Brazilian police arrest IT worker over $100M banking cyberattack

Reuters

Brazilian authorities have arrested a suspect linked to a cyberattack that diverted more than 540 million reais (about $100 million) from the country’s banking network.

The breach targeted Brazil’s PIX instant payment system, which is used by more than 76% of the population. According to police, the hackers infiltrated systems via C&M, a software firm that connects financial institutions to the Central Bank’s PIX platform.

The suspect, João Roque, was an IT employee at C&M. Investigators say he admitted selling his credentials to hackers earlier this year, allowing them to carry out a large-scale overnight fraud operation. The attack affected financial institutions using C&M’s services but did not impact individual customers.

Authorities estimate the $100 million loss reflects just one bank’s damages, with overall losses potentially higher. Police have so far frozen 270 million reais in suspected assets and believe at least four other individuals were involved.

Brazil’s Central Bank suspended parts of C&M’s operations following the breach. The company said it is fully cooperating with investigators and claimed the intrusion was due to social engineering rather than a system failure.

Tags