Brazil and European police arrest suspects over €30 million Commerzbank fraud tied to payment service provider software flaw

Police in Brazil and Europe say suspects exploited a software flaw at a payment service provider and used it to make unauthorized withdrawals from Commerzbank customer accounts. Authorities say the attack ran for four days in November 2023 and caused about €30 million in losses, with funds routed through pass-through accounts, companies, payment institutions, virtual-asset platforms, and payment cards to hide their origin. Commerzbank said customers did not suffer financial losses and blamed technical issues at a service provider; no CVE or vendor name was disclosed.
Why it matters: This shows how a flaw at a third-party payments provider can be turned into large-scale bank fraud even when the bank itself is not named as the vulnerable system owner. Banks and payment processors should review third-party software updates, transaction controls, and fraud monitoring, while affected customers should still watch account statements for unauthorized direct debits.

Sources

Investigation of banking hack leads to arrests in Germany, Brazil
2026.08.14 98% relevant
This article is a direct update on the same late-2023 Commerzbank-linked fraud case, adding that German and Brazilian authorities made multiple arrests this week, executed 21 search and seizure warrants in Brazil, and said the suspects laundered funds through Brazil and four European countries.
Hackers arrested over €30M bank fraud exploiting service provider flaw
Bill Toulas 2026.08.14 100% relevant
This article establishes the story by identifying the affected bank as Commerzbank, confirming customer impact, and detailing arrests and cross-border money-laundering methods tied to the 2023 exploitation of a service-provider software flaw.
← Back to all stories