The Perfect Storm: The Largest Cyberattack on Brazil’s Financial System

05/09/2025

The Perfect Storm: The Largest Cyberattack on Brazil’s Financial System
Designed by Freepik

By Graciela Martínez, Head of LACNIC CSIRT

On June 30 this year, Brazil faced the largest cybercrime in its history. C&M Software (CMSW), a critical financial infrastructure provider authorized by the Central Bank, was compromised by a criminal group that diverted billions of reais through the instant payment system PIX.

The incident not only highlights the magnitude of the risks associated with the digitalization of the financial system but also exposes the vulnerabilities of the supply chain and the power of social engineering in cyberattacks.

Timeline

March 2025 – A junior developer at C&M Software is approached in a bar and agrees to sell his login credentials for R$ 5,000.

May 2025 – The same employee runs commands in the company’s systems to enable remote access for the attackers.

June 11, 2025 – The company Monexa Gateway de Pagamentos is incorporated, later receiving transfers totaling R$ 45 million during the attack.

June 30, 2025 – The criminal group launches the operation: hundreds of fraudulent transactions via PIX are carried out in the early hours of the morning.

(Free access, no subscription required)

July 2, 2025 – The Federal Police open an investigation with the support of the Central Bank.

Attack Mechanism

The intrusion vector originated from the misuse of internal credentials, obtained through social engineering targeting a C&M employee.

Once inside, the attackers mapped the infrastructure of the Corner platform, identifying critical authentication artifacts and shared credentials belonging to client financial institutions.

The views expressed by the authors of this blog are their own and do not necessarily reflect the views of LACNIC.

0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments