Published Security3 min read
A vendor's faulty update moved €30M out of Commerzbank accounts in four days
Seven people now face charges in Brazil, Spain and Bulgaria over a 2023 direct-debit fraud that German police trace to a bad software update at a payment processor.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Four cybercriminals were arrested in Brazil over allegations they exploited a vulnerability at a service provider to withdraw funds from Commerzbank customers' accounts.
- The theft, investigated by the Brazilian and German federal police agencies, occurred over four days in November 2023 and caused losses of around 30 million euros ($34.6 million).
- Police identified another three suspects in Europe, who will be prosecuted in Spain and Bulgaria by law enforcement authorities in those two countries.
- German authorities say the hackers exploited a software vulnerability introduced by a faulty software update at the payment and transaction-processing system of a financial institution.
- Neither the Brazilian Federal Police nor Germany's BKA named the affected German financial institution; Brazilian media identified it as Commerzbank.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Brazil's Federal Police arrested four people and authorities in Europe charged three more over a scheme that pulled roughly €30 million ($34.6 million) out of German bank accounts across four days in November 2023 [1][2][3]. The entry point was not the bank's own controls: German authorities say the attackers exploited a software vulnerability introduced by a faulty software update in a payment and transaction-processing system [4].
Neither the Brazilian Federal Police nor Germany's BKA named the institution, and Brazilian media identified it as Commerzbank [5]. The bank confirmed to BleepingComputer that its clients were hit but bore no losses. "Due to technical issues at a service provider, unauthorized direct debits were made from customer accounts. There was no financial loss to customers," a spokesperson said [6][7].
The two descriptions do not sit perfectly on top of each other. The bank locates the problem at a service provider [7]; the German authorities describe a faulty update at the payment and transaction-processing system of a financial institution [4]. That gap is the whole story for anyone drawing a trust boundary, because in both versions the exploited defect lives in code the customer never touched and, on the available account, outside the bank's own authentication path [11].
Note the instrument. The bank's word is "direct debits," not logins [7]. Nothing in the published police or bank statements alleges stolen customer credentials [11]. Money left accounts because instructions entered the processing chain and were honoured, at an average of about €7.5 million a day for four days [12].
Withdrawals hit numerous German online banking accounts and were routed to Brazil through a network built to obscure origin [8]. The largest share was cashed out in Brazil, a smaller share in four European countries [9]. Investigators say the proceeds moved through pass-through accounts, companies, payment institutions, virtual-asset platforms, and payment cards issued without the named beneficiaries' consent [10].
The enforcement action, Operation Klonen, ran 21 search-and-seizure warrants across seven Brazilian cities with BKA support, producing four preventive detentions in Rio de Janeiro, Guarulhos, Goiânia and Carapicuíba [13][14]. A federal court ordered seizure of assets worth up to R$106 million ($22.4 million), about 65 percent of the stolen sum [15][16]. Investigators also found that one suspect ran for elected office in 2024 and used some of the money to fund the campaign, meaning proceeds were still being spent roughly a year after the four-day window [17][18]. Charges include aggravated theft through electronic fraud, participation in a criminal organization, and money laundering [19].
For Commerzbank, which reports more than €11.1 billion in annual revenue, the loss is about 0.27 percent of a year's top line, and the bank made customers whole [7][20][21]. The transferable lesson is not about the size of the write-off. It is that a processor's release pipeline was sufficient to authorise withdrawals from third-party accounts, and most institutions inventory vendors by contract and data access rather than by which of them can initiate a debit.
Watch whether the service provider is ever named, since the remediation history is not public. Watch the Spanish and Bulgarian prosecutions of the three European suspects, which will test how far the recovery reaches beyond Brazil [3]. And watch whether supervisors treat a vendor's bad update as an outsourcing-controls failure at the bank, or as somebody else's bug.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Four cybercriminals were arrested in Brazil over allegations they exploited a vulnerability at a service provider to withdraw funds from Commerzbank customers' accounts.
- [2]
The theft, investigated by the Brazilian and German federal police agencies, occurred over four days in November 2023 and caused losses of around 30 million euros ($34.6 million).
ReportedView cited source - [3]
Police identified another three suspects in Europe, who will be prosecuted in Spain and Bulgaria by law enforcement authorities in those two countries.
ReportedView cited source - [4]
German authorities say the hackers exploited a software vulnerability introduced by a faulty software update at the payment and transaction-processing system of a financial institution.
- [5]
Neither the Brazilian Federal Police nor Germany's BKA named the affected German financial institution; Brazilian media identified it as Commerzbank.
ReportedView cited source - [6]
In a statement to BleepingComputer, the bank confirmed that its clients were impacted by the fraudulent activity but that customers suffered no financial losses.
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- bleepingcomputer.comBill ToulasAug 14Hackers arrested over €30M bank fraud exploiting service provider flaw
- helpnetsecurity.comSinisa Markovic6d agoPolice bust cybercrime ring accused of stealing €30 million in four-day spree
Additional citations
- BleepingComputer, citing Brazilian Federal Police
- German authorities
- Commerzbank



