The largest robbery of the Central Bank of Brazil - Hackers steal R$400 million
On Tuesday, July 1, 2025, C&M Software — the company responsible for the messaging that connects banks and fintechs to the Brazilian Payment System (SPB) and Pix — suffered a hacker attack that resulted in the diversion of at least R$ 400 million from the reserve accounts of five financial institutions held with the Central Bank. valor.globo.com
Founded in 1992 by Orli Machado, C&M reaffirms that it is a direct victim of the criminal act, guarantees that all of its critical systems remain intact and operational, and actively collaborates with the Central Bank and the Civil Police of São Paulo in the investigations. valor.globo.com
One of the affected institutions, BMP, reported that the incident only compromised resources from its reserve account, without affecting clients or partners, and that it has sufficient collateral to fully cover the impacted amount. valor.globo.com
Despite part of the resources being recovered through the MED (Special Mechanism for Pix Refund), experts question how a diversion of this magnitude went unnoticed by the Central Bank, which does not have volume locks for real-time fraud detection. valor.globo.com
In response, the Central Bank ordered the immediate disconnection of C&M from its infrastructures, and the Federal Police is expected to deepen the investigations. The episode highlights the urgent need to strengthen cybersecurity throughout the instant payment chain. valor.globo.com
#cybersecurity #PIX #Cibercrime