CiberLATAMbywhalemate

Brazil tightens cybersecurity rules

Brazil’s central bank tightened controls on providers, RSFN, Pix and the Reserve Transfer System, with stronger authentication.

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

The Central Bank of Brazil tightened security rules for financial system participants, adding more controls over technology providers, the RSFN, and Pix and Reserve Transfer System environments. The measures include multifactor authentication, environment isolation, and tighter control of credentials and private keys.

Update September 2, 2026: The Central Bank of Brazil tightened security rules for financial system participants and strengthened controls over technology providers, the RSFN, and the Pix and Reserve Transfer System environments. It also added measures such as multifactor authentication, environment isolation, and tighter control over credentials and private keys.

Between 2021 and 2026, the Central Bank of Brazil and the National Monetary Council tightened security requirements for financial institutions and, at the same time, expanded oversight of cryptoassets. That path brought new obligations for cooperatives, banks, fintechs, and virtual asset service providers, along with monitoring and alert tools for crypto transactions.

RadarCoop, the weekly bulletin for the cooperative system, says there is currently no specific Central Bank of Brazil regulation that sets out a general artificial intelligence policy for credit unions. The same bulletin says the rules in force rely on broader prudential standards, especially CMN Resolution No. 4,893/2021 and later amendments.

What does CMN Resolution No. 4,893/2021 require?

CMN Resolution No. 4,893/2021 requires financial institutions, including credit unions, to maintain a cybersecurity policy aligned with their size, risk profile, business model, the nature of their operations, and the sensitivity of the data under their responsibility.

According to RadarCoop, that policy covers authentication, encryption, information leak prevention, traceability, backups, vulnerability management, access control, and protection against malicious software. The bulletin also notes that CMN Resolution No. 5,274/2025 expanded those requirements and reinforced security procedures and controls for institutions in the National Financial System.

SevenRed says that, under the wording introduced by CMN Resolution No. 5,274/2025, the cybersecurity policy explicitly covers the software development cycle, the adoption of new technologies, and integrations through electronic interfaces, including APIs. In practice, that technical analysis says this means vulnerabilities must be assessed and fixed with each new release, not only during scheduled windows.

The same analysis adds that institutions subject to the rule must carry out penetration tests at least once a year with an independent professional and keep a documented action plan to address findings. It also says these obligations extend to software developed by outside vendors, which must be subject to security controls that can be demonstrated contractually and verified.

What did the Central Bank do with cryptoassets?

In August 2026, Brazil’s central bank issued Resolution No. 584, which amends Resolution No. 142/2021 to bring Virtual Asset Service Providers into the anti-fraud rules. The regulation introduces a precautionary hold of up to 24 hours for certain outgoing cryptoasset transfers above US$10,000, with enforcement set to begin on January 1, 2027.

Domestic Monero breaks down that the hold applies when the destination is a self-custody wallet or a virtual asset company abroad, and that the threshold can be measured per transfer or by the total accumulated on the same day. ASA Brasil adds that, when the hold applies, companies must notify the customer, keep a strict record of fraud incidents and attempts, and document corrective measures.

How is oversight of the crypto ecosystem being applied?

The Central Bank has also moved ahead with operational surveillance tools. SpaceMoney reported that it closed an agreement with Hypernative to use an on-chain monitoring, automated response, and fraud prevention platform aimed at crypto brokers.

According to that coverage, Hypernative’s method can track anomalies in trading volumes at major Brazilian brokers and generate alerts to freeze suspicious funds before they move from the traditional financial market into the crypto ecosystem. Bitcoin News and CryptoNews.net agree that the system’s goal is to alert banks, exchanges, and sector associations in real time to threats linked to cryptoassets, trace subsequent transfers, and support a coordinated response.

CryptoNews.net adds that tests have already been carried out, some alerts were issued, and the next step is to expand integration with the Brazilian market, including redistribution of alerts through sector associations. Valor Econômico, for its part, reported that the Central Bank also made available a money-trail tracing tool for payment operations, capable of following subsequent transfers, identifying the different accounts the funds passed through, and alerting the responsible institutions so they can try to block balances.

Where does Pix fit into this tightening?

Pix is also under regulatory and operational scrutiny. A JusBrasil article says the system’s rules require risk management policies, stronger authentication, continuous transaction monitoring, and procedures to identify activity that does not match the user profile, based on the DICT Operational Manual and the Pix Regulation.

At the same time, Jornal Cruzeiro do Sul reported that the Central Bank is studying changes to Pix to strengthen security for overnight transactions, including a possible temporary block on amounts considered high in the recipient’s account for up to 72 hours to analyze potential fraud, although no minimum amount or time window has been defined yet.

Valor Econômico also noted that, over the past year, the Central Bank pushed through a regulatory adjustment with stricter cybersecurity requirements and higher capital levels for fintechs, amid debate over innovation and regulation.

According to Estadão, the Central Bank of Brazil also tightened security rules for participants in the financial system, with more controls over technology service providers, communication with the Rede do Sistema Financeiro Nacional, and especially the Pix and Reserve Transfer System environments. The measures mentioned include multifactor authentication, environment isolation, and stricter control over credentials and private keys.

Sources

View all