CiberLATAMbywhalemate

Brazil Central Bank Tightens Pix Security

Brazil’s central bank may restrict Pix access for firms with cyber failures and apply graduated penalties based on risk.

Whalemate Labs · AI-assisted researchJul 19, 20262 min read

Brazil’s central bank plans to give cyber risk the same weight as capital and liquidity in Pix prudential supervision, with objective criteria to classify participating institutions. The measure would include technical indicators, a definition of serious security failures, and a graduated response that could end with suspension from the system.

Brazil’s central bank is looking to give cyber risk the same weight as capital and liquidity in prudential oversight of Pix, according to NC News. The plan would add objective criteria to classify participating institutions and define what counts as a serious security failure, along with the technical indicators that would be monitored.

Graduated response

According to that report, the authority is weighing a step-by-step response based on the level of risk detected. When technical vulnerabilities or weak procedures are identified, the first move would be to set daily or per-transaction limits and restrict operating hours.

If there are signs of an active attack, large-scale fraud, or repeated noncompliance, the central bank could go further and suspend access to Pix altogether. In that case, the institution would effectively be placed in a digital quarantine until the fixes are technically validated.

NC News also says the agency wants to act preventively and move faster than the responses currently allowed under traditional administrative processes. That points to a model of continuous supervision over the cybersecurity of the Pix ecosystem.

What was reported about new rules

Separately, FDR reported that starting in May 2026, banking apps could be barred from sending and receiving Pix transfers if they do not strengthen digital security. That report describes a temporary suspension of the transfer button until the institution shows it meets the technical requirements.

The same coverage notes that it does not cite a specific regulatory order and frames the scenario as a measure announced in general terms, so that scope is not confirmed in the cited documentation. For now, what can be verified is that the central bank is studying tougher security criteria and broader intervention powers over institutions that operate with Pix.

Sources

View all