Inside Job? How One Employee’s Alleged Betrayal Led to a $140 Million Central Bank Hack
The breach, which targeted C&M Software, the company that links the central bank to local financial institutions, reportedly began with an alleged act of betrayal by one of its own employees. The Growing Danger of Inside...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
The breach, which targeted C&M Software, the company that links the central bank to local financial institutions, reportedly began with an alleged act of betrayal by one of its own employees.
The Growing Danger of Insider ThreatsInvestigators believe the hackers gained access to C&M’s critical systems by purchasing the login credentials of an employee for what seems like a modest sum: around $2,700. This single transaction, if proven true, allowed cybercriminals to bypass sophisticated security measures and steal a staggering 800 million Brazilian reais from reserve accounts held at six different banks.
The alleged sale of login details highlights a growing concern in the cybersecurity world: the “insider threat.” This refers to security risks that come from within an organization, often from current or former employees, contractors, or business partners who have inside information concerning security practices, data, and computer systems. While many cybersecurity threats come from external actors trying to break in, insider threats can be particularly damaging because the individuals already have a level of trusted access.
“Cybercriminals see ‘massive’ returns in targeting centralized systems that can contain millions of passwords, sensitive documents or billions of dollars in capital, which makes these systems attractive targets,” explained Eran Barak, CEO of Shielded Technologies. This perspective suggests that the potential reward for an insider, even if a smaller cut is taken by selling access, can be incredibly tempting when compared to the risks of operating solely from the outside. This latest insider breach follows another earlier this year that saw Coinbase employees selling customer details for
Brazilian police have reportedly arrested a man identified as a C&M employee in connection with the hack, further pointing to the insider angle. This arrest suggests that authorities are focusing on the alleged sale of credentials as the primary point of entry for the attackers.
The stolen funds were quickly moved and disguised. Onchain detective ZachXBT noted that an estimated $30 million to $40 million of the stolen money was converted into popular cryptocurrencies like Bitcoin, Ether, and USDt. These digital assets were then reportedly laundered through exchanges and trading platforms in Latin America, making them harder to trace back to the original theft.
A Centralized System’s VulnerabilityThis incident serves as a stark reminder of the vulnerabilities inherent in centralized digital systems. In these systems, a single point of failure—like one compromised employee account—can have devastating consequences, leading to significant financial losses or the theft of sensitive information.
Why this matters
This security story adds another data point to the current market tape and is useful when read alongside nearby source coverage.
Original source
Read on Brave New CoinRelated market context
Iran-linked exchange sent $676 million to Binance in alleged sanctions-evasion operation: Reuters
Dubai-based Shelbit processed over $4 billion since May 2024 through a network tied to Iranian gambling sites, the central bank, a...
Bitcoin Price Prediction: $10 Billion of BTC and ETH Option Expiry Hitting the Market Today
The largest single-day options expiry in recent months is clearing today, and the market is already pricing in the friction. Bitco...
CEO allegedly steals $5M from blockchain firm, deletes 194 expense records to cover tracks
This incident highlights the urgent need for stronger governance and oversight in blockchain firms to prevent insider fraud and re...
Why 110 corporate blockchains are headed for a massive shakeout – and Coinbase’s secret plan to absorb them
Corporate blockchains are multiplying, but Coinbase CEO Brian Armstrong expects the boom to end in consolidation rather than coexi...
Coldcard Security Notice Puts Bitcoin Wallet Entropy Risk Back In Focus
A Coldcard security issue has put Bitcoin hardware-wallet safety back under the microscope after reports that a firmware flaw affe...
As Ethereum turns 11 years old it hosts $148B in stablecoins, but daily mainnet revenue just fell to $330k
Ethereum turned 11 on July 30, the anniversary of the day users generated and loaded the Frontier genesis block in 2015. In its fi...