Case file · C&M SOFTWARE 2025

The C&M Software hack: a sold login and $140 million from Brazil's bank reserves

Published 2026-09-29 · 4 min read · Missing control: Monitor vendor privileged credential use

Police say the login that opened a path to Brazil's central bank reserve accounts in 2025 cost the buyers about $2,700, and roughly $140 million went out the door in a few early-morning hours.[1][2][3] This case file covers how a payments vendor's employee access was turned against the banks it served, how police traced it, and the one control that would have caught it early.

What happened

C&M Software is a Brazilian company that connects about two dozen smaller financial institutions, which do not have their own direct link, to the central bank's payment systems, including Pix, the country's instant payment network.[2][4] Each of those institutions keeps a reserve account at the central bank that is used only to settle payments between banks.[5]

According to police, the plot started in March 2025, when a man approached a C&M IT employee outside a bar in São Paulo. Further contact happened over WhatsApp calls.[1][2] Around the turn of June into July 2025, attackers used valid C&M access to send fraudulent Pix transfer orders that appeared to come from client institutions, draining reserve accounts within about 3 hours in the early morning.[3] At least 6 institutions were affected, and reported losses came to about 800 million reais, roughly $140 million.[1][2][5]

On July 2 the central bank ordered C&M's connections cut while it investigated.[3][4] Within days, São Paulo police arrested the employee at his home.[2][6]

How it worked

This was not a break-in through a software flaw. C&M said no technical breach of its systems occurred and that the attackers used legitimate credentials, obtained through social engineering, the practice of manipulating a person rather than a machine.[2][3]

Police say the employee sold his login for about 5,000 reais, around $900, and was then paid about 10,000 reais more, around $1,800, to run commands on the attackers' behalf from his own computer.[2] Investigators said he had access to client systems through his work equipment.[6] He also told police he changed phones about every 15 days to avoid being traced.[1][2]

Because the vendor sat between the banks and the central bank, activity from its trusted accounts looked routine. Once the money moved, it was pushed quickly through over-the-counter crypto desks and exchanges, and an estimated $30 million to $40 million was converted into cryptocurrency.[2][3]

How it was caught

The unusual transfers were spotted by the affected institutions and the central bank, which suspended C&M's access. The vendor said its security protocols let it respond quickly and that it was cooperating with the central bank and São Paulo state police.[3][4]

Police traced the employee and arrested him in early July 2025. Police said he admitted selling his login and helping the attackers.[3][7] He has not been convicted. In September 2025 Brazil's Federal Police arrested 8 more suspects linked to the C&M attack and a similar attack on another provider. All 8 denied involvement, according to local reporting.[7]

What it cost

An account holding about 270 million reais, roughly $50 million, that had received diverted money was blocked.[3][6] One of the hardest-hit institutions reported losses of about 400 million reais and recovered about 150 million reais through Pix's special return mechanism.[3][6] The institutions said customer accounts and balances were not touched, because the money came from the banks' own settlement reserves.[4][5] Later Federal Police figures put the total diverted in the C&M attack higher, at about 1.2 billion reais.[7]

The missing control

The missing control: monitoring what privileged vendor credentials actually do. That means watching the behavior of powerful accounts, such as volume, timing and destination of transfers, not just checking that the password is valid.

A correct login proved nothing here, because it was the real login. What was abnormal was the behavior: a burst of large transfers from reserve accounts in the small hours, to new destinations, in a pattern no ordinary workday produces. Alerts on unusual volume, hold periods on large first-time transfers, and dual approval for moves above a threshold would have flagged or slowed it within minutes rather than hours.

What to do in your business

Watch the case
The bank login police say sold for about $2,700Drops 2026-11-17
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More vendors and third parties cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. Bitdefender: Employee arrested after Brazil's central bank service provider hacked for US $140 million
  2. CyberInsider: IT employee sold credentials used in $140M Brazil banks hack
  3. Decrypt: Hacker spent $2K to steal $140 million from Brazil central bank
  4. TEISS: Cyberattack hits Brazilian financial services provider C&M Software, triggers central bank response
  5. Business Insurance: Cyberattack hits reserve accounts of six banks
  6. Money Times: Polícia Civil prende suspeito de ataque hacker à C&M; conta com R$ 270 milhões foi bloqueada
  7. Baguete: PF prende oito suspeitos de ataques à C&M e à Sinqia