Skip to content

Scale Computing Launches SysAdmin Appreciation Initiative to Celebrate IT’s Heroes

Company Rings in 26th National System Administrator Appreciation Day With Gift Giveaway

INDIANAPOLIS — July 11, 2025 Scale Computing, the market leader in edge computing, virtualization, and hyperconverged solutions, today announced a special promotion in celebration of the 26th annual System Administrator Appreciation Day on July 25, 2025. Through August 8th, Scale Computing is recognizing the tireless efforts of System Administrators (SysAdmins) by offering a complimentary “Future-Proof” kit to those who register for the promotion. The giveaway includes a custom hat, an Owala Freesip water bottle, and a Bellroy Melbourne Backpack, as well as complimentary access to the Gartner® report, A Guide to Choosing a VMware Alternative in the Wake of Broadcom Acquisition.

Today’s rapidly evolving IT landscape presents both unprecedented opportunities and complex challenges. As cloud computing, edge deployments, and artificial intelligence continue pushing technological boundaries, system administrators find themselves at the epicenter of transformation, managing increasingly sophisticated environments while meeting rising demands for uptime, security, and scalability.

“SysAdmins are the unsung heroes keeping our digital world running, working tirelessly behind the scenes to prevent disruptions and safeguard our IT environments,” said Jeff Ready, CEO and co-founder of Scale Computing. “Their dedication, often after hours and on weekends, ensures organizations remain resilient and future-ready. This System Administrator Appreciation Day, we’re not just tipping our hats to them—we’re literally giving them our hats, along with our backpacks, water bottles, and actionable insights from Gartner to support their vital work.”

Scale Computing Platform (SC//Platform) mirrors the qualities that make SysAdmins exceptional: versatility, innovation, and unwavering performance. The purpose-built Hyperconverged Infrastructure (HCI) solution seamlessly integrates compute, storage, and virtualization, eliminating the complexity of traditional legacy stacks. A future-ready solution, the platform’s integrated autonomous management, decentralized AI processing, and AI-driven optimization capabilities simplify the complexities of Edge AI adoption as more enterprises move to agentic AI-driven operations. With high availability and built-in self-healing capabilities, SC//Platform significantly reduces downtime—a key reason Gartner recognizes Scale Computing as a Sample Vendor for HCI in its comprehensive guide to VMware alternatives.

In honor of this year’s System Administrator Day, Scale Computing invites SysAdmins to schedule a brief meeting and receive a custom quote to claim their free “Future-Proof” kit and complimentary access to the Gartner® report A Guide to Choosing a VMware Alternative in the Wake of Broadcom Acquisition.

For full details and to register for the limited-time promotion, visit scalecomputing.com/landing-pages/sysadmin-day.

Gartner, A Guide to Choosing a VMware Alternative in the Wake of Broadcom Acquisition, By Julia Palmer, Jeffrey Hewitt, Mike Cisek, 18 March 2025

GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved.

Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

 

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Scale Computing 
Scale Computing is a leader in edge computing, virtualization, and hyperconverged solutions. Scale Computing HC3 software eliminates the need for traditional virtualization software, disaster recovery software, servers, and shared storage, replacing these with a fully integrated, highly available system for running applications. Using patented HyperCore™ technology, the HC3 self-healing platform automatically identifies, mitigates, and corrects infrastructure problems in real-time, enabling applications to achieve maximum uptime. When ease-of-use, high availability, and TCO matter, Scale Computing HC3 is the ideal infrastructure platform. Read what our customers have to say on Gartner Peer Insights, Spiceworks, TechValidate and TrustRadius.

Reaching peak performance: The ultimate guide to Mac optimization

Sluggish system performance? Running out of storage space? It’s frustrating when a device doesn’t run as expected, particularly when the device in question is your beloved Mac.

The good news is that it can be simple to get your Mac to achieve its peak performance—and the solution might be closer than you think.

Let’s explore methods for optimizing your Mac in a range of different ways—from improving performance to reducing storage bloat and everything in between.

Did you know? Parallels Desktop is designed to run Windows and other OSs in virtual machines on Mac but that’s not the only benefit—Parallels Toolbox (included with Parallels Desktop Pro) can improve your Mac’s performance even more. Get your free trial of Parallels Desktop today!

5 ways to optimize your Mac’s memory (RAM)

Your Mac’s random access memory (RAM) affects its ability to multitask and handle software requirements. When it’s overloaded, you’ll see issues with loading times, slower multitasking, and lag.

If you’re encountering RAM issues on your Mac—or if you’re looking to avoid them proactively—try these tips.

1. Monitor your memory usage

Your Mac’s Activity Monitor (found in Applications > Utilities > Activity Monitor) can help you identify any apps that might be consuming too much memory and bogging down your device.

2. Quit unnecessary apps or processes

Along with memory-hogging apps, your Mac may have background processes or programs running that don’t need to be open. Use your Mac’s Activity Monitor to find and close them down.

3. Assign resources for your Mac and virtual machine

One of the neat things Parallels Desktop can do when you’re running a virtual machine (VM) on your Mac is assign resource usage.

Before startup, Parallels Desktop will check your system to see how many resources like RAM it can reasonably assign.

You can check on your assigned resources by opening your VM’s configuration menu and then going to Hardware > CPU & Memory.

In that menu, you can choose to leave your settings at default or use the allocation slider to specify resources like RAM manually and control your virtual machine optimization on Mac.

4. Consider a RAM upgrade

If your Mac often struggles with the same programs and issues, consider upgrading its RAM. Macs do allow you to do this, and it can help improve performance.

Heads up: You can learn more about troubleshooting and hardware improvements for your Mac on our knowledge base.

5. Use Parallels Toolbox to free up memory

Parallels Toolbox is included with the purchase of Parallels Desktop Pro. It offers over 50 tools that give you quick access to hidden, difficult-to-remember, or nonexistent functions on your Mac and your Windows VM.

One of these resources is the Free Memory tool, which helps you reclaim inactive RAM and improve your system’s responsiveness.

Tips and tricks for disk space management on your Mac

Much like a room that’s too cluttered to move around in, an overloaded storage drive can prevent your Mac from being able to do its best work.

When your Mac is struggling with clutter like random files, duplicates, and unnecessary downloads, try these tips to keep it under control.

1. Use your storage management tool

Macs come with a built-in storage management tool (found in Apple Menu > About This Mac > Storage > Storage Settings). This tool helps you clean up large files quickly and effectively.

2. Tidy your folders regularly

Your Downloads and Desktop folders can both become full quickly. Make sure you clean them out regularly to keep your Mac clutter-free.

3. Use the Clean Drive tool in Parallels Toolbox to clear space

Another popular utility in Parallels Toolbox is the Clean Drive tool, which scans your device to locate and clean up free space on your Mac, including running temporary file cleanup. You can learn more about how the Clean Drive tool works in our knowledge base.

You can also try out the Find Duplicates tool in Parallels Toolbox, which does something similar but specifically looks for duplicate files.

4. Uninstall any unused apps

Apps and programs can take up a surprising amount of space. If you have any you haven’t used in a while—or won’t need to use in the near future—consider uninstalling them to save space.

5. Archive your large files externally

Have big files that don’t need to live on your Mac’s internal drive? Archiving them to an external hard drive frees up internal space while keeping those files handy for when you need them.

6. Let your Mac optimize its own storage

Macs have a built-in storage optimization feature that can help you keep clutter under control. By turning on Optimize Storage (found in Apple Menu > About This Mac > Storage > Storage Settings), you can let macOS automatically remove unnecessary files.

How to optimize your Mac’s battery

Looking to extend your Mac’s battery life? Try these battery optimization tips to improve your Mac device’s performance.

1. Monitor your apps’ power usage

Your Mac’s Activity Monitor can help you identify and manage apps that consume too much energy.

2. Switch out power-hungry apps

If you do find apps using too much power, try replacing them with more energy-efficient alternatives.

3. Use Parallels Toolbox’s Energy Saver tool to save energy

Parallels Toolbox includes an Energy Saver tool that can help you extend battery life and simplify battery management for your Mac.

4. Adjust any battery-heavy system settings

Some Mac settings—like display brightness, keyboard backlight, and even some visual effects and animations—can drain your battery faster. Adjusting them can extend your battery life.

5. Switch to the Safari browser

Safari is specially designed to use less power on Macs, so using it instead of other browsers can help your battery last longer. Don’t forget to do some cache cleanup every now and then, too, to keep your browser light.

6 tips and tricks for network optimization on Mac

Your network is as much a part of your experience as your device is. If you’re running into issues loading web-based pages and resources, it could mean you’re experiencing network issues.

To tune up your network, try these tips.

1. Keep your router’s firmware updated

If your Mac is struggling with the network, the problem isn’t always your Mac. Making sure your Wi-Fi router’s firmware is up to date keeps your network in good shape.

2. Use the right Wi-Fi channels

The Wi-Fi channel you use can impact network performance. For example, while a 5-GHz channel will have higher speeds than a 2.4-GHz channel, it has a shorter range—so if you’re too far from a router or pod, you’ll need to switch channels.

3. Use Parallels Toolbox’s Network Usage tool to monitor networks

Parallels Toolbox has a handy Network Usage tool to help you monitor your network usage and identify usage patterns and spikes.

4. Disconnect from your Wi-Fi

Not using your Wi-Fi right away? Disconnecting from it can save your battery and reduce security risks for your Mac.

5. Set up device prioritization

Most routers will allow you to define priority levels for devices connected to your network through your router interface. You can tell it to prioritize essential devices, which should improve bandwidth allocation.

6. Turn on content caching

Content caching is a nifty feature for macOS devices that stores copies of files you access frequently in a temporary storage area. This way, when you open those files, they load much more quickly.

Other ways to keep your Mac current and optimized

Hungry for more ways to keep your Mac in tip-top shape? We’ve got a few extra tips and tricks that may help out.

1. Stay ahead on your updates

Software updates often include fixes and tweaks to improve performance. Making sure you have the latest versions of your OS and apps can keep your Mac running smoothly—and as a bonus, it’s good for your device’s cybersecurity, too.

2. Monitor your CPU usage

Your Mac’s CPU is its brain, and when it’s operating at capacity, the rest of your processes will slow down.

If you’re running Windows or another OS in a VM, Parallels Desktop has a CPU usage monitor in the virtual machine’s window tray that tracks how much of your Mac’s power is being taken up by Windows processes and helps you shut down unnecessary ones.

3. Declutter your dock

Remove any unnecessary items from your dock and menu bar to clear up clutter and keep your device organized.

Maximize the potential of your Mac equipped with Parallels Desktop

With your Mac running at its best, there’s only one thing that can take its performance farther—the right tools. Make the most of your Mac’s potential with Parallels Desktop and enjoy the best of both the Mac and Windows worlds on one device.

Opt for Parallels Desktop Pro and you get Parallels Toolbox included with your purchase.

Start your free trial of Parallels Desktop today.

 

About Parallels 
Parallels® is a global leader in cross-platform solutions, enabling businesses and individuals to access and use the applications and files they need on any device or operating system. Parallels helps customers leverage the best technology available, whether it’s Windows, Linux, macOS, iOS, Android or the cloud.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

How to prevent cyber-attacks in healthcare: from Zero Trust to password management

Summary: Healthcare companies can effectively defend against cyber threats with solutions like encryption, VPNs, and multi-factor authentication.

In this day and age, when a cyber-attack happens roughly every 40 seconds, no industry is safe from threats. Every organization, regardless of what it does, faces some level of risk.

That said, some industries are targeted far more than others. Healthcare, unfortunately, is near the top of that list. First, let us explain why that’s the case. Later, we’ll discuss what healthcare facilities and institutions can do to better protect themselves against hacking attempts.

Why the healthcare industry is particularly vulnerable to cyber-attacks

The key reason why healthcare is often targeted by cybercriminals is that it deals with highly valuable data. To provide their services, healthcare companies must store and manage large volumes of electronic health records, sensitive patient information, and other confidential files. We’re talking ID documents, Social Security numbers, medical histories, insurance papers, and more. All of those, as you can guess, are highly sought after on the dark web.

And that’s only part of the problem. We also need to consider that many healthcare organizations still rely on outdated computer systems and legacy infrastructure. Yesterday’s technologies simply can’t keep up with today’s cybersecurity threats—and attackers know this all too well.

Add to that the growing number of connected devices used in hospitals and clinics—many of which lack proper security—and you get a large attack surface. In this scenario, every device creates a potential risk that cybercriminals can exploit to break into the system.

An infographic presenting the reasons why healthcare is often targeted by cybercriminals

The consequences of cyber-attacks for healthcare organizations

Let’s start with this: if sensitive data—personally identifying information, electronic health records, insurance details, and so on—gets leaked, the consequences can be far-reaching. For instance, attackers can use it to file fake insurance claims. They might also get prescription drugs illegally. In some cases, they could even blackmail patients or medical institutions to keep medical records private.

Of course, the impact of the breach on an organization can be profound. It can lead to severe financial losses and big damage to its reputation. Regular and potential customers may lose trust and run off to competitors.

And if you think incidents like this are probably rare, we hate to tell you otherwise. Cyber-attacks on healthcare companies have been on the rise over the last few years.

In 2024, the Department of Health and Human Services (HHS) reported that the average number of healthcare breaches was two per day. That’s millions of medical records compromised each year. This explains why healthcare organizations cannot afford to rely on half-measures when it comes to cybersecurity.

How to defend against cyber-attacks in healthcare

Just because the healthcare industry is a frequent target for cybercriminals doesn’t mean organizations in this sector should feel helpless. There are plenty of effective strategies and solutions available. If you’re part of this sector, here’s how you can improve your defenses:

Control who has access to electronic medical records

One way to boost healthcare cybersecurity is by adopting the Zero Trust model. Maybe you’ve heard the phrase “Never trust, always verify”—that’s what it’s all about. It means you double-check everyone’s identity every time they need to access sensitive resources, even if you’re 100% sure they work at your company. It may sound strict, but it’s one of the best methods to stop unauthorized access.

Also, just because someone is part of the team doesn’t mean they should have unlimited access to all sensitive information. You want to make sure people only access the apps and data they actually need, based on their role and responsibilities. That’s why it’s important to set up proper access permissions for each user in your organization.

Tools like Zero Trust Network Access (ZTNA) solutions can help you put this framework into practice. They let you set up proper identity checks and control access effectively, so employees only reach what they need for their work—and nothing more.

And one more thing. While focusing on digital access, remember to also control physical access to areas where servers and patient records are stored. Limiting this access helps prevent damage to equipment and data theft.

Divide your network into smaller parts

Speaking of controlling access to resources, you can take that concept further by breaking up your company’s network into smaller elements called “segments.” This process is called network segmentation. Basically, by using firewalls, gateways, and internet protocols, you create separate areas of the network for specific user groups to operate in—without giving them access to the other parts.

How does this help? For one, if a security incident occurs, it will be contained within that one particular segment. This means it won’t spread across the entire network. This not only helps you identify and resolve the issue faster but also protects the rest of your IT environment.

Use encryption to protect all patient records

When you encrypt sensitive information like medical research and patient records, you ensure that even if someone gets hold of this data, it will appear as a scrambled mess when they try to open it. All the information stays unreadable until the correct decryption key is provided.

Encryption is especially useful when you’re sharing sensitive information online, particularly between remote sites or workers. To keep data secure in transit, end-to-end encryption is often used. This means the data is encrypted right on the sender’s device and stays encrypted until it reaches the intended recipient, where it’s decrypted.

Because the data remains encrypted throughout its entire journey, even if someone intercepts it while it passes from point A to point B, they won’t be able to read or misuse it. Just remember that this protection requires using strong algorithms like AES-256 or XChaCha20 for encrypting your data—some weaker ones can still be cracked with modern hacking tools.

Get everyone to use only strong passwords

No matter how much you invest in healthcare cybersecurity, all that effort can go to waste if employees are using weak passwords. Verizon reports that web attacks happen mostly due to stolen credentials (77%) and easily guessable passwords (21%). That’s why it’s so important to make sure everyone on every team uses strong, hard-to-guess credentials.

To make this happen, you can use an advanced business password manager that allows you to enforce a strong password policy. Plus, it can help employees easily create, manage, and securely store strong passwords for all their work accounts. This way, they won’t have to struggle with coming up with long, random strings of characters or keep passwords written down in notebooks.

Add more protection layers to your online accounts

Considering how advanced threat actors’ methods have become for cracking passwords, one thing’s for sure—passwords alone might not be enough to keep work accounts safe. That’s why it’s important to add extra layers of security, like multi-factor authentication (MFA).

By implementing MFA, you require users to prove their identity with something beyond a password. This can be a code sent to their phone or a biometric scan. Access is granted only after that second step is verified. That way, even if someone does get hold of an employee’s password, they still won’t be able to break into their account.

Educate your employees

You can’t expect your team to follow security rules if you don’t explain why those rules exist in the first place.

That’s why investing in cybersecurity training is essential. In these sessions, the team should learn the basics of cyber threats and how to respond to attacks. For example, they should find out what a ransomware attack is, what types of information they can handle online, and what to do if they accidentally click on a phishing link.

By clearly explaining the threats, how they work, and how to avoid them, you greatly increase the chances that employees won’t make the human errors that can lead to security breaches. Also, if you need a knowledge base to refer to, you can check out our Cybersecurity Learning Centre. It covers everything from basic security frameworks to HIPAA compliance.

Update and monitor all software and devices regularly

Most of the software and hardware used in hospitals and clinics receive regular patches and updates, which are specifically designed to strengthen system and device security. With cyber-attacks becoming more and more sophisticated, staying on top of these updates is one of the simplest, most effective ways to protect mobile devices and improve IoT security.

Outdated software can create major vulnerabilities and weaken your device posture security. That’s why it’s so important not to skip updates, not even one. It might not seem urgent at the time, but missing that update could leave your systems exposed when you least expect it.

It’s also crucial that you continuously monitor all devices and platforms within your IT infrastructure. Why? To stay aware of everything connected to your company’s network, ensure each one complies with your security policies, and quickly identify any unusual behavior before it leads to potential vulnerabilities.

With NordLayer, you’re covered on key cybersecurity fronts

NordLayer is a toggle-ready network security platform that checks all the right boxes—especially for healthcare organizations looking to strengthen their defenses. In fact, it delivers on many of the key cybersecurity practices we’ve covered in this article.

For starters, it offers a cutting-edge Business VPN to ensure your team can safely access your network from anywhere. But that’s just the beginning. NordLayer also allows you to segment your network and control who can access what, while monitoring user activity. What’s more, it enables you to apply Zero Trust principles, so every user’s identity is checked before each login. It also helps maintain strong device posture security by allowing you to keep tabs on all devices in your network. Throw in multi-factor authentication, DNS filtering, malware prevention, and strong encryption, and you’ve got a tool built for serious protection.

Bottom line? NordLayer is designed to be an all-in-one solution for many of the cybersecurity challenges healthcare companies face. If you’re in the healthcare industry and want to learn more about our product, just contact our team. We’ll be happy to show you what NordLayer can do to protect your organization.

 

About NordLayer
NordLayer is an adaptive network access security solution for modern businesses – from the world’s most trusted cybersecurity brand, Nord Security.

The web has become a chaotic space where safety and trust have been compromised by cybercrime and data protection issues. Therefore, our team has a global mission to shape a more trusted and peaceful online future for people everywhere.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

ESET PROTECT Shines as a Leader! Proudly securing a second position in G2’s Summer 2025 Grid® Report for Extended Detection and Response (XDR) Platforms

The ESET PROTECT cybersecurity platform has been crowned a Leader in the prestigious G2 Summer 2025 Grid® Report for Extended Detection and Response (XDR) Platforms. This accolade stands as a testament to ESET PROTECT’s outstanding customer satisfaction, earning the highest score in this category, and its strong market presence.

ESET PROTECT outperformed XDR-first vendors like CrowdStrike and SentinelOne. An impressive 97% of users have rated it 4 or 5 stars, with 89% believing it’s on the right track. Furthermore, a remarkable 91% of users are likely to recommend ESET PROTECT to others.

In the Summer 2025 Grid® Report for XDR Platforms ESET PROTECT is rated #1 for Data Security, the highest-rated feature with a 99% rate, Data loss Prevention, Workflow Automation, and Governance. It has been awarded various unique badges in the XDR Platforms category, including “Most Implementable”, “Best Results” for mid-market, “Best Estimated ROI” and “Fastest Implementation” for enterprise, and more.

Users have praised ESET PROTECT for its outstanding ability to meet business requirements and its ease of platform setup and use. Dive into the full report to discover why ESET PROTECT is the go-to choice for businesses worldwide.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Cyberattack on Brazil’s Payment System: Technical Analysis, Timeline, Risks, and Mitigation

Executive Summary

This article presents a detailed analysis of one of the most severe cybersecurity incidents ever to impact Brazil’s Payment System (Sistema de Pagamentos Brasileiro – SPB), which occurred in June and July of 2025. The breach was directly linked to C&M Software, a major Information Technology Services Provider (PSTI) for the national banking sector. This incident exposed, for the first time at this scale, the critical role PSTIs play within the financial ecosystem, and how internal vulnerabilities can reverberate systemically, compromising the integrity of financial operations across hundreds of banks and institutions.

The Brazilian Financial System (Sistema Financeiro Nacional – SFN) serves as the infrastructure enabling the circulation of money, credit, and payments throughout the country. It involves the Central Bank, banks, fintechs, credit cooperatives, payment institutions, and specialized technology providers, such as PSTIs. Through the SPB and the Instant Payments System (SPI), the SFN ensures fast, secure, and traceable settlement of fund transfers between institutions, thereby upholding trust and maintaining market functionality.

This cyberattack was facilitated through the compromise of C&M Software’s internal IT environment. A malicious insider—an employee of the PSTI—was recruited by a cybercriminal group and, in exchange for financial compensation, granted privileged access to internal systems, passwords, and sensitive institutional certificates. That access allowed attackers to manipulate the credentials and private keys of several C&M clients, primarily banks and fintechs, including BMP Money Plus. From there, attackers generated fraudulent transactions, signed in proper compliance with SPI’s cryptographic and procedural standards, allowing them to be instantly settled by the Central Bank. As these operations were technically valid, they were automatically debited from the reserve accounts of the victim institutions.

Because C&M Software acted as a core technical hub for hundreds of institutions, the breach had a wide-reaching and magnified impact. Not only did BMP Money Plus suffer substantial financial losses, but at least five other institutions were also compromised. The siphoned funds were immediately funneled through accounts held by mules, then quickly transferred to cryptoasset exchanges for conversion into Bitcoin and USDT, effectively complicating their traceability and recovery.

Due to its central role, C&M was at the center of the response efforts: alerted by affected institutions, C&M notified the Central Bank, implemented emergency containment measures, and had its operations within the SPB suspended until robust new controls could be enforced. The incident underscores how shortcomings in governance, privilege management, and certificate protection can result in systemic consequences. This analysis underscores the necessity of key security measures, including behavioral monitoring, automated credential management, just-in-time access control, and strict separation of client secrets to prevent similar events within such a highly interconnected financial environment like the SFN.

1. Introduction

In a financial system built on trust and speed, a single insider can bring the entire network to a halt.

Over the last two decades, Brazil has emerged as a global reference in financial innovation and infrastructure modernization. Its Financial System (SFN) stands out for its level of digital maturity, robust regulatory framework, and ability to integrate multiple market actors, fostering inclusion, efficiency, and large-scale security. One of the latest milestones in this evolution is the Instant Payment System (SPI), which, in tandem with PIX, has positioned Brazil ahead of many global markets in terms of speed and ubiquity of electronic fund transfers.

PIX/SPI has become the financial backbone for transactions involving individuals, businesses, fintechs, and banks, processing billions of transfers with near-immediate settlement across accounts belonging to different institutions. This orchestration is made possible not just by the Central Bank but by a network of specialized providers—the Information Technology Services Providers (PSTIs)—who perform critical functions in clearing, settlement, and interconnection for traditional banks, credit unions, payment institutions, and digital platforms. The advent of open finance has further intensified reliance on these technical intermediaries, expanding both the number and diversity of participants and interfaces within Brazil’s digital financial ecosystem.

However, this growth also brings new and complex challenges. As digitalization progresses and integrations multiply, so too do points of exposure to cyber threats, fraud, governance failures, and supply chain vulnerabilities. With operations distributed across many players—often with unequal security maturity—an isolated breach has the potential to jeopardize the confidentiality, integrity, and systemic availability of services that individuals and businesses rely on daily. Additionally, given the growing use of APIs, outsourced operations, and the sharing of institutional secrets, new attack surfaces are created for insiders, cybercriminals, and advanced persistent threat (APT) actors.

The case examined in this article offers a stark exemplification of the risks and critical weak points in Brazil’s so-called “chain of trust.” By analyzing a real-life breach involving a central PSTI supporting banks and fintechs, we highlight the root causes, technical and institutional impacts, and practical recommendations to strengthen system resilience, privileged access management, and behavioral security controls within a complex and highly interconnected financial environment.

2. Understanding Brazil’s Financial System

The SFN operates via multiple interconnected components to ensure fast and secure interbank settlements. The Central Bank of Brazil (BACEN) serves as both the top regulator and operator of the Brazilian Payment System (SPB), which includes banks, payment institutions, technology providers (PSTIs), and cryptocurrency exchanges.

Reserve Accounts

A cornerstone of the SPB is the reserve account, maintained by each financial institution with the Central Bank. These accounts power SPI (Instant Payment System), enabling irreversible, real-time transaction settlements via PIX.

Banking-as-a-Service (BaaS)

BaaS platforms like BMP Money Plus enable fintechs, funds, and digital platforms to leverage full banking infrastructure, maintain reserve accounts, and facilitate payments through the SPB.

Role of Exchanges

Cryptocurrency exchanges such as SmartPay and Truther bridge traditional finance and the crypto world, playing an essential role in transaction traceability and regulatory compliance at scale.

Caption:The client initiates a purchase via SmartPay/Truther. BMP, using its BaaS model, processes the PIX transaction and routes it to the SPI/SPB via C&M Software (PSTI). The payment moves from BMP’s reserve account at BACEN to the recipient’s institution, with instant settlement. The process concludes with confirmation back to the client.

3. Incident Description

At 4:00 a.m. on June 30, 2025, a senior executive at BMP Money Plus—a fintech specializing in banking-as-a-service (BaaS) solutions—received an unexpected call from CorpX Bank, alerting him to an unauthorized transfer of R$18 million from BMP’s reserve account. As the person responsible for managing those reserves with the Central Bank, the executive quickly identified that other similarly unauthorized PIX transactions were actively underway at that moment. BMP’s internal team immediately launched containment efforts and, by around 5:00 a.m., officially reported the incident to C&M Software, their critical payment processing service provider.

Initial investigations and information published in the media indicated that the attack originated from an internal compromise at C&M Software—one of the leading PSTIs in Brazil’s Payment System (SPB). An internal facilitator, allegedly motivated by financial gain, provided privileged credentials to cybercriminals and assisted in executing malicious commands within company systems. Possessing privileged access and the digital certificates of C&M’s financial institution clients—including BMP itself and at least five other institutions—the attackers were able to inject fraudulent PIX orders directly into the SPI/SPB infrastructure. Because the transactions were digitally signed using valid institutional certificates, the Central Bank’s core systems processed them as legitimate, immediately debiting funds from the reserve accounts of the victim institutions.

It is estimated that approximately R$400 million was siphoned from BMP’s reserve account alone, with R$160 million later successfully recovered. Following the breach, stolen funds were swiftly transferred to accounts held by third parties at smaller banks and payment institutions, particularly cryptoasset platforms integrated with PIX, including exchanges, gateways, and swap platforms. Most of the stolen funds were quickly converted into USDT or Bitcoin, further complicating traceability. However, in at least one case, an exchange that detected a high volume of suspicious activity froze the settlement and immediately notified BMP, thereby preventing the dispersion of a portion of the stolen funds.

Given the magnitude of the attack and in order to prevent further losses, the Central Bank ordered an emergency suspension of C&M Software’s systems from the SPB—affecting PIX operations across more than 300 financial institutions that relied on its services. Despite the substantial financial damage, BMP Money Plus publicly emphasized that no end-customer funds were affected and that institutional guarantees fully covered the stolen amounts. Meanwhile, the Federal Police, activated by the Central Bank, opened a formal investigation to examine potential crimes such as criminal conspiracy, fraud-related theft, unauthorized system intrusion, and money laundering. The case remains under active investigation.

4. Incident Timeline

Below is the timeline of key events related to the incident—from initial compromise to response—based on information available at the time.

  • June 30, 2025 – 12:18 AM: Exchanges such as SmartPay and Truther detect unusually high transaction volumes in Bitcoin/USDT and alert executives at financial institutions.
  • June 30, 2025 – 4:00 AM: A BMP Money Plus executive is informed of an unusual PIX transfer totaling R$18 million; multiple unauthorized transactions are identified.
  • June 30, 2025 – 5:00 AM: BMP executives report the incident to C&M Software.
  • June 30, 2025: The Central Bank orders the emergency disconnection of C&M Software from the SPB.
  • July 1, 2025: News portal Brazil Journal publishes an in-depth report on the cyberattack.
  • July 2, 2025: BMP Money Plus issues an official statement acknowledging the breach.
  • July 3, 2025: The Central Bank announces the partial restoration of C&M Software’s operations and confirms the arrest of an employee involved in the incident.
  • July 4, 2025: Authorities confirm the detention of a staff member suspected of aiding the cybercriminal operation.

5. Technical Analysis of the Incident

The incident that unfolded between June 29 and July 4, 2025, may represent one of the largest systemic frauds ever recorded within Brazil’s Payment System (SPB), involving a wide range of actors—from external cybercriminals and internal insiders to financial institutions, technology service providers, and regulatory authorities. Below is a technical, chronological breakdown of the attack’s modus operandi, the mechanisms exploited, the money flow, and institutional responses.

1. Initial Compromise: Insider Threat and Privilege Escalation

The first step in the incident was an internal compromise at C&M Software, an authorized and mission-critical Information Technology Services Provider (PSTI) within Brazil’s financial ecosystem. According to official investigations and media reports, an employee at C&M—referred to here as the “Facilitator”—was recruited by a cybercriminal group. Motivated by financial incentives, the insider shared administrative credentials and, following external instructions, executed strategic commands that enabled the attackers to operate undetected within the company’s internal environment.

This privileged access was essential. It allowed the attackers to discover and retrieve cryptographic keys and digital certificates belonging to C&M’s client institutions, enabling the group to digitally impersonate those financial institutions. In many financial environments, inadequate segregation of secrets management (keys, certificates, and credentials) between clients and tech providers makes these attacks exponentially more dangerous.

2. Injection of Fraudulent Orders and Automated Settlement

Once in possession of the original digital credentials and certificates belonging to compromised institutions—particularly BMP Money Plus and at least five others—the attackers began fabricating and injecting PIX payment orders directly into SPI (Instant Payment System) and SPB. Since the digital signatures were valid and the requests followed standard cryptographic formats, the Central Bank’s settlement infrastructure processed and executed them as legitimate. The SPI system, by design, presumes the authenticity of requests from verified participants.

During the night of June 29 to June 30, these operations were carried out in bulk, automated fashion, outside of business hours—when manual oversight tends to be minimal. The reserve accounts of the victim institutions—held with the Central Bank for interbank operations—were systematically debited without triggering any SPI anomalies.

3. Rapid Dispersion and Chain Effect

The next step involved the immediate dispersion of stolen funds. Large amounts—often sent in batches—were moved to “mule accounts” and smaller payment institutions (PIs), many of which featured less stringent KYC, onboarding, and compliance protocols. Funds were then transferred to cryptoasset service providers such as exchanges, OTC platforms, and swap apps. There, they were converted into Bitcoin and USDT and moved to wallets held by the attackers—often split into many small transactions to evade tracing.

This sequence underscores the attackers’ operational sophistication:

  • Exploiting supply chain links between the PSTI (C&M) and multiple banks/fintechs;
  • Leveraging scripts and automation to submit dozens of transactions in succession;
  • Executing the fraud during off-peak operational hours.

4. Timeline of Actions, Detection, and Response

🕛 June 30, 2025 – 12:18 AM: Initial Detection by Exchanges
SmartPay and Truther exchanges were the first to detect suspicious activity. Their monitoring systems flagged abnormal transaction volumes and unusual purchases of Bitcoin/USDT made via PIX, triggering alerts to internal compliance teams and associated financial institutions.

🕓 June 30, 2025 – 4:00 AM: BMP Executives Flag the Incident
Prompted by exchange alerts and transaction analysis, a BMP Money Plus executive was contacted by a CorpX Bank representative regarding an extraordinary PIX transfer of R$18 million originating from BMP. This kicked off an internal audit that revealed several unauthorized SPI transactions debiting BMP’s reserve account.

🕔 June 30, 2025 – 5:00 AM: Incident Escalation
BMP formally notified C&M Software, reporting the breach and requesting urgent assistance from the provider responsible for part of the institution’s interbank infrastructure. By this point, the breadth of the attack suggested a systemic compromise affecting multiple C&M clients.

⚠️ June 30, 2025: Regulatory Response — Central Bank Intervention
With converging reports from exchanges, BMP, and other affected financial institutions, the Central Bank was officially notified of a potential systemic breach. As an emergency measure, it ordered the precautionary suspension of C&M Software’s connections to SPB—halting PIX operations across all institutions that interfaced through its platform. This action aimed to prevent further fraud and maintain system liquidity, despite triggering operational interruptions for hundreds of banks, fintechs, and payment entities.

📰 From July 1, 2025 Onward: Public Disclosure, Analysis, and Partial Recovery
In the days that followed, national media widely covered the breach, and official statements from BMP, C&M Software, and the Central Bank confirmed that no end-user funds had been affected. BMP reported that, of the R$400 million initially stolen, approximately R$160 million had been recovered through rapid collaboration with crypto exchanges, court orders, and financial tracing efforts.

Later, the Central Bank authorized the partial reactivation of C&M’s services—only after new control mechanisms and stricter access segregation were implemented. Amid the ongoing investigation, authorities confirmed the identification and arrest of the “facilitator”, the insider who enabled the breach. The Federal Police continues to investigate charges related to unauthorized access, banking fraud, and money laundering.

5. Operational Roles Across the Attack Chain

  • Cybercriminals: Strategized and executed the attack, exploiting both human and technical vulnerabilities. Used automation to scale operations and reduce execution time.
  • Insider (Facilitator): Served as the human vulnerability, granting “legitimate” access to core systems. Illustrates the danger of excessive privilege and lack of behavioral monitoring.
  • C&M Software (PSTI): Due to the absence of strong access segregation and behavioral controls, acted as the point of compromise that exposed its entire client base.
  • Victim FIs: Banks and fintechs whose reserve accounts were debited, suffering direct financial loss and reputational impact.
  • SPI/SPB: The infrastructure processed all digitally signed payment orders as expected—highlighting the limitations of automated controls against insider-originated attacks.
  • Mule Accounts / Payment Institutions (PIs): Weak onboarding and due diligence processes made them attractive channels for laundering and dispersing stolen funds.
  • Exchanges: A key positive aspect—proactive exchange-based compliance systems successfully detected, contained, and reported portions of the fraud, helping reduce total impact.

Below, you’ll find a step-by-step visualization of the incident flow:

6. MITRE ATT&CK Mapping

The attack on C&M Software’s environment demonstrates a well-defined chain of techniques documented in the MITRE ATT&CK Framework (Enterprise v17). Mapping these techniques supports threat hunting, incident response, and the enhancement of internal security controls across financial institutions and PSTI providers.

Below, we highlight the main tactics and techniques involved, referencing specific examples from the 2025 incident.

7. APT Groups: Exploratory Assessment

It is important to highlight that, as of now, none of the groups listed below have any confirmed connection to the attack under investigation. These references are intended primarily to inform threat intelligence efforts and assist in shaping strategic defense planning.

Although there has been no formal attribution to any internationally recognized Advanced Persistent Threat (APT) groups, the technical analysis of the attack on C&M Software reveals multiple operational similarities with campaigns previously carried out by sophisticated threat actors. These actors vary in motivation, technical breadth, and focus—often targeting critical financial infrastructures.

The purpose of this mapping is to help place the Brazilian incident within the context of global cyber threat trends, supporting the early identification of attack patterns and contributing to more proactive and intelligence-driven defense strategies.

The groups outlined below demonstrate common Tactics, Techniques, and Procedures (TTPs) seen in supply chain compromises, banking intrusions, ransomware campaigns, and money-laundering-driven data exfiltration:

Notable Examples

  • Plump Spider – Known for leveraging the Clop ransomware, this group has been involved in systemic attacks on global financial institutions. Its operations often combine supply chain compromise, large-scale data and confidential information exfiltration, and laundering of proceeds via cryptoasset mixer services.
  • TA505 – Specializes in malspam-driven campaigns, frequent use of Cobalt Strike for post-exploitation, and targeted attacks on banks and fintechs. Notable for its ability to rapidly convert and disperse illicit funds.
  • FIN7 / Carbanak – With an established reputation for social engineering and persistent access to banking environments, FIN7 is known for extended campaigns that leverage legitimate infrastructure and internal credentials to facilitate stealthy data exfiltration and fund diversion.
  • LAPSUS$ – Gained notoriety for its highly visible and theatrical attacks on major enterprises, with a particular focus on social engineering, privileged access acquisition, and the public exposure of stolen data. While the group is not a direct fit for this incident, which centers on financial operations, some alignment remains in terms of initial access and insider exploitation tactics.

8. Mitigation Strategies

Given the context and the vulnerabilities exposed by the incident, we propose a set of mitigation measures focused on behavioral security, automated credential management, and strong governance across the digital supply chain:

  • Behavioral Analytics: Real-time detection of anomalous privileged access; automatic blocking based on deviation patterns, with correlation by geolocation, time of access, and other indicators.
  • Just-in-Time Access: Grant privileged access strictly for specific tasks or timeframes, thereby reducing exposure windows to insider threats.
  • Credential Rotation (triggered by anomalous behavior): Credentials are automatically refreshed or revoked upon detection of any suspicious activity.
  • Secrets and Token Management for APIs and Supply Chain: Deployment of secure vaulting tools to safely isolate and manage third-party integrations and secrets.
  • Certificate Management and Rotation: Continuous monitoring and automated renewal of digital certificates used in critical financial operations.
  • Third-Party Access Control: Implementation of Zero Trust policies for partners, with strict onboarding and offboarding processes.

Reference Architecture: A recommended visual design illustrating an integrated security model for PSTIs, financial institutions, and the Central Bank (suggested as a flowchart or architecture diagram).

9. Conclusion

The attack that impacted C&M Software and multiple institutions connected to Brazil’s Payment System (SPB) underscores the critical role of behavioral cybersecurity and credential control in safeguarding financial ecosystems. This event exposed significant weaknesses in privileged access management, particularly within trust relationships between financial institutions and their technology service providers. It clearly demonstrates that traditional paradigms—relying solely on logical perimeters, firewalls, and network segmentation—are insufficient to defend against insider threats, supply chain compromise, and sophisticated attacks enabled by the misuse of valid credentials and seemingly legitimate but unauthorized operations.

The incident revealed that insider actions, improper certificate usage, and the absence of behavioral monitoring allowed fraudulent activity to flow through automated systems without triggering alarms across various points in the chain. Additionally, it reinforced the importance of traceability, real-time threat intelligence, and collaborative defense among key ecosystem players including fintechs, banks, exchanges, and regulatory bodies.

From the lessons learned, the following mitigation strategies stand out:

  • Continuous Behavioral Analytics: Monitor privileged user behavior in real time, generating alerts and automated blocks when anomalies are detected—such as unusual access times, organizational changes, or abnormal geolocation data.
  • Just-in-Time Access & Least Privilege: Minimize the time during which sensitive credentials remain active. Grant access strictly for specific tasks and timeframes, with comprehensive logging and traceability.
  • Credential Rotation Triggered by Anomalies: Implement mechanisms for the automatic replacement of passwords, tokens, and certificates whenever suspicious behavior is detected—preventing persistence or reuse of compromised access.
  • Secure Management of Secrets, Tokens, and Digital Certificates: Centralize the lifecycle control, usage auditing, and periodic renewal of these assets—especially across integrations between financial institutions, PSTIs, and APIs—to mitigate leakage and misuse risks.
  • Zero Trust Policies and Tight Third-Party Controls: Define robust procedures for granting, monitoring, and revoking access to partners, vendors, and external teams. Ensure consistent due diligence and oversight.

Ultimately, the case highlights that operational resilience, rapid intelligence sharing, transparent communication, and the integration of technical and procedural controls are foundational pillars for the systemic defense of the national financial environment in the face of evolving and sophisticated threats.

Speak to Our Experts
To learn how Segura® can support your organization in behavioral cybersecurity, privileged access management, and fraud-resistant architecture, contact us for a personalized strategic assessment.

 

About Segura®
Segura® strive to ensure the sovereignty of companies over actions and privileged information. To this end, we work against data theft through traceability of administrator actions on networks, servers, databases and a multitude of devices. In addition, we pursue compliance with auditing requirements and the most demanding standards, including PCI DSS, Sarbanes-Oxley, ISO 27001 and HIPAA.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.