C&M Software Pix heist (Brazil, 2025)
A junior developer at C&M Software — a Central Bank-authorized provider of Pix instant-payment connectivity — was paid roughly R$5,000 to hand over credentials. Attackers used the access to drain approximately R$800 million ($148 million) from reserve accounts at six Brazilian financial institutions in 2.5 hours.
- Victim
- C&M Software (Pix payment infrastructure provider)
- Loss
- $148.0M