Reports published in July 2025 said an employee of Brazilian financial-technology provider C&M Software received about $920 for credentials later used in an attack linked to nearly $140 million in unauthorized transfers. That headline figure is an early estimate, not a final audited loss, and accounts differ on both the employee’s alleged payment and the total amount diverted.
What happened in the Brazil banking-system attack?
The reported attack took place on June 30, 2025, and involved C&M Software, a private company that connects financial institutions to payment and settlement infrastructure. Early reporting alleged that attackers obtained or used an employee’s credentials and then directed the employee to carry out commands. The precise mechanics have not been established in a complete, independently verified technical postmortem.
Reuters reported that C&M notified Brazil’s Central Bank of an attack on July 2. The Bank ordered access to C&M’s infrastructure blocked, and Brazil’s Federal Police opened an inquiry. C&M commercial director Kamal Zogheib said the company was directly victimized and described fraudulent use of client credentials, according to Reuters’ Portuguese-language report republished by UOL Economia.
The reporting does not establish that Brazil’s Central Bank itself was breached. The identified target was C&M’s systems and the connections it provided to financial institutions.
#1 Best Overall
- A FIDO security key with PUF technology provides a unique, hardware-rooted trust anchor that resists tampering and cyber attacks, offering stronger security than conventional designs.
- FIDO2 Certified Protection – Enjoy phishing-resistant security with FIDO2 certification, ensuring top-tier account safety across Windows, macOS, Linux, iOS iOS, Android and more.
- Easy to use & Portable – Designed with a compact USB-C interface, Clife key fits easily on your keychain for secure access anywhere. Simply plug in and authenticate with ease.
- Universal Compatibility – Works seamlessly with hundreds of FIDO2/U2F compliant services, including popular cloud, email, and social platforms.
- Backup recommended – To ensure continuous access, register a backup Clife security key as a spare in case your primary key is lost.
How much was the employee allegedly paid?
The payment accounts differ. BleepingComputer reported that the employee first received approximately $920 for credentials and later another $1,850 for carrying out commands at the attackers’ direction. It said the employee allegedly received instructions through Notion. UOL Tilt, by contrast, reported an alleged total payment of R$15,000. These are separate accounts; the available reporting does not reconcile them.
Police arrested João Nazareno Roque, also reported as João Roque, in early July. The Associated Press described him as an employee suspected of selling credentials. An arrest and allegations are not a conviction, and the sources cited here do not establish a court disposition.
Rank #2
- Hardware-Rooted Security with PUF Technology – PUFido Drive Clife Key uses Physical Unclonable Function technology to generate a unique, hardware-based identity that cannot be duplicated, delivering stronger resistance against tampering and cyber attacks than conventional security keys.
- FIDO2 Certified Phishing-Resistant Protection – Fully compliant with FIDO2/U2F standards, enabling secure passwordless login and two-factor authentication to help protect accounts from phishing and credential theft.
- Security Key + Flash Drive in One Device – Combines a FIDO security key with a built-in USB flash drive, allowing you to carry files and a hardware authentication key together in a single compact device.
- Easy to Use & Portable – Compact USB-C design fits easily on a keychain or in a pocket. Simply plug in the Drive Clife Key to authenticate or access stored files with no extra software required.
- Universal Compatibility – Works with hundreds of FIDO2/U2F compatible services and supports Windows, macOS, Linux, iOS, Android, and other major platforms.
How much money was diverted?
The often-repeated “$140 million” figure came from BleepingComputer’s July 7, 2025 report, which described an early estimate involving six Brazilian banks. Other reports gave different amounts and scopes:
| Report | Amount and scope | What the figure means |
|---|---|---|
| BleepingComputer, July 7, 2025 | Nearly $140 million | Early reported estimate associated with six Brazilian banks; not a final audited total. |
| Associated Press, July 4, 2025 | More than R$540 million | Police-described amount relating to one institution; AP said total losses could be higher. |
| UOL Tilt, July 4, 2025 | R$541 million | Transactions at BMP; the report also attributed a R$1 billion total-loss estimate to investigators as additional clients were being identified. |
LACNIC’s August 2025 incident analysis also described widely varying contemporaneous estimates. These figures should not be added together: they refer to different scopes and may overlap. No final audited loss total or complete accounting of recovered funds is established in the cited reporting.
Quick Recap
Rank #4
- Dual USB-A and USB-C Security Key – Features both USB-A and USB-C connectors for seamless compatibility across desktops, laptops, and tablets. Supports plug-and-stay use or keychain carry.
- NFC-Enabled for Mobile Access – Built-in NFC allows fast, wireless authentication with Android and iPhone devices. Ideal for mobile logins and on-the-go security.
- FIDO Certified for Strong Authentication – [CHECK COMPATIBILITY before purchase] Fully compliant with FIDO2 and FIDO U2F standards. Works with major platforms like Google, Microsoft, GitHub, and Dropbox.
- Passwordless Login with PinPlex – Supports secure passkey login via WebAuthn and CTAP2 with added protection from PinPlex, a complex PIN system that enhances physical security.
- Multi-Layer Authentication Support – Includes PIV certificates and supports both TOTP and HOTP for strong 2FA/MFA coverage across enterprise and consumer apps.
Rank #3
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
What is known—and what remains unresolved?
- Reported attack date: June 30, 2025.
- Company identified: C&M Software, a private connectivity provider for financial institutions.
- Alleged insider role: News reports and investigators described an employee’s credentials and assistance as part of the incident; the reported conduct remains an allegation.
- Central Bank involvement: The Bank ordered C&M’s access to its infrastructure blocked after C&M reported an attack. The available reporting does not show the Bank itself was hacked.
- Open questions: The sources cited here do not establish a final police account, complete victim list, final audited loss, recovery total, or court outcome.
Sources
- BleepingComputer, July 7, 2025
- Reuters via UOL Economia, July 2, 2025
- Associated Press, July 4, 2025
- UOL Tilt, July 4, 2025
- LACNIC / Apura Cyber Intelligence, August 2025
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




