Seven arrested over €30M Commerzbank fraud that abused a service provider flaw
Investigators say the crew drained customer accounts by exploiting a weakness at a third-party firm that connects to the German bank.

Key points
- Brazilian police arrested four suspects and European prosecutors charged three more over a €30 million fraud scheme targeting Commerzbank customers.
- The group didn't hack the bank directly; they abused a flaw at a third-party service provider that had access to customer accounts.
- Losses across German victims are estimated at around €30 million, according to investigators cited by BleepingComputer.
- No customer action is required now, but Commerzbank users should watch statements and report anything odd to the bank.
Brazilian federal police arrested four people last week over a long-running fraud that drained money from Commerzbank customers in Germany. Three more suspects have been charged in Europe. Prosecutors put total losses at roughly €30 million.
The attackers didn't break into Commerzbank itself. They found a weakness at a service provider, a company the bank relies on to handle certain account operations, and used that access to move money out of customer accounts.
That detail matters. Banks spend heavily on their own defences, but attackers increasingly go one step sideways, hitting a smaller supplier that already has a trusted connection into the bank's systems. It's the same pattern we noted in July when covering Brazilian operators behind the Lampion banking trojan, a crew that has run the same playbook since 2019 without needing to change it.
How did the criminals actually take the money?
They abused a vulnerability, meaning a software bug, at a firm providing services to Commerzbank. Once inside, they could authorise withdrawals from real customer accounts as if the requests were legitimate.
Investigators haven't publicly named the service provider or described the exact flaw. The access let the group pull funds repeatedly before the pattern was spotted. Stolen money moved through money mules, people who let their accounts be used to shuffle criminal proceeds, often for a small cut.
Who are the people arrested?
Four suspects were detained in Brazil in raids coordinated with European authorities. Three others face charges in Europe. Officials described them as a coordinated group rather than a known nation-state crew.
A note of caution on attribution. No security vendor has, at time of writing, tied this activity to a tracked cluster such as the financially motivated groups Mandiant labels FIN7 or FIN11, or the crews Microsoft tracks under its weather-themed names. Treat this as organised financial crime with medium confidence until an incident report says otherwise. Overlapping tradecraft alone, specifically abusing a trusted supplier, isn't enough to attribute, since that capability is common across cybercrime and espionage sets alike.
What should Commerzbank customers do?
Nothing urgent. The arrests suggest the immediate operation has been disrupted, and Commerzbank hasn't asked customers to reset credentials or take special steps.
Check recent statements for any transaction you don't recognise, however small. Report anything odd to Commerzbank directly using the number on the back of your card, not a number from an email or text.
| Detail | What we know |
|---|---|
| Estimated losses | around €30 million |
| Arrested in Brazil | 4 suspects |
| Charged in Europe | 3 suspects |
| Bank affected | Commerzbank (Germany) |
| Entry point | vulnerability at a third-party service provider |
Why this case matters beyond Germany
Financially motivated crews are hunting for the weakest trusted connection into a bank or a retailer rather than attacking the front door. That connection is often a smaller vendor with less mature security.
Regulators in the EU have already pushed banks to tighten oversight of third parties under the Digital Operational Resilience Act, which took effect in January 2025. Cases like this are exactly what that rule was written for.
Arrests are a good outcome. They rarely close the door for long. The more useful signal is whether the unnamed service provider has disclosed what failed and patched it, because the next crew will look for the same gap.



