← All Incident Reports
Incident report · TESSOC: Organised Crime / Cyber
Financial infrastructure - supplier defect exploited

Operation Klonen: a supplier's bad update, thirty million euros, four days

A payment processor pushed a faulty software update. The defect it introduced sat in the booking process that German online banking customers relied on. Over four days in November 2023 a criminal network took roughly thirty million euros out through it.

Nearly three years later, Brazilian and German police arrested four people in Brazil and charged three more in Spain and Bulgaria. One of those arrested had stood for elected office in 2024 and is said to have funded the campaign with the proceeds.

↓  Download one-page brief (PDF)
Who
Investigating: Brazil's Federal Police and Germany's Federal Criminal Police Office, with the Frankfurt public prosecutor's office and authorities in Spain and Bulgaria. Arrested: four suspects in Brazil; charged: three more, to be prosecuted in Spain and Bulgaria. Victim institution: not named by either police force; Brazilian media identified it as Commerzbank, which confirmed customers were affected and stated they suffered no financial loss. No state involvement is alleged - this is financially motivated organised crime.
What
A coordinated takedown, run in Brazil as Operacao Klonen, of the network behind the theft of around thirty million euros from German online banking customers. Twenty-one search and seizure warrants were executed across seven Brazilian cities, and courts ordered the seizure of assets, vehicles and property worth about twenty-two million dollars.
Where
The fraud struck German online banking customers. The money was laundered through Brazil and four European countries, with the largest share cashed out in Brazil. Arrests fell in Rio de Janeiro, Guarulhos, Goiania and Carapicuiba.
When
The theft took place over four days in November 2023. The arrests and searches were carried out and announced on 13 and 14 August 2026, after several years of investigation.
Why
Money. Proceeds were layered through multiple channels and, in at least one instance, diverted into financing an election campaign.
How
German authorities state the network exploited a vulnerability in a payment service provider's booking process, introduced by a faulty software update, and used it to make numerous unauthorised withdrawals. Brazilian authorities describe cloned payment cards in the process - the operation is named for it.
What happened
1

A supplier ships a bad update

A payment and transaction-processing provider deploys a software update that introduces a defect into its booking process. Nobody attacked anything to create this opening. It was a release-quality failure at a company most of the affected customers had never heard of.

2

Four days in November 2023

The network makes numerous unauthorised withdrawals from the accounts of German online banking users. Around thirty million euros leaves in that window. Brazilian investigators describe cloned payment cards as part of the mechanism.

3

The money is layered

Proceeds move through pass-through accounts, companies, virtual-asset platforms and payment cards. Reporting states some of those cards were issued without the account holders' consent - a second set of victims, whose identities were used to move the money taken from the first.

4

Most of it goes to Brazil

The largest share is cashed out in Brazil after attempts to conceal the identities of the recipients, with the remainder spread across four European countries.

5

Several years of investigation

Frankfurt prosecutors and the German federal police work the case with Brazilian, Spanish and Bulgarian authorities. The gap between the theft and the arrests is not delay; it is what unpicking this kind of laundering takes.

6

13 to 14 August 2026 - the takedown

Brazil executes twenty-one search and seizure warrants across seven cities and arrests four people. Three more are charged for prosecution in Spain and Bulgaria. Courts order seizure of assets, vehicles and real estate. Investigators also report finding a 3D printer used to manufacture weapons, and that one suspect had stood for elected office in 2024 using part of the stolen money to fund the campaign.

Impact
Financial
Around thirty million euros taken; roughly twenty-two million dollars in assets recovered nearly three years later. The bank stated its customers bore no loss, which means the institution absorbed it.
Supply chain
The substantive finding. A bank's customers lost money because of a defect in a supplier's software release. No security control at the bank was defeated, because the opening was not at the bank.
Identity
Payment cards issued without the account holders' consent were used as a laundering layer. People with no connection to the theft had their identities used to move its proceeds, and will generally learn about it from a letter.
Political
Fraud proceeds allegedly funding an election campaign is the point at which organised crime stops being purely a financial problem. It is the crossover from theft into influence, and it is why an economic crime case carries a subversion dimension.
How a supplier defect becomes a bank's problem
The chain

Who actually moves the money

A retail bank does not process every transaction itself. Payment and transaction-processing providers sit between the bank and the payment networks, handling the booking of debits and credits. The customer sees the bank; the transaction passes through companies the customer cannot name.

The failure

A release, not an attack

The vulnerability was introduced by a faulty software update. Somebody shipped a change that broke a control, and a criminal network found it before the supplier did. This is a quality assurance failure that became a security incident.

The layering

Why it took years

Pass-through accounts, shell companies, virtual-asset platforms and payment cards each add a step that has to be traced, usually across a border and often through a jurisdiction with different disclosure rules. A multi-year gap between the theft and the arrests is normal for this class of case, not exceptional.

Nov 2025

A wider question about the sector

German prosecutors separately announced arrests over fraud and laundering networks operating through payment firms, telling reporters they suspected former employees of major German payment providers had known of fraudulent activity and allowed it. That is a different case, and it indicates the scrutiny this part of the chain is now under.

The most uncomfortable feature of this case is that the bank did nothing wrong in any way that a security assessment would find. Its perimeter held, its authentication held, its customers were made whole. The failure happened inside a supplier's release process, and the bank's only real control over that was contractual.

Assessment
1

Nobody attacked the bank, and that is the point

The opening was created by a supplier's own faulty update, not by an intrusion. The network's skill was in finding it and industrialising the exploitation within days. An organisation's exposure therefore includes the release quality of every firm in its transaction chain, which is not a security property most contracts or assurance reviews measure.

2

Four days is the number to plan against

Roughly thirty million euros moved in a window of about four days. Whatever detection existed, it did not close the gap faster than that. The relevant question for any financial institution is not whether a supplier defect could occur but how quickly an anomalous pattern of debits would be spotted and stopped, because the criminals were evidently able to operate for the better part of a working week.

3

The bank absorbing the loss protects customers and weakens the incentive to fix the supplier

Commerzbank stated its customers suffered no financial loss. That is the right outcome for the individuals concerned. It also means the cost of a supplier's defect landed on the institution rather than on the party that caused it. Where losses are absorbed downstream, the pressure to improve upstream quality has to come from contracts and regulators rather than from the market.

4

The laundering, not the theft, is why this took three years

The money moved through pass-through accounts, companies, virtual-asset platforms and payment cards issued in other people's names, across five countries. Recovering twenty-two million of thirty is a good result by the standards of this work, and it required coordinated action by four national authorities. Organisations should calibrate their expectations of recovery accordingly.

5

The political financing element is the part with consequences beyond money

A suspect is alleged to have used stolen funds to contest an election. That converts a fraud into a governance problem, and it is the mechanism by which organised crime buys standing rather than goods. It is a realistic possibility that this is not isolated; the allegation is untested and the individual has not been convicted.

The comparison worth making

Set this beside North Carolina Ports, where an operator lost its systems and kept freight moving on paper because a degraded mode existed. Here there was no degraded mode to fall back on, because the bank never knew it was operating in one. A supplier defect that opens a window rather than closing a service is the harder problem: nothing stops working, so nothing prompts a response.

What should carry
  • Map who processes your transactions, not just who holds your account. Most organisations cannot name the payment providers in their own chain. That list is the first artefact, and it belongs to finance as much as to security.
  • Ask suppliers about release quality, not only about security controls. This window was opened by an ordinary bad update. Change management, testing and rollback capability are security questions when a supplier sits inside a payment path.
  • Monitor for anomalous patterns of debits, not only for intrusions. Nothing was breached. What was visible, in principle, was an unusual volume of unauthorised withdrawals over four days. Detection built solely around intrusion signals would not have seen it.
  • Agree in advance who bears a supplier-caused loss. The institution absorbed this one. Contractual liability for defects introduced by a provider's own release is worth settling before an incident rather than after.
  • Expect identity abuse as a laundering layer. Payment cards were reportedly issued in the names of people with no involvement. Organisations should anticipate that customers or staff may be drawn into a case they knew nothing about.
  • Set realistic expectations on recovery and timescale. Nearly three years to arrests and roughly two-thirds of the money recovered represents a good outcome in this class of case. Business continuity planning should assume the money does not come back quickly.
Sources

Compiled from open-source reporting for professional security discussion. Seven people have been arrested or charged and none has been convicted; all are entitled to the presumption of innocence, including in respect of the allegation that stolen funds were used to finance an election campaign. Neither the Brazilian Federal Police nor the German federal police named the affected institution; the identification of Commerzbank derives from Brazilian media reporting, and the bank has confirmed its customers were affected and stated they suffered no financial loss. The payment service provider whose faulty update introduced the vulnerability has not been named. Accounts differ in emphasis between a payment-system defect with unauthorised debits and the use of cloned payment cards; both appear in official statements and this report records both. Details may be revised as prosecutions proceed. This is a protective-security lessons-learned assessment, not an operational account.