Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2868+ Articles
168+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Hackers Arrested Over €30M Bank Fraud Exploiting Service Provider Flaw
Hackers Arrested Over €30M Bank Fraud Exploiting Service Provider Flaw
NEWS

Hackers Arrested Over €30M Bank Fraud Exploiting Service Provider Flaw

Operation Klonen: Brazilian and German authorities arrest 7 suspects behind a €30M bank fraud exploiting a third-party payment processor vulnerability at Commerzbank.

Dylan H.

News Desk

August 15, 2026
4 min read

Overview

Brazilian and German authorities have announced the results of Operação Klonen (Operation Clone) — a joint investigation between Brazil's Federal Police and Germany's Federal Criminal Police Office (BKA) that led to the arrest of 7 suspects linked to a €30 million (~$34.6M USD) bank fraud targeting German online banking customers. The fraud exploited a vulnerability in a third-party payment and transaction-processing system — not the bank's own infrastructure — underscoring the supply chain risk posed by technology service providers in financial services.

The Attack: What Happened

In November 2023, over a period of four days, the criminal group exploited a flaw introduced by a faulty software update in a third-party payment processor to initiate unauthorized direct debits from German online banking customer accounts. Brazilian authorities reported that the scheme also involved the use of cloned payment cards as part of the fraud mechanics.

Stolen funds were laundered through pass-through accounts, shell companies, and payment platforms spanning Brazil and four European countries. The affected bank — identified by Brazilian media as Commerzbank — confirmed that unauthorized debits were made from customer accounts but stated that customers suffered no direct financial losses, with the bank absorbing all losses directly.

Official Commerzbank statement: "Due to technical issues at a service provider, unauthorized direct debits were made from customer accounts. There was no financial loss to customers. We cooperated closely and extensively with the authorities."

Arrests and Charges

Brazil (4 arrests):

  • Suspects apprehended in Rio de Janeiro, Guarulhos, Goiânia, and Carapicuíba under preventive detention warrants
  • Brazilian federal courts ordered seizure of financial assets, vehicles, and real estate valued up to R$106 million (~$22.4M USD)
  • 21 search and seizure warrants executed nationwide

Europe (3 charged):

  • Suspects charged in Spain and Bulgaria

Charges across both jurisdictions:

  • Aggravated theft via electronic fraud
  • Participation in a criminal organization
  • Money laundering

One suspect is alleged to have used proceeds from the fraud to fund a political campaign after running for elected office in Brazil in 2024.

Root Cause: Third-Party Software Update Failure

The vulnerability that enabled this fraud did not originate within the bank's own systems. A faulty update deployed by a third-party payment and transaction-processing vendor introduced a flaw that allowed the criminal group to bypass authorization controls and initiate unauthorized direct debits at scale.

This is a critical distinction for organizations assessing their security posture: the bank's own controls were not circumvented — its supply chain was. The third-party vendor's change management and software update testing processes failed to catch a flaw that directly enabled €30 million in fraudulent transactions.

Third-Party Risk Management Implications

Operation Klonen is a textbook example of why vendor risk management must extend beyond contractual due diligence into continuous technical monitoring:

  • Software update controls: Third-party vendors deploying updates that affect transaction authorization logic should be subject to pre-deployment security review and staged rollout requirements
  • Change notifications: Financial institutions should require real-time notification of software changes in payment processing systems
  • Anomaly detection: Unauthorized direct debit patterns at the scale of this attack should trigger automated controls — volume, velocity, and geographic anomalies combined warrant near-real-time alerting
  • Contractual liability: Vendor agreements should clearly define liability when vendor-introduced software defects enable fraud, even when the bank itself is not technically breached

Geographic Scope of the Investigation

The multi-country laundering network involved accounts and shell companies in:

  • Brazil
  • Spain
  • Bulgaria
  • Two additional European countries (unnamed in official statements)

The geographic complexity of the money trail required extended cooperation between Brazilian federal authorities and European law enforcement, with the BKA coordinating on the European side of arrests and asset recovery.

References

  • BleepingComputer: Hackers Arrested Over €30M Bank Fraud Exploiting Service Provider Flaw
  • The Record: Investigation of Banking Hack Leads to Arrests in Germany, Brazil
#cybercrime#banking#fraud#supply-chain#arrest#third-party-risk

Related Articles

U.S. Bank Says Breach Claims Related to Fourth-Party Incident

U.S. Bank confirmed exposure tied to a fourth-party vendor breach, stating no evidence of compromise to its own systems, networks, or data repositories.

3 min read

Lidl Discloses Online Shop Breach After Service Provider Hack

German supermarket giant Lidl has notified customers in Germany, Belgium, and the Netherlands that personal data was stolen following a breach at one of...

5 min read

Police Arrest 5,800 Suspects and Seize $293M in Global Anti-Fraud Crackdown

A sweeping international law enforcement operation spanning 97 countries resulted in the arrest of 5,811 suspects and the seizure of $293 million in...

3 min read
Back to all News