Hackers allegedly bribed a C&M employee to steal $140 million from six banks in one day

Source Cryptopolitan

In a bold cyber heist on June 30, an estimated $140 million (R$800 million) was stolen from six Brazilian financial institutions’ reserve accounts through a sophisticated cyberattack targeting C&M Software, a key service provider that connects banks to the Central Bank of Brazil and its PIX system. 

At least $30 to $40 million of the stolen funds have since been laundered into Bitcoin, Ethereum, and Tether’s USDT via Latin American over-the-counter (OTC) desks and exchanges, according to on‑chain investigator ZachXBT.

The Central Bank of Brazil heist started as an internal compromise

The hackers reportedly paid a C&M Software employee just R$15,000 (~$2,760) in exchange for corporate login credentials. Armed with those, they deployed social engineering techniques to access the central bank service infrastructure. This allowed them to siphon funds from the reserve accounts of six institutions, including Banco BMF and others, within the same day.

Upon discovery, the Central Bank of Brazil swiftly instructed C&M to sever its connections, effectively isolating the provider from banking systems. The breach led to the temporary suspension of PIX-related services while authorities and internal teams rallied to restore security and prevent wider contagion.

The hack closely follows the pattern of the recent attack on the crypto exchange Coinbase, where customer service agents took bribes to reveal customer information. This led to the breach of over 69,000 accounts, with Coinbase expected to reimburse as high as $400 million to customers.

On-chain sleuth follows the crypto laundering trail

ZachXBT, a leading figure in blockchain forensics, reported he has been actively collaborating with Brazilian law enforcement to track stolen funds and prevent further laundering on-chain.

Public statements from ZachXBT indicate he plans to release the addresses linked to the theft “when it’s okay to share them,” to aid authorities in freezing additional crypto assets.

Brazilian federal investigators have arrested at least one suspect: the C&M employee whose credentials were sold. Authorities have already frozen approximately R$270 million, approximately $55 million in compromised funds.

The Central Bank of Brazil also claims to have reinforced monitoring systems to better detect irregular PIX-related transactions.

Security analysts warn that the attention-grabbing $140 million figure distracts from the larger threat of social engineering. This tactic consistently tops the list of vulnerabilities in the financial sector. Despite technical firewalls and hardened systems, insiders with stolen credentials can render them moot.

The response has moved on to damage control and reputational repair

The attack mirrors recent trends in crypto crime and how proceeds from crimes that didn’t happen on-chain are also funneled into crypto.

In the first half of 2025 alone, industry watchdog CertiK estimated losses from hacks and scams at a staggering $2.5 billion, with most of the incidents happening on the Ethereum network, followed by Bitcoin. The report also showed that wallet compromise and phishing are the leading tools hackers employ for their heists.

Although they have both shared press releases acknowledging the hack and pointing out that investigations are ongoing, neither C&M nor the Central Bank of Brazil has released a detailed public breakdown of the damage. The Central Bank of Brazil has not revealed the details of the financial institutions affected by the hack.

However, insiders reveal ongoing operations to mitigate reputational and customer impact, primarily through customer account security assurances and increased transaction verifications.

The immediate focus for authorities lies in recovering laundered assets and preventing further crypto conversions.

On-chain analysts like ZachXBT now occupy a strategic role in global cyber defense, providing a powerful investigative path into crypto laundering networks.

Cryptopolitan Academy: Want to grow your money in 2025? Learn how to do it with DeFi in our upcoming webclass. Save Your Spot

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Natural Gas sinks to pivotal level as China’s demand slumpsNatural Gas price (XNG/USD) edges lower and sinks to $2.56 on Monday, extending its losing streak for the fifth day in a row. The move comes on the back of China cutting its Liquified Natural Gas (LNG) imports after prices rose above $3.0 in June. It
Author  FXStreet
Jul 01, 2024
Natural Gas price (XNG/USD) edges lower and sinks to $2.56 on Monday, extending its losing streak for the fifth day in a row. The move comes on the back of China cutting its Liquified Natural Gas (LNG) imports after prices rose above $3.0 in June. It
placeholder
ECB Policy Outlook for 2026: What It Could Mean for the Euro’s Next MoveWith the ECB likely holding rates steady at 2.15% and the Fed potentially extending cuts into 2026, EUR/USD may test 1.20 if Eurozone growth proves resilient, but weaker growth and an ECB pivot could pull the pair back toward 1.13 and potentially 1.10.
Author  Mitrade
Dec 26, 2025
With the ECB likely holding rates steady at 2.15% and the Fed potentially extending cuts into 2026, EUR/USD may test 1.20 if Eurozone growth proves resilient, but weaker growth and an ECB pivot could pull the pair back toward 1.13 and potentially 1.10.
placeholder
WTI eases below $103.50 as US, Iran reportedly seeking 45-day ceasefireWest Texas Intermediate (WTI), the US crude oil benchmark, is trading around $103.30 during the early European trading hours on Monday. The WTI price retreats after reports that the United States (US) and Iran are making a push for a 45-day ceasefire. 
Author  FXStreet
Apr 06, Mon
West Texas Intermediate (WTI), the US crude oil benchmark, is trading around $103.30 during the early European trading hours on Monday. The WTI price retreats after reports that the United States (US) and Iran are making a push for a 45-day ceasefire. 
placeholder
Crypto Weekly Radar: All eyes on Donald Trump’s ultimatum, US macroeconomic dataCrypto markets begin the week with mixed sentiment, with Bitcoin (BTC) trading above $69,000 following last week’s rebound. Still, markets remain cautious as traders weigh risks stemming from Donald Trump’s renewed threats toward Iran ahead of the ultimatum set for Tuesday.
Author  FXStreet
Apr 06, Mon
Crypto markets begin the week with mixed sentiment, with Bitcoin (BTC) trading above $69,000 following last week’s rebound. Still, markets remain cautious as traders weigh risks stemming from Donald Trump’s renewed threats toward Iran ahead of the ultimatum set for Tuesday.
placeholder
WTI Price Forecast: Seems vulnerable near $90.50 as technical breakdown comes into playWest Texas Intermediate (WTI) – the benchmark US Crude Oil price – plummets to a nearly two-week trough during the Asian session on Wednesday in reaction to news that the US and Iran have agreed to a two-week ceasefire.
Author  FXStreet
13 hours ago
West Texas Intermediate (WTI) – the benchmark US Crude Oil price – plummets to a nearly two-week trough during the Asian session on Wednesday in reaction to news that the US and Iran have agreed to a two-week ceasefire.
goTop
quote