CiberLATAMbywhalemate

Brazil banks face more digital fraud

STJ rulings may help victims recover losses, while a TCU audit says PCC and Comando Vermelho ran digital fraud tied to state benefits.

Whalemate Labs · AI-assisted researchPublished:Updated 3 min read

Recent decisions by Brazil’s Superior Court of Justice (STJ) improve the odds that consumers can recover money lost in fake bank call center scams, by reinforcing the view that banks may be liable when a security failure enables unauthorized remote access to a customer account. At the same time, an audit by the Federal Court of Accounts (TCU) found that criminal groups such as Primeiro Comando da Capital (PCC) and Comando Vermelho organized digital fraud schemes using government social programs.

Recent rulings by Brazil’s Superior Court of Justice (STJ) have improved the odds that consumers can recover money lost in fake bank call center scams, while a July 2026 audit by the Federal Court of Accounts (TCU) found that criminal groups such as Primeiro Comando da Capital (PCC) and Comando Vermelho built digital operations to defraud citizens using government social programs.

What changed in bank fraud cases?

According to coverage by Correio dos Municípios, citing Valor Econômico, the core of the rulings is financial institutions’ responsibility when fraud relies on a security flaw that ultimately enables remote access to an account. The shift matters for bank fraud victims because it strengthens the chance of recovering lost money in this kind of scam.

The issue comes as digital fraud is no longer an isolated problem. In Brazil, the combination of mobile banking, instant transfers, and identity theft expands the reach of attacks and pushes banks and fintechs to tighten controls over leaked credentials, authentication, and identity verification.

What did the TCU audit show?

The TCU audit, released in July 2026, found that criminal groups such as Primeiro Comando da Capital (PCC) and Comando Vermelho organized digital operations to scam citizens using government social programs. The report identified 1,700 fraudulent ads over a few days in January 2025, according to the TCU.

The TCU’s work identified 1,700 fraudulent ads in just a few days in January 2025, a sign of organization that goes beyond scattered scams. That level of activity also affects the financial and digital identity ecosystem, because it connects fraud, CPF impersonation, and the misuse of personal data with criminal monetization channels.

Where are fraud schemes still concentrated?

In this setting, the use of PIX and mobile channels remains at the center of fraud schemes. Pressure on banks and fintechs is not only about blocking suspicious transactions, but also about maintaining stronger authentication mechanisms in the face of compromised credentials.

Biometrics and 2FA stand out as critical controls in an environment where identity theft and personal data leaks can enable unauthorized access. Data protection under the LGPD is also gaining weight, because the theft and fraudulent use of personal information are becoming direct inputs for bank and digital fraud operations.

Sources

View all