PLUMP SPIDER Makes the Bank Rob Itself
most financial ecrime is theft. steal the card, steal the login, sell it, move on. plump spider does something a bit more sophisticated. they do not steal the money. they get inside the bank's own software and tell it to move the money for them.
plump spider is a brazil-based ecrime threat actor, active since 2023, and their specialty is genuinely different. they compromise the payment systems and banking software themselves, then create fraudulent transfers in the name of a legitimate company with real funds sitting in real accounts.
that is way worse than a normal breach. a stolen credit card gets flagged and cancelled. a fraudulent transfer originating from inside the bank's own trusted software, in the name of a real customer, through the real payment rails, looks legitimate to every anti-fraud system watching. the attack is not merely disguised to resemble a real transaction. it is pushed through the real payment infrastructure as one. it just was not authorized by the person whose name is on it.
they target brazil's payment infrastructure, including pix, str, and boleto, and the numbers show how fast this moves. in one documented intrusion, within 24 to 48 hours of reaching the core financial applications, plump spider fired off two waves of hundreds of fraudulent transactions. hundreds, fast, before the window closed.
and they do their homework. this is not a spray-and-pray operation. before they move money, they study each victim's transfer procedures, their anti-fraud controls, their fintech integrations, their approval workflows. they learn how the bank works so their fraud looks like business as usual. in one operation, they walked rogue hardware straight into a retail store's network and plugged it in to establish a foothold.
how do they get in. the usual boring doors, which is the point. password spraying. voice phishing where they call pretending to be it support and talk someone into installing remote-access software. old vulnerable servers left exposed. and the one that should worry every security team, they try to recruit insiders. they do not always break in. sometimes they just hire someone who is already inside.
this is more than a mere ecrime story relegated solely to brazil. google tracks overlapping activity as breeze comet, and that activity has also reused compromised municipal domains in nigeria, paraguay, ghana, and venezuela, suggesting the playbook may be expanding beyond brazil. this is not a group winding down operations. that is a playbook being packed up for export. the technique is not tied to brazil. it is tied to any country running fast, modern, instant-payment systems. this is increasingly everywhere.
we spent years teaching people that fraud looks suspicious. a weird charge, a foreign login, a phishing email. plump spider's whole model is fraud that looks completely normal, because it runs through the real system, in a real name, on the real rails. the money does not get stolen out of the vault. the bank is convinced to hand it over, and the request comes from a voice the bank already trusts, its own software.
it is much harder to flag a transaction when the trusted system itself appears to have authorized it. that is the whole problem, and it is the direction financial crime is heading.