Filipi Pires’ Post

🚨 The Inside Job That Shook Brazil's Financial System 🇧🇷💥 One of the most devastating cyberattacks in Brazil’s history hit the Brazil's Payment System (SPB) and it wasn’t just technical. It was INSIDER-LED. A trusted employee at C&M Software, a key provider in the banking infrastructure, sold access to attackers. With stolen credentials and digital certificates, they executed valid transactions that drained hundreds of millions — instantly and silently. These fraudulent transfers were cryptographically sound and cleared through the Central Bank as if nothing was wrong. This wasn’t just an attack on one company. It was a systemic shock to the financial backbone of Brazil and at least 6 institutions were compromised. Funds were laundered through mule accounts and converted to Bitcoin/USDT gone in seconds. Learnings: 🔸 Lack of behavioral monitoring 🔸 Poor privilege control 🔸 Insecure certificate governance 🔸 No just-in-time access 🔸 No isolation between client secrets In 2025, Identity and Access are not just security concerns they’re the first attack vector. Dive deep into how Identity Threat Labs by Segura investigated it, how this happened and what must change NOW: 👉 https://lnkd.in/df6vtTqw 💥 Let’s start a conversation: What’s your biggest concern when it comes to insider threats? Drop your thoughts below 👇 #segura #identity #identitythreatlabs #Cybersecurity #InsiderThreats #SPB #RedTeam #CISO #Governance #PSTI #DigitalTrust #FintechSecurity #ZeroTrust #CryptoLaundering #BrazilCyber #SPI #PrivilegeAbuse #SecurityByDesign #IdentityIsTheNewPerimeter #SeguraSecurity #ThreatIntelligence #CyberAttack2025 #CodeRed

  • timeline

Filipi. Congratulations on this analysis. This was the biggest Brazilian cybersecurity incident. Great to see Segura working around it

Congratulations for the research! 🚀 🎉

great breakdown, thank you!

See more comments

To view or add a comment, sign in

Explore content categories