C&M Software hack — June 2025
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | July 2, 2025 |
| Target type | Infrastructure provider |
| Loss | $100,000,000Published estimates range $100,000,000 to $140,000,000Price at time of incident |
| Recovered | $49,000,000 |
| Method | Insider actionAn IT employee of C&M Software, the technology provider that connects smaller Brazilian institutions to the central bank's Pix rails, sold his system credentials to people who recruited him; police say he helped others gain unauthorised access to Pix systems. The attackers then issued large volumes of fraudulent Pix transfers out of the reserve accounts that C&M's client institutions hold directly at the Banco Central do Brasil, in a single night. C&M said the breach involved fraudulent use of client credentials obtained through social engineering rather than a flaw in its systems. |
| Chains | Off-chain systems |
| Attributed to | João Nazareno Roque, a C&M Software IT employee, arrested by São Paulo police; police say at least four more people took partAlleged |
| Outcome | Arrests or charges |
What happened
On the night of Monday 30 June 2025, attackers issued fraudulent Pix transfers out of reserve accounts that Brazilian financial institutions hold directly at the central bank, using access to C&M Software, a provider that connects institutions without their own connectivity infrastructure to the Banco Central do Brasil. Reuters reported that the central bank ordered C&M to cut off client access. C&M's commercial director said the company was a direct victim and that the intrusion involved fraudulent use of client credentials rather than a flaw in its systems. The institution BMP told Reuters that it and five others had unauthorised access to their reserve accounts, that no customer accounts were touched, and that it held enough collateral to cover the impacted amount.
São Paulo police arrested João Nazareno Roque, a C&M IT employee. According to police he told investigators he sold his credentials to hackers who had recruited him; The Record reported the payment as about $2,700 in two cash instalments, and G1 reported it as about R$15,000. Police said at least four more people took part and continued tracing assets.
The totals are disputed. Police and the Associated Press put the loss at more than R$540 million, about $100 million, and said that figure covered a single institution with the true total possibly higher; coverage citing researchers has put the total near R$800 million, about $140 million, across six institutions. Authorities blocked R$270 million, roughly $49 million.
The theft itself was of reais on Brazil's payment system. The Record, citing investigator ZachXBT, reported that roughly $30–40 million of the proceeds was converted into bitcoin, ether and USDT through over-the-counter brokers.
Law enforcement
São Paulo state police; Banco Central do Brasil ordered C&M to shut down financial institutions' access and later suspended part of its operations
Sources
- ReutersSecondary · retrieved 2026-08-01
- Associated PressSecondary · retrieved 2026-08-01
- The Record (Recorded Future News)Secondary · retrieved 2026-08-01
- G1 (Grupo Globo)Secondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "C&M Software hack — June 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/cm-softwarehttps://itokenly.com/hacks/cm-softwarePermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.