Seven arrested over €30M Commerzbank fraud that abused a service provider flaw

Investigators say the crew drained customer accounts by exploiting a weakness at a third-party firm that connects to the German bank.

ThreatVectr Newsdesk· 3 min read
Full-frame photoreal news-editorial image of a dimly lit government office at night, a single desktop monitor glowing with an abstract green download progress b
Share

Key points

  • Brazilian police arrested four suspects and European prosecutors charged three more over a €30 million fraud scheme targeting Commerzbank customers.
  • The group did not hack the bank directly, they abused a flaw at a third-party service provider that had access to customer accounts.
  • Losses across German victims are estimated at around €30 million, according to investigators cited by BleepingComputer.
  • No customer action is required now, but Commerzbank users should keep watching statements and report anything odd to the bank.

Brazilian federal police arrested four people last week over a long-running fraud that drained money from Commerzbank customers in Germany. Three more suspects have been charged in Europe. Prosecutors put total losses at roughly €30 million.

The hackers did not break into Commerzbank itself. They found a weakness at a service provider, a company the bank relies on to handle certain account operations, and used that access to move money out of customer accounts.

That detail matters. Banks spend heavily on their own defences, but attackers increasingly go one step sideways, hitting a smaller supplier that already has a trusted connection into the bank's systems. It is the same pattern seen across supply-chain intrusions in the last few years.

How did the criminals actually take the money?

They abused a vulnerability, meaning a bug in software, at a firm that provides services to Commerzbank. Once inside, they were able to authorise withdrawals from real customer accounts as if the requests were legitimate.

Investigators have not publicly named the service provider or described the exact flaw. What is clear is that the access let the group pull funds repeatedly before the pattern was spotted. The stolen money was then moved through accounts and money mules, people who let their bank accounts be used to shuffle criminal proceeds, often for a small cut.

Who are the people arrested?

Four suspects were detained in Brazil in raids coordinated with European authorities. Three others face charges in Europe. Officials have described them as a coordinated group rather than a known nation-state crew.

On attribution, a note of caution. No security vendor has, at time of writing, tied this activity to a tracked cluster such as the financially motivated groups Mandiant labels FIN7 or FIN11, or the crews Microsoft tracks under its weather-themed names. Treat this as organised financial crime with medium confidence until an incident report says otherwise. Capability here (abusing a trusted supplier) is common across both cybercrime and espionage sets, so overlapping tradecraft alone would not be enough to attribute.

What should Commerzbank customers do?

Nothing urgent. The arrests suggest the immediate operation has been disrupted, and Commerzbank has not asked customers to reset credentials or take special steps.

Still, a few sensible habits:

  • Check recent statements for any transaction you do not recognise, however small.
  • Report anything odd to Commerzbank directly using the number on the back of your card, not a number from an email or text.
Detail What we know
Estimated losses around €30 million
Arrested in Brazil 4 suspects
Charged in Europe 3 suspects
Bank affected Commerzbank (Germany)
Entry point vulnerability at a third-party service provider

Why this case matters beyond Germany

The attack fits a wider trend. Financially motivated crews are hunting for the weakest trusted connection into a bank, an insurer or a retailer, rather than attacking the front door. That trusted connection is often a smaller vendor with less mature security.

Regulators in the EU have already pushed banks to tighten oversight of third parties under the Digital Operational Resilience Act, which took effect in January 2025. Cases like this one are exactly what that rule was written for.

Arrests are a good outcome. They rarely close the door for long.

© 2026 Threat Vectr