Skip to main content
AVOID.NET

Summary

C&M Software (also styled CMSW) is a Brazilian financial technology company authorized by the Banco Central do Brasil to provide connectivity between smaller financial institutions and Brazil's national payment infrastructure, including the PIX instant-payment system. On June 30, 2025, hackers exploited credentials sold by an insider employee to drain approximately R$800 million (roughly USD 140–148 million) from reserve accounts of at least six financial institutions, in what became Brazil's largest recorded banking cyberattack. A portion of the stolen funds—estimated at USD 30–40 million—was subsequently laundered through Latin American OTC desks and crypto exchanges using Bitcoin, Ethereum, and Tether USDT, with on-chain investigator ZachXBT playing a central role in tracing and partially freezing the laundered assets.

Connected Entities

6 entities · 60 linked investigations
Organizations
Ethereum64TetherBinanceC&M SoftwareZachXBT
Tokens
Bitcoin
Relationships
  • Ethereummentioned withBitcoin(60%)
  • ZachXBTmentioned withEthereum(70%)
  • ZachXBTmentioned withBitcoin(65%)
  • ZachXBTmentioned withBinance(60%)
  • Binancementioned withTether(60%)
  • Binancementioned withEthereum(65%)
  • C&M Softwarementioned withZachXBT(70%)
  • C&M Softwarementioned withBitcoin(70%)
  • C&M Softwarementioned withTether(70%)
  • C&M Softwarementioned withBinance(70%)
  • + 2 more
Have evidence about C&M Software?

Timeline(7 events)

March 2025

João Nazareno Roque, a C&M Software IT employee, is allegedly approached outside a São Paulo bar by an unidentified individual who demonstrates knowledge of his employer and begins the social engineering recruitment process.

30 June 2025

Between 12:18 AM and 7:00 AM, attackers use insider credentials and stolen digital certificates to inject fraudulent PIX payment orders into Brazil's SPI, draining an estimated R$800 million (USD 140–148 million) from reserve accounts of at least six financial institutions. The Banco Central orders emergency suspension of C&M's SPB connections.

July 2025

Media disclosure begins. Brazilian courts begin freezing accounts; approximately R$160 million reported recovered in initial freeze actions. ZachXBT begins publicly tracing converted crypto funds.

3 July 2025

João Nazareno Roque arrested by São Paulo Civil Police. He confesses to selling credentials for approximately R$15,000 in two installments and enabling remote system access. Police identify at least four hackers involved.

4 July 2025

CoinDesk reports that hackers laundered USD 30–40 million of the stolen funds through Latin American OTC desks and crypto exchanges using Bitcoin, Ethereum, and Tether USDT. ZachXBT publicly describes his investigation and collaboration with Brazilian law enforcement.

4 July 2025

ZachXBT announces that USD 5 million in crypto has been frozen through cooperation with Binance, Bitso, Bybit, Tether, and Chainalysis. He publicly criticizes Circle for allegedly refusing to cooperate with the investigation.

22 November 2025

DragonForce ransomware group lists C&M Software on their dark-web leak site, claiming to have exfiltrated 393.92 GB of sensitive financial infrastructure data. Ransom deadline set for November 29, 2025. Researchers note the data may be recycled from the June 2025 compromise.

Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event).

model: claude-sonnet

generated: 5/4/2026, 4:05:01 PM

last updated: 8/29/2026, 1:35:52 AM

5 views

avoid.net — verified advice for a post-truth world