The C&M Software hack: a sold login and $140 million from Brazil's bank reserves
Police say the login that opened a path to Brazil's central bank reserve accounts in 2025 cost the buyers about $2,700, and roughly $140 million went out the door in a few early-morning hours.[1][2][3] This case file covers how a payments vendor's employee access was turned against the banks it served, how police traced it, and the one control that would have caught it early.
What happened
C&M Software is a Brazilian company that connects about two dozen smaller financial institutions, which do not have their own direct link, to the central bank's payment systems, including Pix, the country's instant payment network.[2][4] Each of those institutions keeps a reserve account at the central bank that is used only to settle payments between banks.[5]
According to police, the plot started in March 2025, when a man approached a C&M IT employee outside a bar in São Paulo. Further contact happened over WhatsApp calls.[1][2] Around the turn of June into July 2025, attackers used valid C&M access to send fraudulent Pix transfer orders that appeared to come from client institutions, draining reserve accounts within about 3 hours in the early morning.[3] At least 6 institutions were affected, and reported losses came to about 800 million reais, roughly $140 million.[1][2][5]
On July 2 the central bank ordered C&M's connections cut while it investigated.[3][4] Within days, São Paulo police arrested the employee at his home.[2][6]
How it worked
This was not a break-in through a software flaw. C&M said no technical breach of its systems occurred and that the attackers used legitimate credentials, obtained through social engineering, the practice of manipulating a person rather than a machine.[2][3]
Police say the employee sold his login for about 5,000 reais, around $900, and was then paid about 10,000 reais more, around $1,800, to run commands on the attackers' behalf from his own computer.[2] Investigators said he had access to client systems through his work equipment.[6] He also told police he changed phones about every 15 days to avoid being traced.[1][2]
Because the vendor sat between the banks and the central bank, activity from its trusted accounts looked routine. Once the money moved, it was pushed quickly through over-the-counter crypto desks and exchanges, and an estimated $30 million to $40 million was converted into cryptocurrency.[2][3]
How it was caught
The unusual transfers were spotted by the affected institutions and the central bank, which suspended C&M's access. The vendor said its security protocols let it respond quickly and that it was cooperating with the central bank and São Paulo state police.[3][4]
Police traced the employee and arrested him in early July 2025. Police said he admitted selling his login and helping the attackers.[3][7] He has not been convicted. In September 2025 Brazil's Federal Police arrested 8 more suspects linked to the C&M attack and a similar attack on another provider. All 8 denied involvement, according to local reporting.[7]
What it cost
An account holding about 270 million reais, roughly $50 million, that had received diverted money was blocked.[3][6] One of the hardest-hit institutions reported losses of about 400 million reais and recovered about 150 million reais through Pix's special return mechanism.[3][6] The institutions said customer accounts and balances were not touched, because the money came from the banks' own settlement reserves.[4][5] Later Federal Police figures put the total diverted in the C&M attack higher, at about 1.2 billion reais.[7]
The missing control
The missing control: monitoring what privileged vendor credentials actually do. That means watching the behavior of powerful accounts, such as volume, timing and destination of transfers, not just checking that the password is valid.
A correct login proved nothing here, because it was the real login. What was abnormal was the behavior: a burst of large transfers from reserve accounts in the small hours, to new destinations, in a pattern no ordinary workday produces. Alerts on unusual volume, hold periods on large first-time transfers, and dual approval for moves above a threshold would have flagged or slowed it within minutes rather than hours.
What to do in your business
- List every vendor that can move your money. Payroll services, payment processors and IT providers with admin access all belong on it, along with what each can do.
- Set limits and alerts at your bank. Ask for daily transfer caps, alerts for every outgoing payment over a set amount, and a second approver for large or first-time payees.
- Watch for odd hours and bursts. Review weekly who logged in to money systems, when and from where. Activity at 4 a.m. or a sudden spike should be a question, not a footnote.
- Give each person their own login. Shared vendor accounts make it impossible to tell who did what. Require named accounts with MFA, and remove them when the work ends.
- Tell staff that selling access is a crime, and that approaches get reported. Make it easy and safe for employees to report someone offering money for logins.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: How to manage vendor, IT provider and contractor access to your systems
- How the Target breach happened: a vendor's billing login and the alarms nobody answered
- How the SolarWinds hack happened: malware shipped as a trusted update
- What caused the Marriott breach: the intruder that came with Starwood
- How the Bybit hack happened: a vendor's laptop and a screen that lied
- How the Caesars hack happened: a con at the outsourced IT help desk
- How the $45 million ATM heist worked: prepaid cards with no limits
- Every vendors and third parties control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- Bitdefender: Employee arrested after Brazil's central bank service provider hacked for US $140 million
- CyberInsider: IT employee sold credentials used in $140M Brazil banks hack
- Decrypt: Hacker spent $2K to steal $140 million from Brazil central bank
- TEISS: Cyberattack hits Brazilian financial services provider C&M Software, triggers central bank response
- Business Insurance: Cyberattack hits reserve accounts of six banks
- Money Times: Polícia Civil prende suspeito de ataque hacker à C&M; conta com R$ 270 milhões foi bloqueada
- Baguete: PF prende oito suspeitos de ataques à C&M e à Sinqia