a third-party payment and transaction-processing vendor introduced a flaw that allowed the criminal group to bypass authorization controls and initiate unauthorized direct debits at scale.

This is a critical distinction for organizations assessing their security posture: the bank's own controls were not circumvented — its supply chain was. The third-party vendor's change management and software update testing processes failed to catch a flaw that directly enabled €30 million in fraudulent transactions.

Third-Party Risk Management Implications

Operation Klonen is a textbook example of why vendor risk management must extend beyond contractual due diligence into continuous technical monitoring:

  • Software update controls: Third-party vendors deploying updates that affect transaction authorization logic should be subject to pre-deployment security review and staged rollout requirements
  • Change notifications: Financial institutions should require real-time notification of software changes in payment processing systems
  • Anomaly detection: Unauthorized direct debit patterns at the scale of this attack should trigger automated controls — volume, velocity, and geographic anomalies combined warrant near-real-time alerting
  • Contractual liability: Vendor agreements should clearly define liability when vendor-introduced software defects enable fraud, even when the bank itself is not technically breached

Geographic Scope of the Investigation

The multi-country laundering network involved accounts and shell companies in:

  • Brazil
  • Spain
  • Bulgaria
  • Two additional European countries (unnamed in official statements)

The geographic complexity of the money trail required extended cooperation between Brazilian federal authorities and European law enforcement, with the BKA coordinating on the European side of arrests and asset recovery.

References

  • BleepingComputer: Hackers Arrested Over €30M Bank Fraud Exploiting Service Provider Flaw
  • The Record: Investigation of Banking Hack Leads to Arrests in Germany, Brazil
#cybercrime#banking#fraud#supply-chain#arrest#third-party-risk

Related Articles

Who Vets AI's Code? The Scale Challenge Facing Open Source Ingestion

With 85% of enterprises using AI coding tools but only 9% deploying AI-specific security controls, open source ingestion faces a critical vetting gap.

3 min read

China-Linked Storm-1175 Turns N-able N-central Into MSP Ransomware Launchpad

Microsoft warns that the China-linked threat actor Storm-1175 is exploiting a critical zero-day in N-able N-central (CVE-2026-18577) to gain god-mode access to MSP platforms and deploy the custom StormEncryptor ransomware across thousands of downstream client networks.

4 min read

Valve Notifies Steam Hardware Customers of CEVA Logistics Data Breach

Valve is notifying Steam hardware customers in Europe that hackers stole shipping and personal data after compromising its logistics partner CEVA Logistics between July 29 and August 1, 2026. No Steam account credentials or payment data were exposed, but the stolen PII creates a high-quality phishing dataset.

4 min read
Back to all News