Security3 publishers3 min readPublished Updated
A vendor's faulty update moved €30M out of Commerzbank accounts in four days
Seven people now face charges in Brazil, Spain and Bulgaria over a 2023 direct-debit fraud that German police trace to a bad software update at a payment processor.
The Watch · Security desk

What happened
- German and Brazilian authorities said there were multiple arrests this week related to a late 2023 hack that drained an estimated 30 million euros ($34.7 million) from German bank accounts.
- Germany's BKA said three suspects were picked up in Europe and charged with fraud.
- Brazil's federal police said four suspects were arrested in Brazil on similar charges as part of Operacao Klonen (Operation Clone), which executed 21 search and seizure warrants nationwide.
- Over four days in November 2023, the hackers were able to make "numerous unauthorized withdrawals from the accounts of German online banking users" by exploiting a vulnerability in a payment provider, the BKA said.
- Brazilian authorities said the process involved cloned payment cards.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Germany's federal police agency, the BKA, and Brazil's federal police announced arrests this week over the late 2023 theft of an estimated 30 million euros ($34.7 million) from German bank accounts [1]. The detail that matters to anyone who maintains a supplier register: the BKA says the money was taken by exploiting a vulnerability in a payment provider, not in the bank whose customers were debited [4].
The mechanics were fast. Over four days in November 2023, according to the BKA, the attackers made "numerous unauthorized withdrawals from the accounts of German online banking users" by way of that provider flaw [4]. Brazilian authorities said the process involved cloned payment cards [5]. At the headline figure, the operation moved roughly 7.5 million euros a day [17].
Three suspects were picked up in Europe and charged with fraud [2]. Four more were arrested in Brazil on similar charges under Operacao Klonen, or Operation Clone, which executed 21 search and seizure warrants nationwide [3]. That is seven arrests in total [18]. Police said the proceeds were moved and laundered through networks in Brazil and four European countries [6], and Brazilian courts ordered the seizure of "financial assets, vehicles, and real estate" worth more than $20 million [8] - at least 58 percent of the dollar value said to have been taken [19].
The prosecutorial map shows how little the geography of a breach matters to the geography of accountability. The suspects detained in Europe will be prosecuted in Spain and Bulgaria, the BKA said, with Spanish and Bulgarian authorities and the Frankfurt public prosecutor's office assisting the investigation [7].
Neither police agency named the affected bank [9]. Brazilian media reported it was Commerzbank [10], and German media reported in late 2023 that Commerzbank had suffered a 30 million euro hack [11]. The Frankfurt-based bank said at the time that customers would not incur losses [12], and it did not immediately respond to a request for comment from The Record [13].
Which leaves the actual failure point unidentified. The bank absorbed the reimbursement and the coverage; the vulnerability, per the BKA's own description, sat with a payment provider [4] that has not been named by either police force, and whose defect has not been described. Nearly three years on, no other institution wired into the same provider can check whether it was exposed to the same weakness, and no one buying that provider's services today can price the history into a contract. Third-party risk owners will recognise the pattern: the entity with the flaw is the one nobody has to disclose.
Two side notes from Brazil. Police said a person identified in the investigation "was a candidate for elected office in 2024 and used part of the illicitly obtained money in his campaign," without releasing his name [14]; local media reported he had been a city council candidate in Rio de Janeiro [15]. The sweep also turned up a 3-D printer used to make weapons [16].
Watch whether the provider is ever identified through the Frankfurt, Spanish or Bulgarian proceedings, since court filings are now the most likely route to a name. Watch whether Commerzbank confirms or denies the Brazilian media identification [10][13]. And watch whether the $20 million-plus in Brazilian seizures survives contest in court [8], because that number is the only one so far that bears on recovery rather than loss.