Software Vulnerability at Service Provider Enables ₹300 Crore Bank Fraud

The420.in Staff
5 Min Read

Brazilian and German authorities have taken action against cybercriminals accused of exploiting a software vulnerability at a service provider to carry out an alleged €30 million bank fraud, equivalent to around ₹300 crore. Four suspects have been arrested in Brazil, while three other suspects have been identified in Europe and are facing legal proceedings. Investigators allege that the attackers exploited a weakness in the payment and transaction-processing system of a financial institution to make unauthorised withdrawals from customers’ online banking accounts.

The cyberattack took place over four days in November 2023. According to investigators, the attackers initiated numerous unauthorised withdrawals from German online banking accounts and moved the money to Brazil through an extensive network. Multiple layers of transactions were subsequently used to conceal the origin and movement of the funds.

Faulty Software Update Opened the Way

German and Brazilian federal investigators said the criminals exploited a technical vulnerability created by a faulty software update issued by a service provider. The weakness allegedly allowed the attackers to initiate unauthorised direct debits from customers’ bank accounts.

German authorities have not publicly identified the affected financial institution. However, Brazilian media reports identified it as Commerzbank, one of Germany’s major financial institutions. The bank confirmed that its customers had been affected by fraudulent activity in 2023 but said customers did not suffer any financial loss. The bank also said it had cooperated extensively with authorities during the investigation.

FCRF Launches Flagship Certified Cyber Security Auditor (CCSA) Program for Next-Generation Cyber Auditors

The case highlights the potential consequences of vulnerabilities in third-party systems that are connected to financial institutions. A flaw introduced through a software update can potentially provide criminals with an opportunity to manipulate financial transactions at scale.

Funds Moved Through an International Network

Investigators said the attackers withdrew money from several German online banking accounts before transferring the proceeds to Brazil. Once the funds reached Brazil, members of the alleged criminal network reportedly withdrew or transferred the money through different channels in an effort to hide its origin.

Authorities said the largest portion of the funds was withdrawn in Brazil, while a smaller amount was cashed out in four European countries. Investigators identified the use of pass-through accounts, companies, payment institutions, virtual-asset platforms and payment cards allegedly issued without the consent of the actual beneficiaries.

The complex movement of funds has prompted authorities to examine the financial trail across multiple jurisdictions. Investigators are also working to establish the roles played by individual suspects in receiving, transferring and concealing the alleged proceeds.

Seven Suspects Under Investigation

Brazil’s Federal Police launched Operation Klonen with support from Germany’s Federal Criminal Police Office, known as the BKA. Authorities executed 21 search-and-seizure warrants across seven Brazilian cities as part of the operation.

Four suspects were placed under preventive detention in Rio de Janeiro, Guarulhos, Goiânia and Carapicuíba. Three additional suspects were identified in Europe and are expected to face prosecution in Spain and Bulgaria.

The arrested suspects face allegations including aggravated theft through electronic fraud, participation in a criminal organisation and money laundering. Investigators are continuing to examine how the technical attack was planned, who coordinated the alleged network and how the stolen funds were distributed.

Alleged Political Campaign Funding

Brazilian investigators also identified one suspect who reportedly ran for elected office in 2024. Authorities allege that some of the illicit proceeds were used to support the suspect’s political campaign.

A Brazilian federal court has additionally ordered the seizure of financial assets, vehicles and real estate linked to the suspects. The total value of the assets targeted for seizure is estimated at around R$106 million, or approximately ₹190 crore.

The investigation remains ongoing, with Brazilian and German authorities examining the technical vulnerability, the international movement of the alleged stolen funds and the mechanisms used to conceal their source.

The case demonstrates how weaknesses in third-party financial technology infrastructure can create opportunities for large-scale cybercrime. It also underscores the importance of secure software updates, continuous monitoring of transaction systems and rapid detection of unusual banking activity to prevent attackers from exploiting technical vulnerabilities across interconnected financial networks.

Stay Connected