Full research report

Hackers arrested over €30M bank fraud exploiting service provider flaw

Original reporting ↗
★ Threat intelligence assessment medium confidence

Executive assessment

Operation Klonen is a significant multi-jurisdictional law enforcement success against a financially sophisticated criminal network that identified and rapidly weaponised a software defect in a third-party payment service provider to drain approximately €30 million from German bank accounts over just four days in November 2023. The three-year gap between the fraud and the August 2026 arrests reflects the complexity of tracing layered money flows across virtual-asset platforms, shell companies, and multiple jurisdictions spanning two continents. The involvement of a Rio de Janeiro city council candidate who allegedly used stolen funds for a 2024 election campaign adds a politically sensitive dimension to the case. Critically, neither the payment service provider's identity nor the technical specifics of the authorisation bypass have been publicly disclosed, limiting independent verification of whether the flaw has been fully remediated. For defenders, the episode underscores the supply-chain risk posed by third-party payment processors: a single inadequately reviewed software update can create an exploitable authorisation gap that criminal actors detect and exploit faster than bank monitoring systems can respond.

What happened

In November 2023, an international criminal network exploited a software flaw introduced by a faulty update to an unnamed payment service provider's booking system, initiating numerous unauthorised direct debits from German online banking accounts over approximately four days. An estimated €30 million was drained and routed primarily to Brazil, with a smaller share distributed across four European countries through pass-through accounts, shell companies, virtual-asset platforms, and payment cards issued without beneficiaries' consent. Brazil's Federal Police launched Operation Klonen on 13–14 August 2026 with BKA and Frankfurt prosecutor support, arresting four suspects in Brazil and charging three further suspects in Spain and Bulgaria. Commerzbank confirmed its customers were affected but stated that no customers incurred financial losses.

Affected scope

German online banking customers of Commerzbank; an unnamed payment and transaction-processing service provider. Money laundering infrastructure spanned Brazil, Spain, Bulgaria, and at least two other European countries. Exact customer count not publicly disclosed.

Technical assessment

Attackers identified and exploited a weakness in the booking and authorisation process of a third-party payment service provider, introduced through a faulty software update. The flaw permitted unauthorised direct debits to be initiated against German bank accounts without legitimate customer authorisation. Funds were then obfuscated through layered financial structures including virtual-asset platforms before being cashed out. The precise technical nature of the authorisation bypass—and whether it required any prior account access or was exploitable remotely—has not been disclosed by investigators.

Recommended defensive actions

  1. Audit third-party payment service provider update procedures: require staged rollout, regression testing, and sign-off on authorisation-control changes before production deployment
  2. Monitor for anomalous direct debit volume spikes originating from a single payment processor over short time windows and alert on deviations from established baselines
  3. Implement real-time transaction velocity controls and automated customer-notification triggers for high-frequency or high-value account debits
  4. Review contractual obligations with payment service providers to mandate rapid vulnerability notification, incident response SLAs, and liability terms for software-introduced flaws
  5. Verify that customer compensation and chargeback procedures are documented, tested, and operable in the event of a third-party payment provider compromise

Uncertainties and evidence gaps

  • The identity of the payment service provider has not been disclosed by German or Brazilian authorities
  • The precise technical mechanism of the authorisation bypass has not been publicly detailed
  • The number of individual German bank customers affected has not been released
  • Whether the payment provider vulnerability has been fully remediated is unconfirmed in public reporting
  • The extent of any additional undisclosed financial institutions affected beyond Commerzbank is unknown

Vulnerability flow

Defender-oriented path reconstructed only from sourced report findings. Unknown stages are omitted.

AccessRemote; attackers required knowledge of the payment service provider's vulnerable booking interface; no evidence that prior authenticated customer access was needed
ComponentThird-party payment and transaction-processing service provider's booking and authorisation process
MechanismA faulty software update introduced a flaw that permitted unauthorised direct debits to be initiated against German online banking accounts without valid customer authorisation
ImpactMass unauthorised withdrawals totalling approximately €30 million over four days; funds exfiltrated internationally via layered laundering infrastructure
DetectionUnusual volume and velocity of direct debit transactions originating from a single payment processor; anomalous geographic routing of outgoing funds to Brazil and multiple European countries
MitigationApply corrective software update to the payment service provider's booking system; enforce authorisation validation controls; require verifiable customer consent for all direct debit initiations
Exploitation status

No CVE assigned; a software flaw introduced by a faulty update to an unnamed payment service provider's booking system was exploited over four days in November 2023 to initiate mass unauthorised direct debits from German bank accounts. Arrests followed in August 2026; no evidence of ongoing exploitation.

The investigation began with a BleepingComputer report on Operation Klonen, a joint Brazil–Germany law enforcement action against a network that exploited a payment service provider flaw to steal €30 million from Commerzbank customers in November 2023. Searches and article fetches across English and German-language sources confirmed the core facts, identified the BKA and Frankfurt Generalstaatsanwaltschaft as German lead authorities, and corroborated the vulnerability description as a faulty-software-update flaw in a payment booking process. No CVE, named service provider, or public proof of concept was found across any source, and official BKA press material was not directly retrieved, leaving sourcing reliant on multiple credible secondary reports.

  1. What are the confirmed facts in the primary report?
    Fetched BleepingComputer article and extracted all factual claims
    bleepingcomputer.com ↗

    Four arrested in Brazil; three charged in Europe; Operation Klonen; fraud occurred November 2023 over four days; €30 million; Commerzbank identified by Brazilian media; service provider flaw introduced by faulty software update; no CVE stated

    why Establishes the event baseline and provides the only available Commerzbank on-record statement confirming customer impact but no customer losses

  2. Is there independent corroboration beyond BleepingComputer?
    Searched for Operation Klonen, BKA, Commerzbank, Brazil arrests 2026

    The Record (Recorded Future News) and multiple German outlets including Handelsblatt, blogspan.net, and Badische Zeitung also covered the story, all confirming arrests, the operation name, and the vulnerability description

    why Multiple independent outlets repeating the same core facts across English and German press elevates confidence; The Record adds detail on a 3D printer seizure and the city council candidate suspect

  3. What additional detail does The Record provide?
    Fetched The Record article
    therecord.media ↗

    Confirmed seven total arrests; cloned payment cards used in the fraud; one suspect was a 2024 Rio de Janeiro city council candidate who used stolen funds for their campaign; a 3D printer for manufacturing weapons was also seized

    why Provides independent corroboration from a specialist security news outlet and adds operational detail about the money laundering and physical-asset seizures

  4. Is there an official BKA press release to cite as a primary authority source?
    Fetched BKA 2026 press release index and searched for BKA Frankfurt prosecutor statement
    bka.de ↗

    No Operation Klonen press release visible on the retrieved BKA index page; German media articles attribute statements to BKA and to Oberstaatsanwalt Benjamin Krause of the Frankfurt prosecutor's office

    why Official attribution is confirmed through credible German media quotes; the absence of a directly retrieved BKA URL is noted as a sourcing gap that slightly reduces confidence

  5. What technical language do German authorities use to describe the vulnerability?
    Fetched blogspan.net German-language article
    blogspan.net ↗

    Vulnerability described as 'Schwachstelle im Buchungsprozess bei einem Zahlungsdienstleister' (flaw in the booking process of a payment service provider) arising from a faulty software update; provider identity not disclosed; no CVE assigned

    why Confirms the technical framing in authorities' own language and establishes that no product name or CVE identifier has entered the public record

  6. Does Handelsblatt provide additional authority-sourced or technical detail?
    Fetched Handelsblatt article
    handelsblatt.com ↗

    Confirmed BKA and Generalstaatsanwaltschaft Frankfurt as German leads; charges described as Computerbetrug (computer fraud); damage described as 'Millionenbereich' without exact figure; no named provider or CVE

    why Adds authoritative German financial press corroboration and identifies the Frankfurt prosecutor's office, enabling a more precise authority attribution

  7. Is there a direct prosecutor quote and any further technical specifics?
    Fetched wirtschaftsticker.com article
    wirtschaftsticker.com ↗

    Oberstaatsanwalt Benjamin Krause quoted saying cybercrime perpetrators cannot feel safe; no additional technical specifics beyond those already confirmed; multi-year investigation confirmed

    why Provides named prosecutorial attribution and confirms the investigation spanned approximately three years from the November 2023 incident to the August 2026 arrests

Actorsunnamed international criminal network (Brazil / Spain / Bulgaria)
TargetsCommerzbank customersGerman online banking usersunnamed payment and transaction-processing service provider

Research coverage

All 68 registered source leaves were evaluated for this run: 60 completed, 0 were unavailable, 1 failed and 7 were disabled. For this story, 1 registered sources supplied useful evidence (1 primary, 0 corroborating, 0 contextual and 0 PoC/exploit references). 59 completed sources contained no matched information for this story.

Primary evidence Independent corroboration Operational context PoC reference Checked — no match Unavailable Failed Disabled
Complete source-by-source audit 68 sources
SourceRun resultValueWhy it was useful — or not
BleepingComputernews ok8 records Primary evidence2 matched items Published the source report used to frame and date the event. Supplied independent analysis opened and verified during focused research.
AlienVault OTXdark_web failed0 records Failed The current collection attempt failed; this source cannot support the report.
CIRCL CVEcve ok30 records Checked — no match The source completed, but none of its retained records matched this story.
CISA Alertsnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
CISA KEVkev ok1665 records Checked — no match The source completed, but none of its retained records matched this story.
Cisco PSIRTvendor_advisory ok5324 records Checked — no match The source completed, but none of its retained records matched this story.
Cisco Talosnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
deepdarkCTI CVE most exploiteddeepdarkcti ok94 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI Discorddeepdarkcti ok7 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI exploitsdeepdarkcti ok24 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI forumsdeepdarkcti ok264 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI malware as a servicedeepdarkcti ok7 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI malware samplesdeepdarkcti ok3 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI marketsdeepdarkcti ok127 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI phishingdeepdarkcti ok19 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI ransomware gangsdeepdarkcti ok683 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI RATsdeepdarkcti ok1 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI Telegram infostealerdeepdarkcti ok130 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI Telegram threat actorsdeepdarkcti ok1009 records Checked — no match The source completed, but none of its retained records matched this story.
deepdarkCTI Twitter threat actorsdeepdarkcti ok39 records Checked — no match The source completed, but none of its retained records matched this story.
DNSDumpster domain IOC enrichmentresearch ok1 records Checked — no match The source completed, but none of its retained records matched this story.
Exploit-DBexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
FIRST EPSSepss ok Checked — no match The source completed, but none of its retained records matched this story.
Fortinet PSIRTvendor_advisory disabled Disabled Disabled in the source registry; no check was attempted.
GitHub topic: cveresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
GitHub topic: exploitresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
GitHub topic: penetration-testingresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
GitHub topic: pocresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
GitHub topic: vulnerabilityresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
GreyNoiseexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
KrebsOnSecuritynews ok1 records Checked — no match The source completed, but none of its retained records matched this story.
LinkedIn RSS proxy feeds (disabled)research disabled Disabled Disabled in the source registry; no check was attempted.
MalwareBazaardark_web ok10 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #cveresearch ok20 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #cybersecurityresearch ok7 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #exploitresearch ok15 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #infosecresearch ok20 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #malwareresearch ok20 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #ransomwareresearch ok19 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #threatintelresearch ok15 records Checked — no match The source completed, but none of its retained records matched this story.
Mastodon #vulnerabilityresearch ok20 records Checked — no match The source completed, but none of its retained records matched this story.
Metasploit module metadataexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Microsoft MSRCvendor_advisory ok1590 records Checked — no match The source completed, but none of its retained records matched this story.
Microsoft Securitynews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
MISP Galaxyresearch ok1 records Checked — no match The source completed, but none of its retained records matched this story.
MISP threat actor galaxyactor ok0 records Checked — no match The source completed, but none of its retained records matched this story.
NVDcve ok900 records Checked — no match The source completed, but none of its retained records matched this story.
Palo Alto Networks PSIRTvendor_advisory ok25 records Checked — no match The source completed, but none of its retained records matched this story.
ProjectDiscovery nuclei templatesexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Rapid7news ok1 records Checked — no match The source completed, but none of its retained records matched this story.
Reddit r/AskNetsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/cybersecurity (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/malware (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/netsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/ReverseEngineering (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
SANS ISCnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Shadowserver public aggregate honeypot observationsexploit_reference ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Shodanresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Sigma Rulesresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Sophos IOCsresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
The Hacker Newsnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
ThreatFoxthreat_intelligence ok100 records Checked — no match The source completed, but none of its retained records matched this story.
UK NCSCnews ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
Unit42 IOCsresearch ok empty0 records Checked — no match The source completed but returned no records in the collection scope.
URLhausdark_web ok10 records Checked — no match The source completed, but none of its retained records matched this story.
VirusTotal Community IOC enrichmentresearch ok4 records Checked — no match The source completed, but none of its retained records matched this story.
VulnCheck KEVkev ok500 records Checked — no match The source completed, but none of its retained records matched this story.
Vulnerability Lookupcve ok30 records Checked — no match The source completed, but none of its retained records matched this story.
Additional verified pages 6 opened outside the registered collection
Analysis & research5
Hackers arrested over €30M bank fraud exploiting service provider flaw bleepingcomputer.com ↗

Primary English-language report including Commerzbank statement and Operation Klonen details

Investigation of banking hack leads to arrests in Germany, Brazil therecord.media ↗

Independent corroboration from Recorded Future News with additional suspect and seizure detail

Online-Banking-Betrug: BKA hebt Netzwerk hinter Millionen-Abbuchungen aus blogspan.net ↗

German-language reporting confirming BKA attribution and payment-provider booking-process vulnerability language

Fahndungserfolg: Millionenbetrug an Bankkunden: Ermittler heben Netzwerk aus handelsblatt.com ↗

German financial press corroboration naming BKA and Frankfurt Generalstaatsanwaltschaft as lead authorities

Millionenbetrug an Bankkunden: Ermittler heben Netzwerk aus wirtschaftsticker.com ↗

Includes direct quote from Frankfurt Oberstaatsanwalt Benjamin Krause and confirms multi-year investigation timeline