Decoding the world of cybersecurity

€30m banking fraud traced to payment provider flaw

Arrests in Europe and Brazil have followed an investigation into a €30 million German banking fraud that authorities traced to exploitation of a payment provider vulnerability.

€30m banking fraud traced to payment provider flaw
Summary
  • Authorities say attackers exploited a payment provider vulnerability to make unauthorised withdrawals from German online banking accounts in 2023.
  • Four suspects have been arrested in Brazil, while three suspects in Europe face prosecution in Spain and Bulgaria.
  • A weakness inside shared transaction infrastructure transferred financial and operational exposure to banking customers.

A cross-border investigation into a cyber attack that caused an estimated €30 million in losses at a German financial institution has led to arrests in Brazil and criminal proceedings in Europe, more than two years after attackers exploited a vulnerability at a payment provider.

Brazil’s Polícia Federal launched Operação Klonen on 13 August, executing 21 search and seizure warrants and four preventive arrest warrants across several Brazilian states. The investigation began after a German financial institution reported a cyber attack originating in Brazil in late 2023.

German investigators say attackers exploited a vulnerability at a payment provider over four days in November 2023, enabling numerous unauthorised withdrawals from German online banking users. Three suspects detained in Europe are due to be prosecuted in Spain and Bulgaria, while authorities in both countries have assisted the investigation.

Neither German nor Brazilian police named the affected financial institution in their current disclosures. Media reports have linked the incident to Commerzbank, but that attribution has not been formally confirmed by the investigating authorities.

Brazilian investigators say proceeds from the fraud were moved and concealed using payment cards issued without beneficiaries’ consent, pass-through accounts, companies, payment institutions, and virtual asset platforms. Courts authorised the seizure of financial assets, vehicles, and property up to approximately R$106 million.

Compromise of a provider inside the payment chain allowed attackers to create losses across banking customers without having to compromise each victim account independently. Shared transaction infrastructure can therefore concentrate exposure in a service that may sit outside the bank’s own systems while remaining integral to customer transactions.

Banks increasingly depend on specialist providers for payment processing, identity checks, messaging, fraud controls, cloud services, and other functions tied closely to regulated operations. Those relationships create technical trust paths that can transfer supplier vulnerabilities into customer-facing financial loss.

European regulation now treats those dependencies as part of operational resilience. Under the Digital Operational Resilience Act, financial entities must manage information and communications technology third-party risk within their broader resilience framework rather than separating supplier security from regulated operations.

The German attack predates DORA’s application, but the structure of the incident reflects the type of dependency the regime is intended to address. A technical weakness at a provider can leave the regulated institution carrying financial, customer, operational, and reputational consequences.

Criminal accountability has unfolded on a much longer timeline than the original attack. Technical containment can take place within hours or days, while following money flows, identifying suspects, obtaining evidence, coordinating across jurisdictions, and securing asset seizures can continue for years.

The Brazilian Federal Police disclosure says the operation remains part of a wider investigation into electronic banking fraud, criminal organisation, and money laundering.

Several elements remain unresolved publicly, including the identity of the affected financial institution in the official record and the detailed technical circumstances of the payment provider vulnerability. The investigation has nevertheless established a clear sequence from a supplier weakness, through substantial customer losses, to an international criminal case spanning several jurisdictions.

×