Brazilian Federal Police and Germany's BKA have closed a case that began in November 2023, when roughly €30 million (about $34.6 million) was taken from German online banking accounts over four days.
Four suspects arrested in Brazil — Rio de Janeiro, Guarulhos, Goiânia, Carapicuíba. Three charged in Europe, with prosecutions in Spain and Bulgaria. Assets worth R$106 million (about $22.4 million) seized.
The operation is called Klonen.
The opening was a software update
The vulnerability was not in the bank. It was introduced by a faulty software update at a financial institution's payment and transaction-processing system.
That is a supply-chain failure in the least glamorous possible form: a routine release at a processor, and a window it opened.
Attackers used it to initiate unauthorised withdrawals from customer accounts, then moved the money to Brazil through pass-through accounts, shell companies, payment institutions, virtual-asset platforms and fraudulent payment cards.
Commerzbank is the affected institution. Its spokesperson:
unauthorized direct debits were made from customer accounts. There was no financial loss to customers.
Worth being precise about that sentence. Customers were made whole. The bank absorbed the loss. Neither of those facts means the money was recovered — that is what the seizures are for, three years later.
Four days
The compression is the part that should worry anyone running payments.
€30 million over four days is roughly €7.5 million a day through a fault introduced by an update. Whatever monitoring existed did not stop it inside that window, and the fault was live long enough to be found, weaponised and drained.
Why the arrests took three years
Because the money went through pass-through accounts, companies, payment institutions, virtual-asset platforms and fraudulent cards — in that order, across at least four countries.
Each hop is a separate legal request. Brazil, Germany, Spain and Bulgaria each have their own process, and the chain has to be reconstructed in order before anyone can be charged.
One arrested suspect ran for elected office in 2024 using the proceeds, which is the sort of detail that makes a financial-crime case findable: laundering that ends in visible spending leaves a trail that laundering into more crypto does not.
Why we are writing up an arrest
Because the enforcement side is under-covered, and the shape of it is informative.
The stories that dominate are breaches. The stories that rarely get written are the ones where it works — and when they are written, they show what actually makes a case: money that has to become spendable, a jurisdiction willing to seize, and years of patient correlation.
Set this against the White House memo proposing that vetted US companies conduct disruption operations against foreign criminal groups. The argument for that memo is that law enforcement is too slow. Klonen took three years and produced arrests, charges in three countries and $22 million in seizures. Slow, and it ended with people in custody rather than with infrastructure that reconstitutes in a week.
Both things are true. Which one you weigh more heavily is the actual policy question.
What is not established
- Which processor shipped the faulty update, and what the fault was. Neither has been named in the reporting we could reach.
- How much of the €30 million has been recovered, as opposed to seized pending proceedings.
- Whether the seven charged are the whole group. Nothing in the reporting suggests it is closed.
The lesson for anyone running payments
The bank did nothing wrong that has been reported. Its processor shipped an update, and €30 million moved.
If you run reconciliation, the question this raises is not "are we patched". It is: would you notice €7.5 million a day of unauthorised direct debits, and how many days would it take?