NEW: Unlock the Future of Finance with CRYPTO ENDEVR - Explore, Invest, and Prosper in Crypto!
Crypto Endevr
  • Top Stories
    • Latest News
    • Trending
    • Editor’s Picks
  • Media
    • YouTube Videos
      • Interviews
      • Tutorials
      • Market Analysis
    • Podcasts
      • Latest Episodes
      • Featured Podcasts
      • Guest Speakers
  • Insights
    • Tokens Talk
      • Community Discussions
      • Guest Posts
      • Opinion Pieces
    • Artificial Intelligence
      • AI in Blockchain
      • AI Security
      • AI Trading Bots
  • Learn
    • Projects
      • Ethereum
      • Solana
      • SUI
      • Memecoins
    • Educational
      • Beginner Guides
      • Advanced Strategies
      • Glossary Terms
No Result
View All Result
Crypto Endevr
  • Top Stories
    • Latest News
    • Trending
    • Editor’s Picks
  • Media
    • YouTube Videos
      • Interviews
      • Tutorials
      • Market Analysis
    • Podcasts
      • Latest Episodes
      • Featured Podcasts
      • Guest Speakers
  • Insights
    • Tokens Talk
      • Community Discussions
      • Guest Posts
      • Opinion Pieces
    • Artificial Intelligence
      • AI in Blockchain
      • AI Security
      • AI Trading Bots
  • Learn
    • Projects
      • Ethereum
      • Solana
      • SUI
      • Memecoins
    • Educational
      • Beginner Guides
      • Advanced Strategies
      • Glossary Terms
No Result
View All Result
Crypto Endevr
No Result
View All Result

How a Hacker Spent Only $2.7K to Steal $140 Million From Brazilian Banks

How a Hacker Spent Only .7K to Steal 0 Million From Brazilian Banks
Share on FacebookShare on Twitter

rewrite this content

In brief

  • Hackers stole $140 million from a network of Brazilian banks connected to the country’s central banking system.
  • The hackers orchestrated the scheme by paying just $2,760 to a technology company employee for his credentials.
  • Hackers then laundered portions of the stolen money through crypto, using Bitcoin, Ethereum, and Tether.

Here’s some ammo for decentralization advocates: Hackers stole approximately R$800 million ($140 million) from Brazilian banks after paying a technology company employee just R$15,000 ($2,760) for his corporate credentials, according to law enforcement officials investigating what they describe as the largest digital heist in the country’s history.

The attack targeted C&M Software, a São Paulo-based company that connects smaller banks and fintechs to Brazil’s Central Bank infrastructure, including the Pix instant payment system. Six financial institutions experienced unauthorized access to their reserve accounts on June 30, with criminals draining funds in under three hours.

“This is the biggest fraud suffered by financial institutions through the internet,” Paulo Barbosa, the São Paulo police detective leading the investigation, said at a press conference Thursday.

The scheme began in March when criminals approached João Nazareno Roque, an IT operator at C&M, outside a bar near his home. Roque confessed to selling his system credentials for R$5,000 initially, then receiving another R$10,000 to help create software that enabled the breach. Police arrested the 30-year-old at his City Jaraguá residence on July 3.

Between 4 a.m. and 7 a.m. local time on June 30, attackers issued fraudulent Pix transfer orders while impersonating the affected banks. BMP, a banking-as-a-service provider, was one of the most affected, confirming losses of more than R$400 million ($73.8 million) from its central bank reserve account. The company filed the initial police report that exposed the wider attack.

Criminals immediately began converting the stolen reais to cryptocurrency through Latin American over-the-counter desks and exchanges. Blockchain analysis from crypto sleuth ZachXBT indicates at least $30 million to $40 million moved into Bitcoin, Ethereum, and Tether (USDT) before authorities could freeze accounts. One wallet containing R$270 million ($49.8 million) has since been blocked.

The pseudonymous investigator said earlier today via Telegram that he has been helping investigators identify and freeze the cryptocurrency addresses associated with what he described as “one of the most insane cases from this year.”

What is Pix and C&M and why were they targeted?

Pix, Brazil’s instant payment platform launched in November 2020, processes billions of transactions monthly and has become the dominant payment method across the country. The system allows instant transfers between banks 24 hours a day, including weekends and holidays, with transactions completing almost instantly.

It has become widely adopted because users can link their accounts to familiar identifiers such as their phone number, email, or ID number. Pix also enables QR payments and offers different features designed to compete with credit card providers, including options that allow users to pay for purchases in installments.

The system works by interconnecting banks and financial institutions directly through the central bank’s digital infrastructure, allowing funds to move instantly between accounts. When a user initiates a Pix transfer, the payment request is routed directly through the central bank, which verifies the details and authorizes the transaction in real time. This eliminates the delays associated with traditional bank transfers, which often took minutes or even hours to clear, enabling payments and transfers to be completed within seconds, any time of day.

There have been other adjacent technologies implemented in Brazil, like banks being able to monitor other bank’s transactions for credit rating, for example.

Unlike previous attacks targeting individual Pix users through malware like PixPirate, this breach exploited the infrastructure connecting financial institutions to the central bank. The attackers accessed reserve accounts that banks maintain for settling transactions, rather than customer deposits.

“The analyses conducted so far have not identified any technical failures or vulnerabilities in CMSW’s systems. The incident occurred due to the unauthorized use of legitimate credentials. In addition to the employee’s credentials, there are indications that other authentication methods may have been exploited. The company’s quick response was only possible thanks to its robust security architecture,” C&M said in an official Q&A .

Founded in 1992 by Orli Machado, C&M provides messaging services that allow approximately 23 smaller financial institutions to access Brazil’s payment systems without building their own infrastructure. The company’s role as an intermediary made it an attractive target for criminals seeking access to multiple banks simultaneously.

Brazil’s central bank ordered C&M to disconnect from all financial infrastructure on July 2, temporarily disrupting Pix services for several institutions. Banco Paulista reported a “temporary interruption” in instant payments due to an “external failure,” while reassuring customers that no personal data or funds were compromised.

Banco Paulista reported a “temporary interruption” in instant payments. Image: Screenshot

Federal Police Director Andrei Passos Rodrigues said his agency launched an immediate investigation in coordination with São Paulo state authorities. Investigators are examining whether the attack connects to Brazil’s sophisticated cybercriminal networks, which frequently coordinate through Telegram and WhatsApp channels.

Roque, the compromised IT operator, told investigators he communicated with at least four different voices during the June 30 attack, all sounding like young men. He claimed to have changed cell phones every 15 days to avoid detection and never met the other conspirators in person beyond the initial bar encounter.

The breach occurred despite Brazil’s banking sector investing heavily in cybersecurity following earlier incidents. C&M stated it had implemented “all technical and legal measures” after discovering the intrusion and continues cooperating with authorities.

BMP assured clients that sufficient collateral covered the stolen amounts, preventing any customer losses. The central bank confirmed it recovered portions of the diverted funds from regulated entities under its supervision, though recovery efforts remain limited for transfers to non-regulated cryptocurrency exchanges.

Police continue analyzing devices seized from Roque’s residence while working to identify other participants. Authorities have created a joint task force with the Federal Police and Public Ministry to trace the cryptocurrency transactions and potentially freeze additional assets.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

in well organized HTML format with all tags properly closed. Create appropriate headings and subheadings to organize the content. Ensure the rewritten content is approximately 1500 words. Do not include the title and images. please do not add any introductory text in start and any Note in the end explaining about what you have done or how you done it .i am directly publishing the output as article so please only give me rewritten content. At the end of the content, include a “Conclusion” section and a well-formatted “FAQs” section.

cryptoendevr

cryptoendevr

Related Stories

Sweden Orders Police to Increase Seizures of Criminal Crypto Profits

Sweden Orders Police to Increase Seizures of Criminal Crypto Profits

July 5, 2025
0

rewrite this content In brief Sweden’s Minister of Justice has called on the country’s authorities to increase efforts to seize...

Gold Explorer Joins Bitcoin Treasury Bandwagon

Gold Explorer Joins Bitcoin Treasury Bandwagon

July 5, 2025
0

rewrite this content In brief Early-stage mineral exploration company Hamak Gold is shifting part of its treasury into Bitcoin. Its...

Another Solo Bitcoin Miner Beats the Odds, Winning 0K Jackpot

Another Solo Bitcoin Miner Beats the Odds, Winning $350K Jackpot

July 5, 2025
0

rewrite this content In brief Block 903,883 was processed by a solo miner that pocketed a sweet reward of $349,028....

Russian Arms Maker Wants Its Own Stablecoin Too—On Tron

Russian Arms Maker Wants Its Own Stablecoin Too—On Tron

July 4, 2025
0

rewrite this content In brief Russian weapons manufacturer Rostec will launch its own stablecoin. The RUBx token will run on...

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Bitcoin Bullish Again? Potential All-Time High in Sight: Analysis

Bitcoin Bullish Again? Potential All-Time High in Sight: Analysis

July 3, 2025
Hunters International shuts ransomware operations, reportedly becomes an extortion-only gang

Hunters International shuts ransomware operations, reportedly becomes an extortion-only gang

July 3, 2025
Bitcoin Rejected! | Stock Markets Losing MAJOR Support! | Options Closeout!

Bitcoin Rejected! | Stock Markets Losing MAJOR Support! | Options Closeout!

July 3, 2025

Arthur Hayes and Hanson Birringer on Hyperliquid’s Success (And What Could Stop It)

July 3, 2025
Circle stock outpaces Bitcoin with 472% growth since June IPO

Circle stock outpaces Bitcoin with 472% growth since June IPO

July 3, 2025

Our Newsletter

Join TOKENS for a quick weekly digest of the best in crypto news, projects, posts, and videos for crypto knowledge and wisdom.

CRYPTO ENDEVR

About Us

Crypto Endevr aims to simplify the vast world of cryptocurrencies and blockchain technology for our readers by curating the most relevant and insightful articles from around the web. Whether you’re a seasoned investor or new to the crypto scene, our mission is to deliver a streamlined feed of news and analysis that keeps you informed and ahead of the curve.

Links

Home
Privacy Policy
Terms and Services

Resources

Glossary

Other

About Us
Contact Us

Our Newsletter

Join TOKENS for a quick weekly digest of the best in crypto news, projects, posts, and videos for crypto knowledge and wisdom.

© Copyright 2024. All Right Reserved By Crypto Endevr.

No Result
View All Result
  • Top Stories
    • Latest News
    • Trending
    • Editor’s Picks
  • Media
    • YouTube Videos
      • Interviews
      • Tutorials
      • Market Analysis
    • Podcasts
      • Latest Episodes
      • Featured Podcasts
      • Guest Speakers
  • Insights
    • Tokens Talk
      • Community Discussions
      • Guest Posts
      • Opinion Pieces
    • Artificial Intelligence
      • AI in Blockchain
      • AI Security
      • AI Trading Bots
  • Learn
    • Projects
      • Ethereum
      • Solana
      • SUI
      • Memecoins
    • Educational
      • Beginner Guides
      • Advanced Strategies
      • Glossary Terms

Copyright © 2024. All Right Reserved By Crypto Endevr