MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Compromise of CM SOFTWARE enables massive PIX fund diversion in Brazil

On 30/06/2025, Brazilian provider CM SOFTWARE was compromised, enabling unauthorized access to reserve accounts of at least six institutions via the PIX infrastructure and diversion of funds estimated at BRL 800 million (~USD 148M). The Central Bank ordered the provider’s immediate disconnection, degrading services and disrupting operations for connected institutions.

88

Estimated severity

88 / 100

84

Source reliability

84 / 100

Approximate Date

30/06/2025

Targeted Company

CM SOFTWARE

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

Brazil

BRA

Other Affected Countries

No other affected countries reported

Target country

Brazil

Affected countries

Brazil

Impacted regions

South America · Brazil

Operational Impact

Duration

No information

Financial impact (USD M)

$148M

Impact types

Operational disruptionService degradationDownstream customer disruptionSupply chain coordination disruption

Affected sectors

Finance & Insurance

Affected departments

Information Technology

Attack Profile

Attack types

Unauthorized access

Attributed threat actors

No information

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.