Article Details
Understand how the PF has reached hackers suspected of attacks on the national financial system
Published on September 15, 2025
A- A+
Investigation Understand how the PF reached hackers suspected of attacks on the national financial system eight suspects were arrested in Sao Paulo last Friday
The operation of the Federal Police that arrested eight suspects of hacker attacks on the national financial system last Friday, it was possible after the targets monitor the targets and start a "controlled action", a type of investigation technique that allows postponement to obtain more evidence, identify crime participants and achieve more effective action.
The operation was adopted after a complaint made by the Caixa Econômica Federal Comptroller and the interception of messages and videos of criminals bragging about accessing the Pix system.
The agents identified the group after receiving a statement from Caixa last Thursday that two suspects would bring a Credential Machine and external access to the VPN (Virtual Private Network) from the manager of a São Paulo downtown agency.
In a controlled action, the agents followed the movement of the targets and the transportation of the notebook through the streets of São Paulo towards a house in the east of the capital - where other hackers were gathered.
In this place, the PF made the arrest in the act of those involved.In testimony, most of them denied involvement with cyber attacks and said they were there for a party.Investigators seized twelve cell phones, a notebook and a USB stick.
In intercepted messages, the PF identified the performance of hackers who communicated through codenames such as "Sethh 7", "RBS" and "BA".Among them, according to the researchers, was one of the responsible "for the construction and feasibility of the means of access to the Pix system," according to the PF report.He would have introduced structural vulnerabilities into the system to make new attacks viable.
The agents also found a video in which a suspect boast of having "the password that spins the pix".
In addition, the PF detected involvement in the scheme of "mateiros, assigned as responsible for the allocation of the amounts to be subtracted", according to the document.To make it difficult to track the stolen money, much of the amount was converted into cryptocurrency and transferred abroad through small fintechs.
The Federal Court of São Paulo converted the arrest in the act of preventive last Saturday based on the findings of the Federal Police.
"Firstly, as mentioned in the videos, the identified persons would have access to the Caixa Econômica Federal passwords, and that there would only be the need for access to VPN. Secondly, as indicated in the videos, there is the involvement of a person who allegedly participated in the construction of the instant payment arrangement. Thirdly, it is actually repeated, and the reported fraud," says the report, "PF, which concludes:
"In short, it is a criminal organization, which has been subtracting funds from the instant payment arrangement, with improper access to PI accounts, maintained by financial institutions in the Central Bank."
According to the document some criminals arrested last Friday are suspected of being involved in hacker attacks on Sinqia and C&M, companies that connect banks to the Pix system and have been targeted by invasions in recent months.The actions would have resulted in the alleged diversion of about R $ 1.5 billion through these institutions.
In a statement, the PF reported that the suspects will be responsible for the crimes of "criminal organization and attempted qualified theft by electronic means" and that investigations continue to identify "others involved."The findings are conducted under confidential by the PF.
See also