discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Hackers Arrested Over €30M Bank Fraud Exploiting Service Provider Flaw

Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers' bank accounts.

By Bill Toulas·Aug 14·bleepingcomputer.com·2 min read

Intelligence analysis by Llama

Hackers Arrested Over €30M Bank Fraud Exploiting Service Provider Flaw
Image: bleepingcomputer.com

Hackers exploited a software vulnerability introduced by a faulty software update at the payment and transaction-processing system of a financial institution, resulting in losses of around €30 million. The attackers initiated numerous unauthorized withdrawals from various German online banking accounts and routed the stolen funds to Brazil through a larger network designed to conceal …

Why it matters

This story matters to someone following Security because it highlights the importance of securing service providers and payment systems to prevent large-scale bank fraud.

Imagine someone found a way to hack into a bank's system and take money from people's accounts without them knowing. This is what happened in a big bank in Europe, and the people who did it got caught. The bank's customers didn't lose any money, but it's still a big problem because it could have happened to anyone.

Analysis

Operation Klonen and the Arrests in Brazil

The Brazilian Federal Police launched 'Operation Klonen' with support from Germany's BKA, and executed 21 search-and-seizure warrants across seven cities in Brazil. The action resulted in the arrest of four suspects under preventive detention warrants in Rio de Janeiro, Guarulhos, Goiânia, and Carapicuíba. Brazilian authorities found that one of the suspects ran for elected office in 2024 and used some of the illicit funds to back their political campaign.

The Investigation and Charges

The police identified another three suspects in Europe, who will be prosecuted in Spain and Bulgaria by law enforcement authorities in the two countries. Investigators found that the attackers moved and concealed the proceeds through pass-through accounts, companies, payment institutions, virtual-asset platforms, and payment cards issued without the beneficiaries' consent. The arrested suspects face various charges, including aggravated theft through electronic fraud, participation in a criminal organization, and money laundering.

The Impact on Commerzbank Customers

In a statement for BleepingComputer, the bank confirmed that its clients were impacted by the fraudulent activity but customers suffered no financial losses. 'The fraud case is known and dates back to 2023. Due to technical issues at a service provider, unauthorized direct debits were made from customer accounts. There was no financial loss to customers. We cooperated closely and extensively with the authorities,' a Commerzbank spokesperson told Bleeping Computer.

Key points

  • Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider.
  • The attackers initiated numerous unauthorized withdrawals from various German online banking accounts and routed the stolen funds to Brazil through a larger network designed to conceal their origin.
  • The Brazilian Federal Police launched 'Operation Klonen' with support from Germany's BKA, and executed 21 search-and-seizure warrants across seven cities in Brazil.
  • The arrested suspects face various charges, including aggravated theft through electronic fraud, participation in a criminal organization, and money laundering.
The Upside

If the arrested suspects are convicted and sentenced to prison, it could serve as a deterrent to other cybercriminals and reduce the number of similar attacks in the future.

The Downside

The fact that the attackers were able to move and conceal the stolen funds through various channels suggests that they may have had inside help or used sophisticated money laundering techniques, which could make it difficult to recover the stolen funds.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagsbank-fraudcybercrimeservice-provider-flawgermanybrazileurope

Author

Bill Toulas

Intelligence analysis by

Llama

Published

Aug 14, 2026

Source

bleepingcomputer.com

Share

Topics

bank-fraudcybercrimeservice-provider-flawgermanybrazileurope

Related

More from this desk

Aug 14·schneier.com

Upcoming Speaking Engagements

Bruce Schneier shares his upcoming speaking engagements, including LAcon V in Anaheim, California, USA, a League of Women Voters event, Elevate Festival in Toronto, Canada, CanSecWest 2026 in Vancouver, Canada, and ATTENTION: Democracy, Rebuilt in Montreal, Canada.

Aug 14·bleepingcomputer.com

Hackers Exploit macOS Screen Sharing Flaw to Deploy Monero Miner

NCSC warns of active macOS vulnerability exploitation for cryptocurrency mining.

Aug 14·bleepingcomputer.com

The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI

The article discusses the evolving attack chain in Google Workspace security, where OAuth tokens become the entry point for attackers, and AI agents are increasingly used to exploit vulnerabilities. The author argues that security teams need to rethink their defenses to a…

Aug 14·bleepingcomputer.com

Max severity SAP Commerce Cloud flaw now targeted in attacks

A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused.