Skip to content
feed: live
>_0dayNews
threat intel
● Breaking

Seven Arrested in €30M Commerzbank Account Fraud

German BKA and Brazil's federal police arrested seven over a service provider flaw that enabled withdrawals from Commerzbank customer accounts. €30M stolen.

Seven Arrested in €30M Commerzbank Account Fraud
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
airgapairgap·Published ·2 min read

Seven arrests. Two countries. €30 million stripped from Commerzbank customer accounts.

Germany’s Federal Criminal Police Office (BKA) charged three suspects in Europe. Brazil’s Polícia Federal arrested four more. The operations were coordinated, announced Thursday, and aimed at a group that had exploited a vulnerability at a third-party service provider to pull funds directly from customer accounts — not a phishing run, not a credential-spray campaign. They had back-end access.

BleepingComputer and The Record both confirmed the enforcement action, citing BKA and Polícia Federal statements.

Confirmed

  • €30M extracted from Commerzbank customer accounts (BKA-confirmed)
  • 4 arrested in Brazil by Polícia Federal, Thursday
  • 3 charged in Europe by BKA-led operation, Thursday
  • Attack vector: vulnerability exploited at an unnamed service provider with back-end connectivity to Commerzbank
  • Mechanism: access enabled direct fund withdrawals, not credential collection alone

The Service Provider Flaw

The specific vulnerability and the service provider’s identity have not been disclosed in available reporting. What is confirmed: the attackers reached deep enough into banking infrastructure to authorize outbound transfers. That matters — a credential or intercepted session token typically requires additional steps to move money; back-end access compresses that chain considerably.

Charging documents will clarify the technical entry point. Until then: unconfirmed. Do not fill in the gap.

What’s Not Confirmed

  • The service provider’s name or the specific flaw exploited
  • Whether the underlying vulnerability has since been patched
  • Number of Commerzbank customers affected
  • Whether the seven arrested represent the full operation or whether additional suspects remain outstanding
  • How long fraudulent withdrawals went undetected before the investigation triggered arrests

What to Watch

BKA typically releases detailed indictment summaries after initial arrest announcements. Polícia Federal briefings on financial cybercrime arrests follow within weeks. Both are the primary sources to monitor for the service provider’s identity and technical specifics.

Third-party access to financial back-ends is a specific and underreported attack surface. Beacon CRM’s breach via an exposed AWS key — disclosed today, affecting over 1,000 charities — runs the same structural pattern at a different scale: service provider compromised, downstream victims pay. For prior cross-border enforcement context, INTERPOL’s Operation First Light ran 5,811 arrests across 61 countries in mid-2026.


Also today: Shell under investigation after Clop claims 89GB theft. ShinyHunters hits RingCentral — 1.6 million accounts.

Found this useful? Share it.