Summary
- C & M Software Ltda. is the same Brazilian legal entity, CNPJ 03.215.009/0001-08, that received a documented PSTI authorisation in 2020 and that the Banco Central do Brasil now lists as 'in orderly wind-down' under its post-2025 certification regime.
- The July 2025 incident did not bring down Pix's central settlement engine, but it showed how one access provider can become a concentrated control surface for multiple institutions' messages, credentials, fraud settings, support decisions and migration options.
- C&M states that the attack began with social engineering and misuse of valid credentials rather than a flaw in its software. This distinction does not settle the harder control question: whether privileged access, transaction integrity controls, anomaly detection and client–provider segregation were strong enough as a combined system.
- Brazil's revised PSTI rules make the buyer a continuous supervisor, not a passive client. Institutions must retain private signing keys, validate transactions before signing, monitor the provider and be able to execute an orderly change without carrying old trust into a new environment.
- Public evidence does not disclose why C&M is in the orderly wind-down category, when that process will end, the final consolidated loss from the 2025 fraud, or the outcome of the independent review the company says it commissioned. These are material gaps, not invitations to guess.
The payment rail that acquired office hours
For a brief period in July 2025, the most telling fact about C & M Software was a schedule. Pix is designed for continuous use, but operations connected through C&M could only resume on working days between 6:30 am and 6:30 pm. Each participating institution had to give express consent, fraud monitoring had to be strengthened, and transaction limits had to be enforced. The Banco Central do Brasil, or BCB, had first ordered institutions to disconnect from the infrastructure operated by C&M; it later replaced the precautionary suspension with a partial suspension after mitigation measures.Reuters reported the terms of this controlled return, whileFolha de S.Paulo described the regulator’s enhanced oversight.
This twelve-hour window was not merely an outage statistic. It made visible a layer that ordinarily disappears behind the Pix brand. The BCB operates the Sistema de Pagamentos Instantâneos, or SPI, as Brazil’s single central infrastructure for instant inter‑institution payment settlement. It processes each instruction individually in real time; once settled, a transfer is final and irrevocable. Direct entities settle via dedicated PI accounts at the central bank, without overdrafts. These arethe BCB’s own descriptions of the SPI. Yet not every institution builds and operates every connection, messaging interface, operations console, fraud rule and support process itself. A Provedor de Serviços de Tecnologia da Informação, or PSTI, may process data for access to the Rede do Sistema Financeiro Nacional, the RSFN.
C&M occupied that seam. It was neither Pix nor the central bank and, as the BCB stressed after the attack, not a contractor of the central bank. It sold technology to institutions that needed a pathway into the regulated payment infrastructure. This distinction matters. The central SPI could remain available while a group of connected institutions lost or had restricted their path to it. Customer balances could stay intact while money belonging to financial institutions was allegedly moved from settlement accounts. An attack could exploit apparently legitimate authority rather than break the central rail’s cryptography.
Here is the article’s central proposition: the economically important product was never simply a connection. It was a privately operated switchboard for public financial infrastructure. The provider could reduce each client’s cost and implementation burden by pooling specialised systems and people. The same scope economies could concentrate operational knowledge, privileged workflows and recovery decisions.
The 2025 incident at C&M, followed by the company’s appearance in the BCB’s current orderly wind-down category, turns this proposition from an abstract outsourcing concern into a practical test of the governance of Brazil’s payment periphery.
One company, three different status questions
The identity bridge is unusually solid, but the status language requires unusual caution. A current public‑registry search based on federal registry data identifiesC & M Software Ltda., CNPJ03.215.009/0001-08, as an active limited‑liability company in Barueri, São Paulo, opened on 8 June 1999 and primarily classified under non‑customisable computer program development and licensing.Serasa Experian’s current CNPJ page records these particulars. The same CNPJ appears in the company’s long‑standing CMSW business identity and at the same Barueri address on its website.
A second question is the historical regulatory status. In a notice published in the Brazilian official gazette on 22 May 2020, the BCB stated that it had authorised C&M Software Ltda., CNPJ 03.215.009/0001-08, as a PSTI on 20 May under the then‑applicable Circular 3.970.The Diário Oficial notice is explicit. This is solid evidence that the assigned company and the historically authorised provider are the same entity. C&M’s own history says it played this role much earlier and was the first provider approved by the central bank, but those broader origin claims are company statements rather than substitutes for the official act.
The third question is current PSTI status under a regime that changed after the 2025 attacks. The BCB’s current RSFN page divides the named providers into three sets. Gokei, JD Consultores and Sinqia are listed in the new certification process and compliant with Instruction 664. Tivit and Topaz are listed in certification and adjustment without clients. ABBC and“PSTI CMSW (C&M Software) – CNPJ: 03.215.009/0001-08”are listed“in orderly wind-down” under Resolution 498.
These three facts can coexist. The company’s corporate registration can be active. Its 2020 PSTI authorisation can be genuine. Its current regulatory line can nevertheless be a wind-down line rather than the certification cohort. Corporate existence is not PSTI certification; historical authorisation is not proof of current permission; and an orderly wind-down process is not proof that the software company has ceased all lines of business.
The BCB page does not specify why C&M is in that category. Resolution 498 provides several pathways and powers concerning transition, precautionary measures, decertification and exit, but the public line does not say which facts applied to CMSW. The chronology raises an obvious question because the 2025 attack preceded the new regime. It does not prove that the incident caused the current classification. Nor does the page disclose a wind-down completion date or the precise scope of permitted activity during the transition.
The responsible conclusion is therefore narrow: as of 17 July 2026, the regulator’s current list does not allow C&M to be described as a currently certified PSTI. It allows C&M to be described as the exact legal provider now listed in an orderly wind-down process.
This conclusion conflicts with the tone of C&M’s current marketing. TheCMSW homepage says it is ‘homologado’ by BACEN, and the current Corner page promotes a ‘PSTI Clássico’ model with full CMSW infrastructure and full central‑bank compliance. These are the company’s present‑tense claims. They may describe products, historical status, transition arrangements or the company’s interpretation; the pages do not reconcile the claims with the current BCB table. In a regulated access market, a buyer should resolve this conflict from the regulator and the proposed contract before treating a sales page as authority.
What Corner actually controlled
C&M’s value proposition is easier to understand by following a payment institution’s work rather than listing software modules. A small bank, fintech, credit cooperative, broker or payment institution wants to offer Pix and other services. Its customer‑facing application may create the instruction, but the institution still has to manage participation rules, exchange standardised messages, reach the RSFN, maintain certificates, control liquidity, reconcile settlements, monitor fraud, respond to operational exceptions and keep service running through failures.
Building these capabilities directly means combining regulated connectivity with specialised 24‑hour payment operations.
C&M’s Corner platform promised to compress that burden. Itscurrent product pagesays the platform connects institutions to the BCB via the traditional Sistema de Pagamentos Brasileiro and the SPI. It promotes Pix, Open Finance, the Nova Plataforma de Cobrança, boletos and older payment services; integration with common legacy systems; messaging via a front‑end interface or web services; fraud scoring and behavioural rules; liquidity support; cash‑position views; and continuous availability. The page offers three deployment models for ‘Corner 2026’: a classic model using CMSW infrastructure, a hybrid arrangement sharing operations with a CMSW data centre, and an on‑premises installation where the client retains more technological sovereignty and CMSW provides specialised third‑line support.
These models allocate control differently. In a fully managed arrangement the provider may own more of the network, processing, monitoring and support path. This can accelerate entry and reduce the client’s need to maintain scarce RSFN expertise. A hybrid model may move application or data components without necessarily moving operational knowledge. An on‑premises licence may put the execution infrastructure under the institution’s roof while leaving it dependent on proprietary code, version knowledge and escalation engineers.
‘On‑premises’ is therefore not synonymous with ‘independent’, just as ‘managed’ is not synonymous with ‘uncontrolled’.
A historical C&M document submitted as a business and technical plan for Corner gives more detail, although it should not be read as an audit of the 2026 system. It describes web consoles, messaging services, RSFN access, VPN arrangements, client firewalls, redundant communication, cash controls and use of the SPB as contingency for Pix. It also describes controls around a entity’s PI‑account liquidity: balances, contribution and redemption rules, simulations when other settlement services are closed, approvals and operational notifications.The document is a useful map of C&M’s claimed design, but its age and provenance limit what it proves about the environment involved in 2025 or the product offered now.
The economic unit sold was therefore broader than packets moving between two endpoints. Corner sat where a customer’s business instruction became a message acceptable to a regulated system. It helped determine how an instruction was authenticated, approved, scheduled, watched, reconciled and escalated. Its consoles and APIs could become the operational memory of the client’s payment team. Its support staff could become the people who understood why a message failed at 2 am. Its fraud settings could intervene at the point where a valid credential produced an apparently valid transaction.
This breadth explains both the appeal and the danger. Shared payment infrastructure can be cheaper and more reliable than each small institution recreating it. Specialists see more failure modes and can maintain dedicated teams. But when multiple clients share the same provider, one flaw, compromised access path, mis‑release or slow emergency decision can cross institutional boundaries. The product’s greatest advantage – concentrated expertise – is adjacent to its greatest risk – concentrated control.
From an instruction to irrevocable money
The architecture becomes clearer if the transaction is separated into control stages. First, a customer or institution creates a planned payment. Second, the institution applies account, authorisation, fraud and compliance rules. Third, the systems build the appropriate Pix message and establish a secure channel. Fourth, the entity authenticates and signs what it intends to send. Fifth, the message reaches the BCB‑operated SPI via the regulated network. Finally, settlement changes PI‑account balances and becomes irrevocable.
A PSTI may help at several stages without legally owning the client’s decision. This is why phrases such as ‘connects a bank to Pix’ are both useful and dangerously imprecise. Network connectivity is only one dependency. Message formation, certificate management, API authorisations, console access, exception queues, liquidity views and fraud limits can determine whether the institution knows what it is authorising.
If an attacker can make a fraudulent instruction appear operationally normal before final signing or can use an overly privileged legitimate path, the central system may do exactly what it was designed to do: settle a validly presented instruction.
The 2025 evidence does not establish the full chain used by the attackers. C&M’s narrative says the incident began with misuse of credentials, while police reports alleged that a company employee enabled unauthorised access. There is no final public investigation report that maps every command, privilege escalation, certificate action and transaction approval. It would be reckless to fill that gap with imagined technical exploitation. Nevertheless, it is possible to identify the architectural questions a defensible investigation should answer.
Who generated each instruction? What identity, device and network path initiated it? What did the institution see before signing? Did the provider own, store or reach private signing hardware? What human and automatic approvals were required for unusual changes in value, volume or destination? Were client environments sufficiently segregated that access tied to one institution could not affect another? Did fraud controls operate before settlement, or mainly watch it? Could a support identity invoke an API intended for an institution?
Did the timing, velocity and concentration of transfers differ enough from the affected institutions’ normal patterns to stop rather than merely alert?
These questions distinguish four controls that marketing often conflates into ‘security’. Channel security protects the route. Identity security establishes who or what is present. Transaction integrity establishes that the exact data approved are the data signed and sent. Behavioural control asks whether an apparently authorised action is plausible. A secure channel with a compromised identity can perfectly carry a fraudulent instruction. Multi‑factor access to an overly privileged role can still be dangerous. A predictive score that arrives after irrevocable settlement can be both impressive and useless.
Brazil’s revised rules now make this separation explicit. The client must retain its private signing keys and validate transaction integrity before signing. The provider must build traceability and real‑time monitoring. Different certificates must serve different environments and functions. These are not redundant controls. They are an attempt to prevent a single provider account, client credential or operational shortcut from collapsing the entire chain of intent.
The night of the breach, without false precision
The public chronology begins around the night of 30 June to 1 July 2025. On 2 July,Reuters reportedthat C&M had informed the BCB of a cyber‑attack on its technological infrastructure. The regulator ordered the blocking of financial institutions’ access to the infrastructure operated by C&M. BMP, an affected institution, said that unauthorised access had reached reserve accounts held at the central bank for interbank settlement but had not affected customer accounts or internal balances. Reuters quoted a source saying that C&M served about two dozen small institutions, while stressing that reported loss estimates differed and no official total had been given.
C&M’s narrative evolved into a detailed public Q&A on 3 July. The company said that the evidence then available pointed to an employee being induced by social engineering to share credentials, possibly followed by later use of other credentials or authentication mechanisms. It denied any technical vulnerability or direct invasion of its critical systems. It said it had revoked credentials and keys, isolated the affected environment, invoked the Pix special return mechanism, requested reversals, notified authorities and clients, and commissioned an external assessment. It also said that products were segregated and that the incident involved a client‑specific simulation of Pix transactions.The Q&A is the company’s position, not an independent conclusion.
The company also acknowledged important control choices. It said Corner offered approvals, channel and time controls, multi‑factor authentication, a reserve operation pilot and other security parameters, but that some clients did not activate all available controls. It said it was reviewing API governance, integration and external access policies and would consider higher mandatory security requirements. This narrative implies a shared‑responsibility boundary: the provider offered options, clients configured some, and an apparently legitimate access path was abused.
It does not establish whether optionality was appropriate to risk, whether secure defaults were strong enough, or whether provider‑level controls should have stopped the activity regardless of a client’s configuration.
Independent reporting added allegations, not a final technical verdict.The Associated Press reportedthat São Paulo police accused a C&M employee of selling credentials and helping others obtain unauthorised access. The police said that more than R$540 million had been diverted from one financial institution, that total losses could be higher, and that R$270 million had been blocked.CNN Brasil reported a police figure of R$542 million for BMPand quoted the BCB clarifying that neither C&M nor its staff were central‑bank contractors. These were allegations and preliminary investigative statements concerning an alleged crime. An arrest or charge is not a conviction, and amounts associated with one institution are not necessarily a final total.
Press estimates ranged even higher. Folha and other media reported figures around R$800 million or R$1 billion, while Reuters quoted a source disputing a R$1 billion total. The company declined to confirm a value. The responsible choice is not to average the numbers or elevate the largest headline.
The verified core is narrower: funds belonging to financial institutions were affected; at least one police account put the amount for BMP above R$540 million; customer deposit balances were said not to have been affected; the BCB’s central Pix infrastructure was not described as compromised; and the final consolidated loss remains undisclosed in the evidence examined here.
The recovery sequence matters as much as the amount. The BCB first disconnected the dependent institutions, then authorised controlled weekday operation from 6:30 am to 6:30 pm after mitigation measures, with enhanced monitoring, limits and client consent. C&M said DICT service and controlled Pix operation had returned. The restriction reduced immediate exposure but also demonstrated the continuity cost of dependency: institutions reliant on the provider could not simply bypass it without regulatory, technical and operational work.
‘Valid credentials’ is the beginning of the investigation
C&M’s distinction between compromised credentials and a software vulnerability is technically significant. It is not exculpatory in itself. A buffer overflow, unpatched component, stolen password, bribed employee and poorly scoped support role are different failure mechanisms. They require different fixes. Yet a payment control system must be designed for the possibility that an authorised identity becomes hostile or is convincingly impersonated. Security that works only as long as every credential holder is trustworthy is a personnel policy, not a resilient transaction architecture.
The 2025 episode therefore raises a more useful question than ‘Was the code hacked?’: how much harmful authority could a compromised path assemble before another independent control intervened? The answer depends on least privilege, separation of duties, client isolation, transaction signing, behavioural limits and human escalation. If one employee’s credentials alone could not create or approve messages, an attacker would need a second independent capability. If the affected institution validated the exact payment data before using a key it alone controlled, provider access would not suffice.
If unusual overnight volume caused a hard stop, speed would work against the attacker rather than for them.
None of this proves that a particular missing control caused the C&M incident. The public evidence is not granular enough. That explains why the regulator’s subsequent requirements focus on these points. Instruction 664 required existing providers to harden end‑to‑end paths, secure storage and client access to logs, review privileged and remote access, and monitor external connections and unusual access patterns. Thecurrent Resolution 498says a PSTI must not have access to private keys used to sign payment system messages. It requires 24‑hour real‑time fraud monitoring capable of assessing unusual values, volumes and rates before submission, not just after settlement.
The principle is that authenticity and plausibility must be separated. A valid certificate can establish that a message comes from an expected cryptographic identity. It cannot establish that the underlying economic instruction was intentional. A legitimate support account can establish that a recognised operator logged in. It cannot establish that the operator should have reached a client’s production action at that hour. A client’s consent to use a managed provider can establish a contract. It cannot transfer the client’s obligation to know what leaves its account.
The same logic applies to ‘optional controls’. Software providers often let clients trade friction for speed. In an ordinary business application, a buyer may reasonably choose lighter approvals. In an irrevocable real‑time settlement path, an option that protects against a catastrophic but plausible transaction may become part of the minimum safe product. Resolution 498 moves in this direction by turning several controls into conditions of participation and imposing duties on both the provider and the institution. The hard procurement question for any C&M client is not whether a feature exists on a brochure.
It is whether the feature is mandatory in the relevant path, independently testable and incapable of being switched off by the same identity it is supposed to constrain.
Brazil rewrote the PSTI contract
The BCB’s regulatory response extended beyond C&M. In September 2025, citing organised‑crime involvement in recent attacks on financial and payment institutions, the central bank imposed an immediate R$15,000 cap on Pix and TED transfers for payment institutions without full authorisation and for institutions connecting via PSTIs.The BCB announcementsaid the restriction could be lifted after demonstrated controls, while reinforcing access, IP‑address changes and institutional authorisation timelines.
Resolution 498 then replaced a relatively light concept of provider authorisation with a comprehensive certification and supervision framework. As amended in early 2026, it requires a Brazilian legal structure, compatible technical and administrative capacity, governance and control functions, cyber and fraud policies, independent audit, civil‑liability and operational insurance, and at least R$15 million in capital and equity. The BCB can demand more in proportion to transaction volume, client count and risk. The regulation explicitly states that certification is not a general authorisation to conduct the provider’s economic activity.
That is why careful status language matters: a software company may continue to exist and sell other products while lacking the required status for a particular RSFN service.
Instruction 664 provided urgent technical detail for providers already in operation in September 2025. It required end‑to‑end audit trails, retention rules, secure logs available to clients for reconciliation and risk management, stricter access control, and monitoring of abnormal external or privileged access. A reasonable‑assurance report from an independent auditor registered with Brazil’s securities regulator was part of compliance evidence. This is materially different from a provider saying it commissioned an assessment: the institution and the regulator need a defined scope, a standard, an exceptions list and a fix status.
The BCB further separated signing authority from transport.Instruction 667required institutions seeking relief from the Pix limit to attest that they do not share private signing keys with the PSTI nor store those keys in its environment. Certificates accessible to a provider had to be revoked and replaced. Clients had to use separate credentials for production and testing and between message signing and channel establishment, review authorisations including those of subcontractors, and validate transaction integrity.
In January 2026, the BCB adjusted the regime via Resolution 547. It clarified governance and risk requirements, allowed risk‑proportionate capital above the floor, strengthened decertification and extended the transition deadline for incumbents to apply for new certification to eight months.The BCB’s explanatory notesaid that institutions using a PSTI would remain under the R$15,000 Pix and TED limit until their provider passed certification. The transitional rule says that an incumbent that does not apply within the deadline is automatically decertified and must execute an orderly wind‑down plan. It would be wrong, however, to deduce from this general clause that C&M’s line results from a missed application; the current list does not specify the reason.
The resulting contract is more expensive and more honest. A PSTI can still give small institutions scale and specialised access. In return, the provider must demonstrate financial capacity, independent control evidence and hardened security architecture. The institution cannot outsource responsibility. It must continuously monitor governance, cyber risk, fraud management and continuity; retain documentation and audit reports; implement required controls; report material failures; keep its signing keys; and verify the message it signs. Outsourcing changes who does the work. It does not change who owns the regulated outcome.
Orderly wind‑down is a technology programme
‘Orderly wind‑down’ sounds administrative. In a payment system it is an engineering and operations programme carried out while the old service may still be critical. Resolution 498 says the plan must prioritise limiting impact on client institutions and on the regular functioning of the SFN and SPB. This objective is deceptively compact. A client cannot change its payment periphery by changing a domain name and copying a database.
The transition begins with legal and regulatory eligibility. The receiving provider must have the appropriate current certification, or the institution must qualify and build a direct route. Participation registrations, contact points and operational responsibilities must change. Network access must be established on both independent telecommunication networks of the RSFN – the BCB says each entity must use both – and then tested for failure and recovery. Firewalls, addresses, routes, channel certificates and monitoring need new ownership.
The application work follows. Pix and SPB messages have defined versions, validation rules and lifecycles. The new path must reproduce client‑specific transformations, idempotence, retries, acknowledgements, exception handling and reconciliation without duplicating or losing an instruction. Historical messages and audit evidence must remain available for regulatory review and dispute. Treasury staff need reliable visibility into PI accounts. Fraud rules must be moved without losing baselines or giving the new provider a blind learning period.
Interfaces with core banking, ledgers, customer applications, compliance systems and support tools all need parallel testing.
Trust must be regenerated, not carried forward. In February 2026, the BCB issuedSPI Notice 003/2026, telling entities that whenever a technology environment, connection model or provider with certificate access changes, they must issue new channel and signing certificates, deactivate the old ones with the BCB and revoke them with the certificate authority. The notice also calls for new certificates in case of suspected fraud. This is a crucial exit principle: the migration is incomplete if old credentials can still exercise authority.
The distinction between certificates became sharper in June 2026. The BCB’s updated Pix security information separates certificates used to authenticate the communication channel from those used to sign messages and prohibits one purpose from substituting for the other. This separation reduces the likelihood that control of transport becomes control of value. It also adds work: inventories must be accurate, hardware storage and protection must be reviewed, certificate renewal must be repeated, and rollback cannot mean silently restoring a compromised trust path.
C&M’s three announced deployment models illustrate why every client exit is different. A client on a classic CMSW infrastructure model may need a complete destination environment. A hybrid client may control some application components but still depend on CMSW’s data centre and operational knowledge. An on‑premises client may have execution but lack code‑level capacity or specialised third‑line support. Asset ownership is not operational independence. A credible exit plan identifies each irreducible dependency before a crisis and tests the path away from it while the incumbent provider is healthy.
The current BCB list does not disclose C&M’s client‑level wind‑down timeline, destination providers, residual scope or completion criteria. These details may be rightly confidential. Their absence means outsiders cannot judge how far the wind‑down has progressed. Clients and regulators, however, should be able to answer a measurable set of questions: how many institutions remain dependent; what messaging services still traverse the provider; whether new credentials have been issued; whether each client has completed dual‑path testing; how reconciliation exceptions performed; and what event permits decommissioning the old path.
Support is part of the security boundary
Payment software is often bought as technology and experienced as support. A failed message at 3 am may not announce whether the cause is the client’s core, the provider’s transformation, a certificate, a network path, an SPI rule change or limited public evidence liquidity. The fastest resolution depends on people who can see across these layers. C&M’s claimed advantage – long experience in SPB and Pix messaging – would be most valuable precisely in those moments.
This creates an under‑examined concentration. Third‑line engineers and operational analysts can accumulate broad visibility and exceptional privileges because ordinary client teams cannot solve the hardest cases. Emergency access may bypass normal workflow to get payments running quickly. Shared support tools may connect many client environments. A small group of people may understand certificate replacement, message reprocessing and coordination with the regulator. Their knowledge improves resilience while their accounts, devices, working hours and judgement become part of the attack surface.
The alleged involvement of a C&M employee in 2025 makes personnel control unavoidable, but the response cannot be reduced to training staff not to disclose credentials. A resilient support design assumes that coercion, corruption, fatigue, error and account takeover are possible. It uses just‑in‑time privilege, separate approval for production actions, device‑bound identity, session recording, client‑visible logs, narrow client partitions, forced expiry and behavioural stops. It prevents a support identity from generating or approving value‑carrying instructions.
It makes an emergency elevation visible enough that another person must explain it while it is happening.
Compensation and staffing also belong in due diligence, even though the public record is not sufficient to judge C&M’s practices. A provider selling continuous availability needs teams deep enough to avoid a single indispensable operator. It needs named incident direction, bilingual or local support where applicable, tested contact paths to the BCB and certificate authorities, and succession for specialists who understand older SPB services. Buyers should inspect turnover in privileged roles, background‑check policy, access‑revocation timelines and the ratio of on‑call engineers to critical clients.
A glossy 24/7 service statement says nothing about whether the third person in an escalation is awake, authorised and trained.
Support evidence should be outcome‑based. Useful metrics include time to acknowledge a regulatory message failure, time to isolate a client, time to revoke a certificate, age of unresolved reconciliation exceptions, false‑negative and false‑positive rates in fraud controls, frequency of privileged access, and recovery performance in unannounced exercises. Average ticket resolution can hide the single payment incident that matters. A provider should therefore report critical paths separately and let clients see their own traces.
Finally, support obligations must survive contract termination and regulatory exit. The incumbent provider may have less commercial incentive to retain experts while clients migrate, just when historical knowledge is most needed. An orderly wind‑down plan should fund a dedicated transition team, identify key‑person risk, require up‑to‑date runbooks and maintain response levels until switchover. Continuity is not achieved if the infrastructure remains live but the people who understand it leave first.
The price of delegation
C&M does not publish a general PSTI price list. Its Corner page directs potential clients to sales contact, while a Pix Automático FAQ says that one specific service is billed per message and incurs no additional setup fees or surprise monthly charges for existing Corner users. That is a circumscribed marketing statement, not a comprehensive price list. Any estimate of C&M’s overall commercial terms would therefore be speculative.
The cost logic of the product can nevertheless be analysed. A managed PSTI service replaces several visible expenses: dual‑network connectivity, secure environments, specialised payment engineers, messaging software, certificates, monitoring, testing, regulator‑facing operations and ongoing support. The provider can spread fixed costs across clients. A small institution can reach Pix earlier and with a more experienced team than it could assemble alone. Per‑message pricing also aligns some expenses with transaction volume.
But the invoice is only the first layer. Implementation costs include mapping core‑banking data into payment messages, establishing environments, integrating identities, setting fraud thresholds, running homologation tests, training operations and proving reconciliation. Recurring economics may combine a platform or support fee, usage fees, modules, connectivity, storage, audit support and higher service levels. Regulatory changes create additional work. C&M’s published data‑protection terms say that changed legal or regulatory requirements may produce costs to be negotiated, and that client‑requested audits may be billed to the client.The policy also sets out audit and incident responsibilities, although it is a company contract document rather than an independently verified control report.
Risk adds another price. Insurance deductibles, capital buffers, fraud losses, incident counsel, investigation work, client remediation and regulatory restrictions can eclipse subscription savings. The R$15,000 limit imposed on institutions using providers that have not completed the new certification process can change a client’s product economics even while its technology still works. A cash‑management or corporate‑payment product becomes less useful if routine transfers exceed the cap. Provider status is therefore a commercial feature with immediate revenue consequences.
Exit is the last layer and often the least priced. A client that saves by using proprietary consoles, transformations and operational knowledge may later pay for parallel infrastructure, data extraction, new certificates, dual support and months of testing. Switching cost increases with every undocumented rule, provider‑controlled fraud configuration and integration that exists only in the incumbent’s head. On‑premises deployment may reduce infrastructure migration cost but preserve application and expertise dependency. A lower monthly bill may therefore buy a more expensive future option.
A rational comparison uses total cost of control rather than cost per message. Add implementation, internal supervision, independent assurance, incident exercises, regulatory‑change work and a funded exit. Then compare residual risk: what value can be moved before an independent stop; how many clients share a failure domain; how quickly a key can be replaced; and whether an alternative route has already carried a real test message. The cheapest provider is not the one with the lowest rate. It is the one that produces the required payment outcome with the smallest combined cost of operation, supervision, failure and departure.
Competition is a choice of control architecture
The BCB’s current provider page names only a small transition set, but it must not be used to calculate market share. It shows three providers in certification and compliant with Instruction 664, two in adjustment without clients, and two in orderly wind‑down. The page does not say this is a full economic census of every software provider, direct connection or intra‑group arrangement. C&M’s own website displays changing market‑share figures that appear to be generated dynamically and are not accompanied by a verifiable methodology. They are inappropriate evidence for concentration percentages.
Competitive choices are nevertheless identifiable. An institution can seek another successfully certified PSTI, build direct RSFN and SPI capability where its regulatory form permits, use an intra‑group technology provider under the regime’s segregation exception, or reconsider whether it needs direct participation in a particular Pix service. Direct and indirect Pix participation also allocate settlement and directory functions differently. Each option changes cost and control rather than simply replacing one logo with another.
Another managed provider offers the closest functional substitute. It may reduce migration complexity if it supports the same message catalogue and familiar legacy systems. The buyer must still ask whether ‘different provider’ means different failure domain. Two brands may share a data centre, a telecommunications operator, a certificate process, a software component, a security subcontractor or a small pool of specialised staff. Concentration must be mapped across fourth parties and common infrastructure, not counted by provider name.
Direct operation increases control but also creates a new operational institution inside the institution. It needs people who can follow catalogue versions, maintain both RSFN networks, protect keys, manage liquidity, monitor fraud continuously and coordinate incidents. The security gain exists only if the buyer can execute these tasks better than a specialist. An under‑resourced direct connection may trade provider concentration for key‑person risk and weaker maintenance.
An intra‑group provider may align incentives and retain knowledge, but it may share governance, identity systems and crisis management with the financial institution it is meant to protect. Amended Resolution 498 exempts intra‑group processing providers from the full external PSTI framework while requiring operational segregation and applicable technical and security controls. This is not a licence to collapse duties. The group must show that compromise of an ordinary corporate environment cannot become payment authority.
International standards reinforce this architectural view. The CPMI‑IOSCO methodologyfor critical service providersasks about enterprise risk, information security, reliability, technology planning and third‑party dependencies. Basel’s2025 principles for third‑party risktreat concentration, supply‑chain dependency, lifecycle management and exit as bank responsibilities. These standards do not pick out C&M or a competitor. They explain why a procurement decision must cover the full dependency graph and remain revisable throughout the contract.
For C&M, competition now has a time dimension. A product page may continue to advertise Corner 2026, hybrid deployment and specialised support. A regulated institution needing RSFN access must start with the BCB’s current status evidence. If a proposed service depends on C&M acting as an external PSTI, the buyer needs written confirmation of the legal basis, transition scope and timeline authorised by the competent authority. If the proposal is an on‑premises software licence, a support service or a non‑PSTI product, the buyer must define which regulated functions remain with C&M or not.
Ambiguity about role is itself a control failure.
Twelve procurement tests
The useful response to the 2025 incident is not a generic cyber questionnaire. A buyer should run tests that make control boundaries observable before entrusting production payments to any provider. For C&M, these tests must also address the current orderly‑wind‑down classification.
1. Prove legal and regulatory role.Match the contracting party’s legal name and CNPJ to the current BCB record. Obtain exact status and scope for each service date. Distinguish software licence, managed processing, RSFN access, indirect Pix support and central‑bank participation. Do not accept a historical official notice or a marketing claim as proof of current certification.
2. Trace an end‑to‑end payment.Start from the customer instruction and identify every system, identity, transformation, approval, key, certificate, queue, log and reconciliation record up to settlement. Mark which party controls each step. Repeat for reversal, timeout, duplicate, malformed message and liquidity lack. Architecture slides are not enough; the buyer should observe a controlled transaction.
3. Demonstrate exclusive signing control.The institution must generate and retain its private signing keys within a boundary the provider cannot reach. It must verify the exact message before signing. Test that a provider administrator, support engineer or compromised channel certificate cannot produce a valid value‑carrying message. Confirm separate credentials for testing, production, channel establishment and message signing.
4. Attempt an insider scenario.Give a red‑team operator a legitimate but narrow support identity. Try to reach another client, modify a fraud limit, create a new integration, replay a message and elevate privileges at an unusual hour. The test only passes if preventive controls stop the harmful action and client‑visible evidence explains the attempt in real time.
5. Test abnormal value and velocity before submission.Simulate transfers that are individually permitted but collectively abnormal by time, destination, amount and rate. Verify when a hard stop occurs, who can override it, whether the override requires different authorisation and how quickly the institution is notified. A dashboard that alerts after irrevocable settlement is not a preventive control.
6. Isolate a client without stopping everyone else.Force a failure or suspected compromise in one tenant. Measure time to revoke access, rotate credentials and preserve evidence. Confirm that other institutions continue securely and that shared components cannot leak authority between partitions. Then test the reverse: a common‑component failure must enter a controlled safe state rather than produce uncertain transactions.
7. Revoke and rebuild trust.Exercise the BCB’s certificate‑change process. Issue new certificates, deactivate old registrations and revoke them with the certificate authority. Prove that every old path fails, including contingency systems and forgotten test endpoints. Time the exercise; during a real attack, certificate recovery is part of service recovery.
8. Run both network paths and lose one.The RSFN uses two independent telecommunication networks. The institution must observe traffic switching, capacity, alarms and recovery when one fails. It must also map dependencies that may make apparently independent routes share power, facilities, DNS, identity or operations.
9. Reconcile from client evidence.Buyer must be able to reconstruct what was generated, approved, signed, sent, acknowledged and settled without relying entirely on the provider’s console. Logs must be tamper‑evident, retained for the required period, available quickly and correlated across identities and messages. Sample exceptions must resolve to accounting entries.
10. Inspect independent assurance rather than badges.Obtain the auditor, scope, period, systems, exclusions, exceptions and fix dates for security and continuity work. Verify whether the review covered the exact production service and post‑incident controls. C&M said it commissioned external investigation and control work after the attack; a potential regulated client should determine which report can legally be shared and what remained unresolved.
11. Price a full exit before entry.Name the alternative provider or direct model, required staff, data and configuration exports, certificate plan, parallelism duration, support obligations and maximum tolerated interruption. Put costs and service levels in the contract. Then perform a partial migration exercise. A document that has never moved a message is not an exit capability.
12. Define evidence for the wind‑down phase.For a client still affected by C&M’s transition, record regulator‑approved milestones, residual services, allowed limits, migration destination, client consent, monitoring measures and final decommissioning event. Review them at board level. Because the BCB’s public page does not explain the reason or timeline, private governance evidence must be particularly precise.
What the public record cannot answer
The evidence around C&M is substantial for a firm identity and meaningful risk analysis. It is not sufficient for a final verdict on culpability or current operational scope. Several absences should remain explicit.
First, no final public investigation report examined for this article establishes the complete technical sequence of the 2025 fraud. C&M stated that social engineering and misuse of credentials were the starting point and denied a software flaw. Police and press accounts alleged that an employee facilitated access. These accounts may be compatible, but they do not disclose the precise privileges used, whether additional vulnerabilities were exploited, which messages were signed by whom, or which control detected the transfers first.
Second, there is no authoritative consolidated loss figure in the public record examined here. Police reports attributed more than R$540 million to BMP, while other press estimates ranged towards R$800 million or R$1 billion. Some funds were said to have been blocked or recovered. The number of affected institutions also varied. A lawsuit amount, attempted transfer value, gross diverted value, blocked value and final economic loss are different measures. Until an authority reconciles them, a single headline number would create false certainty.
Third, the current BCB page gives C&M’s category but not its cause. It does not say whether the orderly wind‑down was voluntary, transitional, the consequence of an application decision, a precautionary measure, a failure to meet a new requirement, or a combination. It does not say whether every legacy client has migrated, which services may continue during wind‑down, or when completion is expected. Resolution 498 describes possible routes; it does not identify which route applies to C&M.
Fourth, current product marketing is not reconciled with this status. The website promotes full PSTI compliance and present‑access capabilities. There may be a legal explanation involving transition, deployment model, product licensing or services outside the regulated PSTI role. No public clarification found here matches each claim to the current BCB table. Buyers should deduce neither legality nor illegality from the mismatch; they should require the role to be resolved.
Fifth, the control evidence is largely self‑described. C&M publishes historical security and continuity documents and says it commissioned independent work after the incident. The public record examined here does not contain the resulting investigation report, an current independent assurance opinion, an current disaster‑recovery test, client‑specific availability data or proof that each post‑incident fix has been completed. The absence of public view does not mean the work does not exist. It means an external reader cannot verify it.
Finally, concentration itself is not measured. C&M has made historical and current market‑share claims, but the visible figures vary and lack a disclosed method. Reuters cited about two dozen small clients at the time of the attack, while the company pages cite a much broader historical reach. The BCB’s transition list is not a denominator for market share. A rigorous concentration assessment would need current client numbers, their transaction values, common dependencies, substitutability and migration time – data more likely available to the regulator than to the public.
Watchpoints for C&M and its counterparties
The first watchpoint is the BCB list itself. A future change could show completion of the orderly wind‑down, a different status or a new public explanation. Until then, C&M should not be described as currently certified simply because its website uses present‑tense PSTI language. Conversely, an orderly wind‑down line should not be stretched into a claim that the company is defunct or banned from selling any software.
The second is client migration. Evidence that institutions have migrated to a successfully certified provider, built direct access, replaced certificates and completed reconciliation would show whether the wind‑down is working as intended. Evidence of repeated deadline extensions, persistent transaction limits or reliance on temporary arrangements would indicate higher continuity risk. The critical metric is not a migration announcement but a tested production capability without the old trust path.
The third is independent control disclosure. C&M said it engaged external investigation and security work and was reviewing API governance, integration and access. A summary that identifies scope, findings, residual exceptions and fix dates – without exposing exploitable detail – would significantly improve public understanding of the fix. Similarly, a current assurance report available under confidentiality for clients. Marketing pages saying ‘full compliance’ are weaker than circumscribed evidence with exceptions.
The fourth is enforcement and adjudication. Police allegations, criminal charges, civil claims or regulatory action may clarify who did what and what loss figure is relevant. They may also discard early theories. Reporting should preserve the distinction between allegation and finding throughout. A subsequent conviction would establish criminal conduct by named individuals; it would still not by itself answer every architecture or governance question.
The fifth is product repositioning. Corner 2026’s classic, hybrid and on‑premises models suggest that C&M may seek to preserve software and expertise revenue even if the provider role changes. This may be a legitimate path, but contracts must state who operates the regulated connection, who holds keys, who monitors fraud and which company is responsible for support. A client‑deployed licence may still contain proprietary dependencies; a hybrid may still concentrate privileged operations.
The sixth is the regulator’s enforcement of its own new standard. The current table shows a market in transition rather than a stable field. Successful certification decisions, higher capital requirements, assurance findings and client limits will reveal how strictly Resolution 498 is applied. The BCB should also be watched for aggregate information on provider concentration and migration risk. Stricter provider rules may improve security while unintentionally reducing the number of providers; fewer, stronger providers may still create sector‑wide dependency.
The last watchpoint belongs to client boards. Resolution 498 imposes continuous monitoring obligations on the contracting institution. A board that treats PSTI status as a procurement certificate rather than a live operational condition has missed the lesson. It should receive metrics on privileged access, abnormal transactions, certificate health, incident exercises, audit exceptions, concentration and exit readiness. It should know the maximum value that could leave before an independent stop and the time needed to operate via another path.
## The switchboard beneath the public service
Pix’s success is not diminished by acknowledging its dependencies. The central system can be highly available, final and secure while the periphery access remains uneven. Indeed, the 2025 incident demonstrates a form of resilience: the BCB isolated an affected provider layer, kept the central rail running and restored limited access under enhanced controls. It also demonstrates the cost of that isolation for institutions whose route depended on C&M.
C & M Software built a business by making a difficult infrastructure usable. It gathered knowledge about payment messaging, connected legacy systems, offered operational consoles and supported institutions that did not want to reproduce the entire RSFN stack. This is genuine technology work. It is precisely why the company became consequential. The closer a provider sits to the point where intent becomes irrevocable settlement, the less adequate it is to assess the provider as ordinary enterprise software.
The 2025 attack showed that a credential can be more dangerous than a broken server. The current orderly wind‑down line shows that continuity must include departure, not just redundant hardware. The new regulatory regime shows that the institution must preserve a cryptographic and operational core it does not delegate: its keys, its validation of transaction intent, its oversight of the provider and its ability to change route.
There is no evidence‑based shortcut to a final judgement on C&M. The company’s narrative of social engineering is plausible and partly reflected in police reports, but the public investigation trail is incomplete. The regulator’s current status is clear, but its reason is not. The website’s product claims are visible, but their relationship to the orderly wind‑down process is not resolved. These tensions should remain visible rather than be smoothed into vindication or condemnation.
The more durable conclusion is about market design. Shared providers allow small institutions to join a sophisticated public infrastructure. They also create private bottlenecks under a universal service. Brazil’s post‑2025 response – capital, insurance, independent assurance, key separation, pre‑settlement fraud controls, client supervision and orderly wind‑down – recognises that a PSTI is not a neutral pipe. It is a critical control surface.
For any institution considering C&M software, migrating from its provider service or selecting a successor, the decisive question is therefore not ‘Can this provider connect us to Pix?’ It is ‘What powers will this connection concentrate, what powers will remain independently ours, and can we prove both answers during the contract’s worst night?’ Pix can settle in seconds. The trust in the switchboard beneath it must be designed for years.

