Commerzbank Hack: €30M Drained in 2023, 7 Arrested Across Germany and Brazil
German and Brazilian authorities have announced multiple arrests in connection with a late 2023 cyberattack that siphoned an estimated €30 million (approximately $34.7 million) from accounts at Germany's Commerzbank. Germany's Federal Criminal Police Office (BKA) confirmed three suspects were detained in Europe and charged with fraud, while Brazil's federal police arrested four additional individuals under Operação Klonen (Operation Clone), executing 21 search and seizure warrants nationwide. Brazilian authorities identified the method as involving cloned payment cards, while the BKA attributed the breach to the exploitation of a vulnerability in a third-party payment provider over four days in November 2023, during which the perpetrators executed numerous unauthorized withdrawals from online banking accounts.
The stolen funds were subsequently laundered through financial networks spanning Brazil and four European countries, according to investigators. Brazilian courts ordered the seizure of financial assets, vehicles, and real estate worth more than $20 million as part of the operation. Among the suspects, Brazilian police revealed one individual was a candidate for elected office in 2024 and allegedly funneled portions of the illicit proceeds into his campaign. Local media identified him as a former city council candidate in Rio de Janeiro. The European suspects will face prosecution in Spain and Bulgaria, with both nations assisting the BKA alongside the Frankfurt public prosecutor's office.
A 3-D printer allegedly used to manufacture weapons was also seized during the Brazilian raids. Commerzbank, headquartered in Frankfurt, stated at the time of the incident that customers would not bear financial losses, and the bank did not immediately respond to requests for comment following the arrests. The coordinated takedown underscores the growing international cooperation required to dismantle cross-border financial cybercrime operations. For organizations concerned about payment infrastructure exposure, running a regular SSL/TLS checker can help identify misconfigurations that attackers might exploit, while individuals can use our email breach checker to determine whether their banking credentials have surfaced in known data dumps. Security teams should also conduct periodic port scans to ensure no unauthorized services are exposed to the public internet, reducing the attack surface available to financially motivated threat actors.