CiberLATAMbywhalemate

Brazil SISVISA database exposed without auth

A SISVISA-linked database was reportedly left open without authentication, exposing more than 102,000 files with sensitive data.

Whalemate Labs · AI-assisted researchPublished:2 min read

Hackread reported that a database linked to Brazil’s SISVISA system may have been publicly accessible, with 102,215 files and about 79 GB of data that reportedly included names, addresses, phone numbers, CPF/CNPJ numbers, identity documents, and health inspection reports.

Hackread reported that a database associated with Brazil’s SISVISA system may have been publicly accessible, and said researcher Jeremiah Fowler identified it as belonging to the Brazilian Health Surveillance Information System.

Scope of the exposure

According to Hackread’s coverage, the exposed database contained 102,215 files, with an estimated volume of about 79 GB. The data mentioned reportedly included names, addresses, phone numbers, CPF/CNPJ numbers, identity documents, and health inspection reports. Security Affairs carried the same story and said the database was accessible without authentication, with 102,215 Brazilian health records.

Access shut down after notices

According to the secondary coverage, public access was disabled after the researcher sent notices to government offices. No confirmed official response from Brazilian authorities appears in the available material.

Hackread’s report and Security Affairs’ follow-up both indicate that the exposure affected information tied to Brazil’s health surveillance system, and that unauthenticated access was at the center of the finding. Digital Reviews also published coverage of the SISVISA exposure, although the available results do not provide any additional official confirmation of the incident.

Sources

View all