CiberLATAMbywhalemate

Brazil banks face more digital fraud

STJ rulings may help victims recover losses, while a TCU audit says PCC and Comando Vermelho ran digital fraud tied to state benefits.

Whalemate Labs · AI-assisted researchPublished:3 min read

Recent decisions by Brazil’s Superior Court of Justice (STJ) improve the odds that consumers can recover money lost in fake bank call center scams, by reinforcing the view that banks may be liable when a security failure enables unauthorized remote access to a customer account. At the same time, an audit by the Federal Court of Accounts (TCU) found that criminal groups such as Primeiro Comando da Capital (PCC) and Comando Vermelho organized digital fraud schemes using government social programs.

Recent decisions by Brazil’s Superior Court of Justice (STJ) have improved the odds that consumers can recover money lost in fake bank call center scams, after the court solidified the view that banks can be held responsible when a security flaw enables unauthorized remote access to a customer account.

What changed in bank fraud cases

According to coverage by Correio dos Municípios, citing Valor Econômico, the core issue in the rulings is the liability of financial institutions when fraud depends on a security vulnerability that ends up allowing remote access to a customer’s account. The shift matters for victims of bank fraud because it strengthens the chances of getting lost funds back in this kind of scam.

The debate is unfolding as digital fraud is no longer an isolated problem. In Brazil, the mix of mobile banking, instant transfers and identity theft widens the reach of attacks and forces banks and fintechs to tighten controls over leaked credentials, authentication and identity verification.

Digital fraud with a criminal structure

The other side of the problem came from an audit by the Federal Court of Accounts (TCU), released in July 2026. The report found that criminal factions such as Primeiro Comando da Capital (PCC) and Comando Vermelho organized digital operations to defraud citizens using government social programs.

The TCU identified 1,700 fraudulent ads in just a few days in January 2025, a sign of coordination that goes beyond scattered scams. That level of activity also affects the financial and digital identity ecosystem, because it links fraud, CPF impersonation and the misuse of personal data to criminal monetization networks.

PIX, biometrics and data protection

In this setting, PIX and mobile channels remain at the center of fraud schemes. Pressure on banks and fintechs is not only about blocking suspicious transactions, but also about maintaining stronger authentication methods in the face of compromised credentials.

Biometrics and 2FA stand out as critical controls in an environment where identity theft and personal data leaks can enable unauthorized access. Data protection under the LGPD also matters more, because the theft and fraudulent use of personal information have become direct inputs for bank and digital fraud operations.

Sources

View all