Skip to main content
Emerging ThreatsData Breaches

Hackers Exploited Service Provider Flaw in €30M Commerzbank Heist

German bank branch interior with customers and payment terminal in foreground.

"The fraud case is known and dates back to 2023. Due to technical issues at a service provider, unauthorized direct debits were made from customer accounts. There was no financial loss to customers. We cooperated closely and extensively with the authorities," a Commerzbank spokesperson told Bleeping Computer.

How a service-provider software flaw produced mass unauthorized debits

German authorities say the incident began with a software vulnerability introduced by a faulty update at the payment and transaction-processing system of a financial institution. In November 2023, attackers leveraged that flaw to initiate numerous unauthorized withdrawals from German online banking accounts over a four-day period. The cumulative theft caused losses of around €30 million (about $34.6 million) before investigators intervened.

Operation Klonen: Brazilian raids, arrests and asset seizures

Brazil’s Federal Police, supported by Germany’s BKA, executed “Operation Klonen” and carried out 21 search-and-seizure warrants across seven Brazilian cities. The action produced preventive-detention warrants and led to the arrest of four suspects in Rio de Janeiro, Guarulhos, Goiânia, and Carapicuíba. A Brazilian federal court ordered seizure of financial assets, vehicles, and real estate worth up to R$106 million (about $22.4 million).

Charges in Brazil and prosecutions in Spain and Bulgaria

The arrested individuals face charges that include aggravated theft through electronic fraud, participation in a criminal organization, and money laundering. Separately, investigators identified three additional suspects in Europe; those individuals will be prosecuted by law enforcement authorities in Spain and Bulgaria.

How the proceeds were laundered and where they were cashed out

According to authorities, the attackers routed the stolen funds to Brazil via a broader concealment network. Investigators found the group moved and concealed proceeds using pass-through accounts, companies, payment institutions, virtual-asset platforms, and payment cards that were issued without the beneficiaries’ consent. The largest portion of the funds was withdrawn in Brazil, while a smaller share was cashed out in four European countries.

Commerzbank confirmation and customer impact

Brazilian media identified the affected German financial institution as Commerzbank, a bank the source notes generates more than €11.1 billion ($12.8 billion) in annual revenue. Commerzbank confirmed to Bleeping Computer that its clients were impacted by the fraudulent activity but said customers suffered no financial losses. The bank emphasized cooperation with authorities in response to the incident.

What this means for technologists, regulators, and affected banks

  • Technologists and security teams: The incident underlines the operational risk introduced by third-party service-provider updates—authorities attribute the root cause to a faulty software update at a payment-processing system. Teams responsible for change control and supply-chain verification will be watching how a single update can create large-scale transactional exposure.
  • Policymakers and regulators: Cross-border flow of illicit funds and prosecution across Brazil, Spain, and Bulgaria illustrate the transnational nature of fraud stemming from a single software defect. Regulators involved in payment system oversight and anti-money-laundering enforcement may focus on controls around providers that process transaction batches or direct-debit operations.
  • Banks and customers: Although Commerzbank reported no customer financial loss, the case demonstrates how quickly unauthorized direct debits can be executed and then dispersed through complex cash-out chains. Banks that rely on third-party transaction processors will likely reassess contractual and technical safeguards tied to updates and rollback procedures.

The case remains an active law enforcement matter spanning continents: for investigators, the immediate tasks are prosecuting the identified suspects and tracing remaining proceeds; for institutions, the concrete lesson is that a single faulty update at a payment processor can cascade into multi-million-euro losses and a cross-jurisdictional criminal investigation. The original reporting is available at BleepingComputer: https://www.bleepingcomputer.com/news/security/hackers-arrested-over-30m-bank-fraud-exploiting-service-provider-flaw/