Illustrative image generated with AI
Attack on German Bank Accounts: Seven Arrests Across Germany, Brazil, and Europe
Seven arrested in Germany and Brazil for a €30 million fraud targeting German bank accounts through a payment provider vulnerability.
Text generated by artificial intelligence, published without human review. AI transparency
Seven Arrests Over a €30 Million Fraud
German and Brazilian authorities recently announced seven arrests linked to an attack that allegedly stole around €30 million from German users’ bank accounts in late 2023.
Germany’s Federal Criminal Police Office, the BKA, announced the detention of three suspects in Europe. The charges concern fraud targeting customers of online banking services. Legal proceedings against them will be initiated in Spain and Bulgaria, with the involvement of local authorities and the Frankfurt Public Prosecutor’s Office.
In Brazil, the Federal Police arrested four additional people as part of Operação Klonen, also known as Operation Clone. The operation led to the execution of 21 search and seizure warrants across several locations in the country.
The estimated haul amounts to approximately €30 million, equivalent to $34.7 million. While the figure indicates the financial scale of the attack, authorities have not disclosed how much money was recovered.
The Attack Targeted the Payment Chain
According to the BKA’s reconstruction, the attackers operated over a four-day period in November 2023. During that time, they allegedly carried out numerous unauthorized withdrawals from the accounts of German online banking users.
The exploited entry point was reportedly a vulnerability in a payment provider. The company involved and the specific technical component affected remain unknown. Authorities have not released information about the code, the authentication-bypass method, the compromised systems, or any tools allegedly used by the attackers.
This distinction is significant. The incident has not been described as a simple credential theft operation involving phishing, but rather as an attack on a component of the payment-processing chain. A weakness at that layer can allow attackers to target multiple customers through a single access point, even when the bank’s own systems are not directly compromised.
Brazilian authorities added an operational detail: the use of cloned payment cards. It remains unclear whether the cards were used to withdraw the money directly, move it between accounts, or make purchases that were later converted into cash.
The Bank Has Not Been Officially Identified
None of the law-enforcement agencies has publicly named the affected bank. German and Brazilian media, however, have linked the investigation to Commerzbank.
The bank confirmed an attack worth €30 million in late 2023 and stated that customers would not suffer losses. It did not immediately provide further comments on the latest phase of the investigation.
The lack of an official identification leaves several questions unanswered. It is not known which specific payment provider was involved, which systems were used to authorize the withdrawals, or whether the incident affected a single infrastructure or multiple intermediaries.
The software versions involved have also not been made public. As a result, the incident cannot be linked to a specific release, security advisory, or CVE identifier.
The Money Allegedly Passed Through Several Countries
Following the withdrawals, the money was allegedly transferred and laundered through networks operating in Brazil and four European countries. The geographic distribution of the activity required coordination between police forces and prosecutors in multiple jurisdictions.
The three suspects detained in Europe will face prosecution in Spain and Bulgaria. Spanish and Bulgarian authorities, as well as the Frankfurt Public Prosecutor’s Office, also contributed to the investigation. In Brazil, the operation targeted both the individuals involved and assets that may have been purchased with the proceeds of the fraud.
Brazilian courts ordered the seizure of financial assets, vehicles, and real estate worth more than $20 million. A seizure does not constitute the definitive recovery of the funds: the assets will have to be assessed during the legal proceedings and any subsequent confiscation decisions.
The investigation also uncovered possible links to local politics. One individual identified by investigators was a candidate for elected office in 2024 and allegedly used part of the illicit proceeds to finance the campaign. Local media described the person as a candidate for Rio de Janeiro City Council, without disclosing their name.
A 3D printer allegedly used to manufacture weapons was also seized during the searches. The discovery broadens the investigation beyond bank fraud and money laundering, but by itself does not prove an operational connection between the weapons production and the attack on the bank accounts.
What Banks and Customers Can Do
The available information does not identify any public patches, updates, or workarounds for the payment provider’s vulnerability. It is therefore not possible to recommend a specific version for users to install or a configuration to change.
For online banking customers, the most practical measures remain reviewing account statements and payment notifications, particularly for the period in which the withdrawals occurred. Unrecognized transactions, newly issued cards that were not requested, or anomalous account access should be reported to the bank immediately.
Financial organizations should review the controls applied to third-party providers involved in authorizing and executing payments. In a supply-chain attack, the bank’s own defenses may not be sufficient if an intermediate component can generate or validate fraudulent transactions.
Priority checks include privilege separation, monitoring for anomalous withdrawals, dynamic transaction limits, and correlation between logins, devices, cards, and beneficiary details. However, the public brief does not establish which of these controls, if any, failed during the incident.
An Investigation Still Lacking Technical Details
The arrests and seizures show that investigators have identified a transnational network, but they do not yet clarify the full mechanics of the intrusion. The name of the payment provider, the exploited vulnerability, the method used to clone the cards, and the amount recovered all remain unknown.
There is also no indication that the vulnerability has been added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog. Accordingly, no catalog entry date or associated remediation deadline is available for this case.
For now, the case is being treated primarily as a judicial investigation into fraud, money laundering, and international money transfers. A technical reconstruction of the attack will depend on further statements from the authorities, court documents, and any information published by the bank or the provider involved.
Sources
This article is an original reworking based on the sources below.
