Skip to content
Tech News
← Back to articles

Hackers arrested over €30M bank fraud exploiting service provider flaw

read original more articles
Why This Matters

The arrest of cybercriminals over a €30 million bank fraud highlights the ongoing risks associated with software vulnerabilities in financial services. This incident underscores the importance of robust cybersecurity measures and timely updates to prevent large-scale financial thefts, protecting both institutions and consumers. It also demonstrates the increasing sophistication of international cybercrime networks operating across borders.

Key Takeaways

Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers’ bank accounts.

The theft, investigated by the Brazilian and German federal police agencies, occurred over four days in November 2023 and caused losses of around €30 million ($34.6 million).

While neither the Brazilian Federal Police nor Germany's BKA named the affected German financial institution, Brazilian media identified it as Commerzbank, a major European financial institution that generates more than €11.1 billion ($12.8 billion) in annual revenue.

In a statement for BleepingComputer, the bank confirmed that its clients were impacted by the fraudulent activity but customers suffered no financial losses.

"The fraud case is known and dates back to 2023. Due to technical issues at a service provider, unauthorized direct debits were made from customer accounts. There was no financial loss to customers. We cooperated closely and extensively with the authorities," a Commerzbank spokesperson told Bleeping Computer.

German authorities say that the hackers exploited a software vulnerability introduced by a faulty software update at the payment and transaction-processing system of a financial institution.

In November 2023, the attackers initiated numerous unauthorized withdrawals from various German online banking accounts and routed the stolen funds to Brazil through a larger network designed to conceal their origin.

According to the authorities, the largest portion of the funds was withdrawn in Brazil, while a smaller share was cashed out in four European countries.

The police identified another three suspects in Europe, who will be prosecuted in Spain and Bulgaria by law enforcement authorities in the two countries.

Investigators found that the attackers moved and concealed the proceeds through pass-through accounts, companies, payment institutions, virtual-asset platforms, and payment cards issued without the beneficiaries’ consent.

... continue reading