{"investigation":{"slug":"cm-software","entity_name":"C&M Software","trust_score":8,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"C&M Software (also styled CMSW) is a Brazilian financial technology company authorized by the Banco Central do Brasil to provide connectivity between smaller financial institutions and Brazil's national payment infrastructure, including the PIX instant-payment system. On June 30, 2025, hackers exploited credentials sold by an insider employee to drain approximately R$800 million (roughly USD 140–148 million) from reserve accounts of at least six financial institutions, in what became Brazil's largest recorded banking cyberattack. A portion of the stolen funds—estimated at USD 30–40 million—was subsequently laundered through Latin American OTC desks and crypto exchanges using Bitcoin, Ethereum, and Tether USDT, with on-chain investigator ZachXBT playing a central role in tracing and partially freezing the laundered assets.","sections":[{"content":"C&M Software is a Brazilian technology company that provides integrated real-time payment infrastructure, credit-risk platforms, digital onboarding, fraud prevention, and ISO 20022-compliant interbank payment solutions. The company was one of eight entities authorized by the Banco Central do Brasil to operate as an Information Technology Services Provider (PSTI), granting it privileged connectivity to the Sistema de Pagamentos Brasileiro (SPB) and the Pix Instant Payment System (SPI). In this capacity, C&M acted as a mission-critical intermediary connecting over 300 smaller financial institutions—banks, fintechs, and payment processors—to the Central Bank's core settlement infrastructure. This architectural centrality meant that C&M held administrative access to the cryptographic certificates and credentials of its client institutions, creating a concentrated point of systemic risk.","heading":"Company Overview and Role in Brazilian Financial Infrastructure","sources":[],"severity":"medium"},{"content":"On June 30, 2025, between approximately 4:30 AM and 7:00 AM local time, hackers executed a coordinated attack on C&M Software's systems, siphoning an estimated R$800 million (approximately USD 140–148 million) from the reserve accounts of at least six financial institutions. BMP Money Plus was reported to be among the hardest-hit institutions, losing approximately R$400 million. The attack originated from an insider-threat vector: João Nazareno Roque, a 48-year-old IT worker at C&M Software, allegedly sold his administrative login credentials to the attackers for approximately R$15,000 (USD 2,700–3,000). According to Brazilian police and media reporting, Roque was first approached by an unidentified man outside a São Paulo bar in March 2025, in what investigators described as a classic social engineering recruitment. Roque subsequently created separate system accounts and enabled remote access that allowed the attackers to retrieve the digital certificates belonging to C&M's client institutions. Using these valid certificates, the attackers fabricated and injected fraudulent PIX payment orders directly into the SPI. Because the fraudulent transactions carried valid digital signatures, the Central Bank's settlement infrastructure processed them automatically without triggering anomaly alerts. The first irregularities were detected by exchanges at approximately 12:18 AM; by 4:00 AM a BMP Money Plus executive was alerted to an R$18 million unauthorized transfer, and by 5:00 AM the incident had been reported to C&M Software. The Banco Central subsequently ordered an emergency suspension of C&M's SPB connections. C&M Software issued a statement describing itself as 'a direct victim of criminal action, which included the misuse of credentials.'","heading":"June 2025 Insider-Enabled Cyberattack and $140M+ Bank Heist","sources":[],"severity":"medium"},{"content":"Following the theft, the attackers converted an estimated USD 30–40 million of the stolen funds into cryptocurrency—specifically Bitcoin, Ethereum, and Tether USDT—through Latin American over-the-counter (OTC) desks and crypto exchanges. On-chain investigator ZachXBT identified unusual volume spikes on several Brazilian exchanges on June 30, 2025, matching the timing of the C&M breach. ZachXBT manually traced hot wallet outflows and collaborated with multiple platforms—including Binance, Bitso, Bybit, and Tether—to freeze approximately USD 5 million in stolen cryptocurrency. ZachXBT stated he was working with Brazilian law enforcement and planned to release the associated wallet addresses publicly once authorities confirmed it was appropriate to do so. Brazilian courts separately froze approximately R$270 million (roughly USD 49–50 million) in fiat accounts suspected of receiving diverted funds. A significant portion of the laundered crypto remained unrecovered as of reporting.","heading":"Crypto Laundering via OTC Desks and Exchanges","sources":[],"severity":"medium"},{"content":"ZachXBT's on-chain investigation into the C&M Software hack drew significant attention to differing compliance postures among major crypto firms. ZachXBT publicly criticized Circle, the issuer of USDC, alleging that the company refused to assist in tracing or freezing stolen funds despite requests from investigators. ZachXBT stated that 'Circle leadership does not actually care about the industry,' contrasting Circle's alleged non-cooperation with the cooperation provided by Binance, Bitso, Bybit, Tether, and Chainalysis. The controversy highlighted an ongoing debate about the role and responsibility of stablecoin issuers in post-incident asset recovery. Circle had not publicly responded to the specific allegations as of reporting.","heading":"ZachXBT Investigation and Circle Controversy","sources":[],"severity":"medium"},{"content":"João Nazareno Roque, 48, was arrested by the Civil Police of São Paulo on July 3, 2025, two days after the attack. He reportedly confessed to selling his corporate login credentials in two payments: an initial R$5,000 and a subsequent R$10,000 for creating system access that enabled the diversions. Roque stated he communicated with the criminals only by mobile phone, changed handsets every 15 days to avoid detection, and did not know the attackers' identities. Brazilian police identified at least four hackers believed to be involved in orchestrating the attack. Roque remained in custody as the investigation continued. The Agência Brasil (state news agency) reported on the arrest.","heading":"Arrest of Insider Facilitator","sources":[],"severity":"medium"},{"content":"On approximately November 22, 2025, the DragonForce ransomware group listed C&M Software as a victim on their dark-web leak site, claiming to have exfiltrated 393.92 GB of data including financial automation logic, secure transmission documentation, customer data, email archives, software modules, and configuration files. DragonForce set a ransom deadline of November 29, 2025. German news outlet Ad-Hoc-News reported that C&M Software and security researchers suggested the group may have been recycling or re-releasing data from the earlier June 2025 compromise rather than presenting genuinely new exfiltration—a tactic sometimes called 're-extortion' or 'data recycling.' The botcrawl.com analysis did not independently confirm whether the data was recycled. Regardless of origin, the publication of 393 GB of critical financial infrastructure data on a dark-web forum represents a significant exposure risk for C&M's client institutions.","heading":"DragonForce Ransomware Claim — November 2025","sources":[],"severity":"medium"},{"content":"Security researchers and the LACNIC Blog identified the C&M incident as a paradigmatic example of supply-chain risk in financial infrastructure. Because C&M Software maintained centralized custody of cryptographic certificates for over 300 client institutions, a single insider compromise was sufficient to impersonate multiple financial institutions simultaneously within the Central Bank's settlement system. Researchers flagged specific governance failures: absence of behavioral monitoring on privileged accounts, excessive privilege concentration, lack of secrets-management segregation between clients and the technology provider, and inadequate access controls. The Segura Security technical analysis noted that transactions carried valid digital signatures, meaning the SPI processed fraudulent payment orders automatically as legitimate operations. The incident prompted calls for mandatory behavioral analytics, hardware security modules (HSMs) for certificate storage, and stricter separation of duties for PSTIs operating within Brazil's payment ecosystem.","heading":"Supply Chain Risk and Systemic Vulnerabilities","sources":[],"severity":"medium"}],"timeline":[{"date":"2025-03","event":"João Nazareno Roque, a C&M Software IT employee, is allegedly approached outside a São Paulo bar by an unidentified individual who demonstrates knowledge of his employer and begins the social engineering recruitment process.","source":"","source_url":"https://www.technadu.com/tragic-fall-from-electrician-to-it-c-suite-aspirations-end-as-employee-gets-arrested-for-selling-credentials/602034/","date_original":"2025-03-01"},{"date":"2025-06-30","event":"Between 12:18 AM and 7:00 AM, attackers use insider credentials and stolen digital certificates to inject fraudulent PIX payment orders into Brazil's SPI, draining an estimated R$800 million (USD 140–148 million) from reserve accounts of at least six financial institutions. The Banco Central orders emergency suspension of C&M's SPB connections.","source":"","source_url":"https://segura.security/post/cyberattack-on-brazils-payment-system-technical-analysis-timeline-risks-and-mitigation/"},{"date":"2025-07","event":"Media disclosure begins. Brazilian courts begin freezing accounts; approximately R$160 million reported recovered in initial freeze actions. ZachXBT begins publicly tracing converted crypto funds.","source":"","source_url":"https://segura.security/post/cyberattack-on-brazils-payment-system-technical-analysis-timeline-risks-and-mitigation/","date_original":"2025-07-01"},{"date":"2025-07-03","event":"João Nazareno Roque arrested by São Paulo Civil Police. He confesses to selling credentials for approximately R$15,000 in two installments and enabling remote system access. Police identify at least four hackers involved.","source":"","source_url":"https://therecord.media/brazil-police-arrest-worker-theft"},{"date":"2025-07-04","event":"CoinDesk reports that hackers laundered USD 30–40 million of the stolen funds through Latin American OTC desks and crypto exchanges using Bitcoin, Ethereum, and Tether USDT. ZachXBT publicly describes his investigation and collaboration with Brazilian law enforcement.","source":"","source_url":"https://www.coindesk.com/business/2025/07/04/hackers-behind-usd140m-brazil-banking-heist-turn-to-crypto-to-launder-their-loot"},{"date":"2025-07-04","event":"ZachXBT announces that USD 5 million in crypto has been frozen through cooperation with Binance, Bitso, Bybit, Tether, and Chainalysis. He publicly criticizes Circle for allegedly refusing to cooperate with the investigation.","source":"","source_url":"https://coinedition.com/zachxbt-slams-circle-brazil-heist-investigation/"},{"date":"2025-11-22","event":"DragonForce ransomware group lists C&M Software on their dark-web leak site, claiming to have exfiltrated 393.92 GB of sensitive financial infrastructure data. Ransom deadline set for November 29, 2025. Researchers note the data may be recycled from the June 2025 compromise.","source":"","source_url":"https://botcrawl.com/cm-software-data-breach/"}],"sources_used":[],"source_tags":["etherscan","zachxbt"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet","created_at":"2026-05-04T16:05:01.406714+00:00","updated_at":"2026-08-29T01:35:52.245+00:00"}}