LATAM Pass exposed member data in Brazil
LATAM confirmed a LATAM Pass incident in Brazil that exposed member data. The company said it contained the event and notified Brazil’s ANPD.
LATAM confirmed a security incident that affected a limited number of LATAM Pass members in Brazil. The company said it detected the event on July 29, 2026, notified Brazil’s ANPD, and applied containment and cybersecurity measures.
LATAM confirmed a security incident affecting a limited number of LATAM Pass members in Brazil. The company said it detected the event on July 29, 2026, notified Brazil’s ANPD, and applied containment and cybersecurity measures, as the case once again drew attention to digital fraud and identity theft in the region.
What data was exposed?
According to the information disclosed, the incident exposed names, dates of birth, email addresses, phone numbers, home addresses, loyalty account data, and some payment card information. Full card numbers, CVV codes, and passwords were not disclosed.
That distinction matters because the incident did not involve a complete card data leak, but it did leave information exposed that could be used to enable other forms of abuse. TechTimes also noted that the case creates a risk of fraud beyond the mention of partial card data.
How does it fit into regional digital fraud?
The case comes at a time when several sources describe an increase in digital fraud across Latin America, with phishing, bank impersonation, and account takeover among the most common methods.
In Central America, BioCatch described a multistage fraud chain that starts with data exposure or capture, continues with credential compromise, and can end in account takeover, authorized payment fraud, and fund dispersion through mule accounts. The attack logic is similar to what financial institutions in Panama, Costa Rica, and Guatemala are seeing.
In Colombia, a media report cited the DIJIN and said that in 2026 authorities had blocked 400 websites impersonating financial institutions and arrested 205 people linked to that crime. Deloitte, in a regional analysis, said cybersecurity in payments has shifted focus toward protecting customers and the digital business ecosystem.
That backdrop helps frame the LATAM Pass case as part of a broader attack surface, where personal and loyalty data can be used later for fraud, impersonation, or attempts to access accounts.
Sources
- La ciberseguridad en pagos cambió de objetivodeloitte.com· Deloitte LATAM
- LATAM Pass sofre invasão cibernética e expõe dados de clientestecmundo.com.br· TecMundo
- Últimas Notícias - AM PM Segurosampmseguros.com.br· AM PM Seguros
- Estas son las tarjetas que enfrentan mayor riesgo en compras onlinemsn.com· MSN Chile
- The fraud landscape in Central America: From credential theft to scamsbiocatch.com· BioCatch
- Alerta por ciberestafas en Colombia: así robaron 11 millones de pesos con un portal falsobluradio.com· Blu Radio
- Latam Pass Data Breach: Exposed BIN Data Creates Fraud Risk Beyond Partial Card Claimstechtimes.com· TechTimes



