Full research report
Hackers arrested over €30M bank fraud exploiting service provider flaw
Executive assessment
Operation Klonen is a significant multi-jurisdictional law enforcement success against a financially sophisticated criminal network that identified and rapidly weaponised a software defect in a third-party payment service provider to drain approximately €30 million from German bank accounts over just four days in November 2023. The three-year gap between the fraud and the August 2026 arrests reflects the complexity of tracing layered money flows across virtual-asset platforms, shell companies, and multiple jurisdictions spanning two continents. The involvement of a Rio de Janeiro city council candidate who allegedly used stolen funds for a 2024 election campaign adds a politically sensitive dimension to the case. Critically, neither the payment service provider's identity nor the technical specifics of the authorisation bypass have been publicly disclosed, limiting independent verification of whether the flaw has been fully remediated. For defenders, the episode underscores the supply-chain risk posed by third-party payment processors: a single inadequately reviewed software update can create an exploitable authorisation gap that criminal actors detect and exploit faster than bank monitoring systems can respond.
What happened
In November 2023, an international criminal network exploited a software flaw introduced by a faulty update to an unnamed payment service provider's booking system, initiating numerous unauthorised direct debits from German online banking accounts over approximately four days. An estimated €30 million was drained and routed primarily to Brazil, with a smaller share distributed across four European countries through pass-through accounts, shell companies, virtual-asset platforms, and payment cards issued without beneficiaries' consent. Brazil's Federal Police launched Operation Klonen on 13–14 August 2026 with BKA and Frankfurt prosecutor support, arresting four suspects in Brazil and charging three further suspects in Spain and Bulgaria. Commerzbank confirmed its customers were affected but stated that no customers incurred financial losses.
Affected scope
German online banking customers of Commerzbank; an unnamed payment and transaction-processing service provider. Money laundering infrastructure spanned Brazil, Spain, Bulgaria, and at least two other European countries. Exact customer count not publicly disclosed.
Technical assessment
Attackers identified and exploited a weakness in the booking and authorisation process of a third-party payment service provider, introduced through a faulty software update. The flaw permitted unauthorised direct debits to be initiated against German bank accounts without legitimate customer authorisation. Funds were then obfuscated through layered financial structures including virtual-asset platforms before being cashed out. The precise technical nature of the authorisation bypass—and whether it required any prior account access or was exploitable remotely—has not been disclosed by investigators.
Recommended defensive actions
- Audit third-party payment service provider update procedures: require staged rollout, regression testing, and sign-off on authorisation-control changes before production deployment
- Monitor for anomalous direct debit volume spikes originating from a single payment processor over short time windows and alert on deviations from established baselines
- Implement real-time transaction velocity controls and automated customer-notification triggers for high-frequency or high-value account debits
- Review contractual obligations with payment service providers to mandate rapid vulnerability notification, incident response SLAs, and liability terms for software-introduced flaws
- Verify that customer compensation and chargeback procedures are documented, tested, and operable in the event of a third-party payment provider compromise
Uncertainties and evidence gaps
- The identity of the payment service provider has not been disclosed by German or Brazilian authorities
- The precise technical mechanism of the authorisation bypass has not been publicly detailed
- The number of individual German bank customers affected has not been released
- Whether the payment provider vulnerability has been fully remediated is unconfirmed in public reporting
- The extent of any additional undisclosed financial institutions affected beyond Commerzbank is unknown
Vulnerability flow
Defender-oriented path reconstructed only from sourced report findings. Unknown stages are omitted.
No CVE assigned; a software flaw introduced by a faulty update to an unnamed payment service provider's booking system was exploited over four days in November 2023 to initiate mass unauthorised direct debits from German bank accounts. Arrests followed in August 2026; no evidence of ongoing exploitation.
The investigation began with a BleepingComputer report on Operation Klonen, a joint Brazil–Germany law enforcement action against a network that exploited a payment service provider flaw to steal €30 million from Commerzbank customers in November 2023. Searches and article fetches across English and German-language sources confirmed the core facts, identified the BKA and Frankfurt Generalstaatsanwaltschaft as German lead authorities, and corroborated the vulnerability description as a faulty-software-update flaw in a payment booking process. No CVE, named service provider, or public proof of concept was found across any source, and official BKA press material was not directly retrieved, leaving sourcing reliant on multiple credible secondary reports.
- What are the confirmed facts in the primary report?Fetched BleepingComputer article and extracted all factual claimsbleepingcomputer.com ↗
Four arrested in Brazil; three charged in Europe; Operation Klonen; fraud occurred November 2023 over four days; €30 million; Commerzbank identified by Brazilian media; service provider flaw introduced by faulty software update; no CVE stated
why Establishes the event baseline and provides the only available Commerzbank on-record statement confirming customer impact but no customer losses
- Is there independent corroboration beyond BleepingComputer?Searched for Operation Klonen, BKA, Commerzbank, Brazil arrests 2026
The Record (Recorded Future News) and multiple German outlets including Handelsblatt, blogspan.net, and Badische Zeitung also covered the story, all confirming arrests, the operation name, and the vulnerability description
why Multiple independent outlets repeating the same core facts across English and German press elevates confidence; The Record adds detail on a 3D printer seizure and the city council candidate suspect
- What additional detail does The Record provide?Fetched The Record articletherecord.media ↗
Confirmed seven total arrests; cloned payment cards used in the fraud; one suspect was a 2024 Rio de Janeiro city council candidate who used stolen funds for their campaign; a 3D printer for manufacturing weapons was also seized
why Provides independent corroboration from a specialist security news outlet and adds operational detail about the money laundering and physical-asset seizures
- Is there an official BKA press release to cite as a primary authority source?Fetched BKA 2026 press release index and searched for BKA Frankfurt prosecutor statementbka.de ↗
No Operation Klonen press release visible on the retrieved BKA index page; German media articles attribute statements to BKA and to Oberstaatsanwalt Benjamin Krause of the Frankfurt prosecutor's office
why Official attribution is confirmed through credible German media quotes; the absence of a directly retrieved BKA URL is noted as a sourcing gap that slightly reduces confidence
- What technical language do German authorities use to describe the vulnerability?Fetched blogspan.net German-language articleblogspan.net ↗
Vulnerability described as 'Schwachstelle im Buchungsprozess bei einem Zahlungsdienstleister' (flaw in the booking process of a payment service provider) arising from a faulty software update; provider identity not disclosed; no CVE assigned
why Confirms the technical framing in authorities' own language and establishes that no product name or CVE identifier has entered the public record
- Does Handelsblatt provide additional authority-sourced or technical detail?Fetched Handelsblatt articlehandelsblatt.com ↗
Confirmed BKA and Generalstaatsanwaltschaft Frankfurt as German leads; charges described as Computerbetrug (computer fraud); damage described as 'Millionenbereich' without exact figure; no named provider or CVE
why Adds authoritative German financial press corroboration and identifies the Frankfurt prosecutor's office, enabling a more precise authority attribution
- Is there a direct prosecutor quote and any further technical specifics?Fetched wirtschaftsticker.com articlewirtschaftsticker.com ↗
Oberstaatsanwalt Benjamin Krause quoted saying cybercrime perpetrators cannot feel safe; no additional technical specifics beyond those already confirmed; multi-year investigation confirmed
why Provides named prosecutorial attribution and confirms the investigation spanned approximately three years from the November 2023 incident to the August 2026 arrests
Research coverage
All 68 registered source leaves were evaluated for this run: 60 completed, 0 were unavailable, 1 failed and 7 were disabled. For this story, 1 registered sources supplied useful evidence (1 primary, 0 corroborating, 0 contextual and 0 PoC/exploit references). 59 completed sources contained no matched information for this story.
Complete source-by-source audit 68 sources
| Source | Run result | Value | Why it was useful — or not |
|---|---|---|---|
| BleepingComputernews | ok8 records | Primary evidence2 matched items | Published the source report used to frame and date the event. Supplied independent analysis opened and verified during focused research. |
| AlienVault OTXdark_web | failed0 records | Failed | The current collection attempt failed; this source cannot support the report. |
| CIRCL CVEcve | ok30 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| CISA Alertsnews | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| CISA KEVkev | ok1665 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Cisco PSIRTvendor_advisory | ok5324 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Cisco Talosnews | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| deepdarkCTI CVE most exploiteddeepdarkcti | ok94 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Discorddeepdarkcti | ok7 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI exploitsdeepdarkcti | ok24 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI forumsdeepdarkcti | ok264 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI malware as a servicedeepdarkcti | ok7 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI malware samplesdeepdarkcti | ok3 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI marketsdeepdarkcti | ok127 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI phishingdeepdarkcti | ok19 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI ransomware gangsdeepdarkcti | ok683 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI RATsdeepdarkcti | ok1 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Telegram infostealerdeepdarkcti | ok130 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Telegram threat actorsdeepdarkcti | ok1009 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| deepdarkCTI Twitter threat actorsdeepdarkcti | ok39 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| DNSDumpster domain IOC enrichmentresearch | ok1 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Exploit-DBexploit_reference | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| FIRST EPSSepss | ok | Checked — no match | The source completed, but none of its retained records matched this story. |
| Fortinet PSIRTvendor_advisory | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| GitHub topic: cveresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| GitHub topic: exploitresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| GitHub topic: penetration-testingresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| GitHub topic: pocresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| GitHub topic: vulnerabilityresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| GreyNoiseexploit_reference | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| KrebsOnSecuritynews | ok1 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| LinkedIn RSS proxy feeds (disabled)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| MalwareBazaardark_web | ok10 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Mastodon #cveresearch | ok20 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Mastodon #cybersecurityresearch | ok7 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Mastodon #exploitresearch | ok15 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Mastodon #infosecresearch | ok20 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Mastodon #malwareresearch | ok20 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Mastodon #ransomwareresearch | ok19 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Mastodon #threatintelresearch | ok15 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Mastodon #vulnerabilityresearch | ok20 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Metasploit module metadataexploit_reference | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| Microsoft MSRCvendor_advisory | ok1590 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Microsoft Securitynews | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| MISP Galaxyresearch | ok1 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| MISP threat actor galaxyactor | ok0 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| NVDcve | ok900 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Palo Alto Networks PSIRTvendor_advisory | ok25 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| ProjectDiscovery nuclei templatesexploit_reference | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| Rapid7news | ok1 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Reddit r/AskNetsec (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/cybersecurity (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/malware (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/netsec (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| Reddit r/ReverseEngineering (pending API approval)research | disabled | Disabled | Disabled in the source registry; no check was attempted. |
| SANS ISCnews | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| Shadowserver public aggregate honeypot observationsexploit_reference | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| Shodanresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| Sigma Rulesresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| Sophos IOCsresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| The Hacker Newsnews | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| ThreatFoxthreat_intelligence | ok100 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| UK NCSCnews | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| Unit42 IOCsresearch | ok empty0 records | Checked — no match | The source completed but returned no records in the collection scope. |
| URLhausdark_web | ok10 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| VirusTotal Community IOC enrichmentresearch | ok4 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| VulnCheck KEVkev | ok500 records | Checked — no match | The source completed, but none of its retained records matched this story. |
| Vulnerability Lookupcve | ok30 records | Checked — no match | The source completed, but none of its retained records matched this story. |
Additional verified pages 6 opened outside the registered collection
Analysis & research5
Primary English-language report including Commerzbank statement and Operation Klonen details
Independent corroboration from Recorded Future News with additional suspect and seizure detail
German-language reporting confirming BKA attribution and payment-provider booking-process vulnerability language
German financial press corroboration naming BKA and Frankfurt Generalstaatsanwaltschaft as lead authorities
Includes direct quote from Frankfurt Oberstaatsanwalt Benjamin Krause and confirms multi-year investigation timeline