Skip to content

Incidents in country:

Brazil

3 incidents catalogued

Social engineeringContained

C&M Software Pix heist (Brazil, 2025)

A junior developer at C&M Software β€” a Central Bank-authorized provider of Pix instant-payment connectivity β€” was paid roughly R$5,000 to hand over credentials. Attackers used the access to drain approximately R$800 million ($148 million) from reserve accounts at six Brazilian financial institutions in 2.5 hours.

Victim
C&M Software (Pix payment infrastructure provider)
Loss
$148.0M