CiberLATAMbywhalemate
Intelligence report

Brazil Cybersecurity Snapshot, Aug. 2026

ANPD tightened penalties, Pix changed antifraud rules, and fraud, ransomware, and leaks rose with a focus on financial services

Sep 1, 202618 min read
Brazil Cybersecurity Snapshot, Aug. 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are completed automatically with verified dated facts within the period. Each one states its basis and counting criterion so the figures reconcile across modules. They are the recurring month-to-month reading; the analysis that follows develops the cases without repeating this summary.

Indicator window: 76 dated facts in August 2026 · 2 from previous months (comparison framework, not monthly volume). Facts from previous months are used only as a comparison framework in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Monthly verified signal dashboard August 2026 · Brazil Top threat: Unclassified (19 of 69 events). Coverage: 76 dated events in August 2026 · 2 months an… VERIFIED EVENTS 69 period base: total count measured from below on this total RANSOMWARE / EXTORTION 17 2 data exfiltration without encryption (simple extortion) · 2 only mentioned on leak site · 13 UNCLASSIFIED INCIDENTS 6 breaches or outages without declared threat type FRAUD / PHISHING 9 documented fraud campaigns documented REGULATION 11 rules, resolutions, or penalties UNIQUE CVEs 4 CVE-2019-1068 / CVE-2026-48907
Monthly verified signal dashboard — Base: 69 verified dated events in Brazil for the period.
FIXED MONTHLY MODULE Threat-axis distribution August 2026 · Brazil Each incident is counted in only one axis, so the total is exactly 69. "Unclassified incidents" is the remainder. Unclassified 19 Ransomware 17 Regulation 11 Fraud 9 Vulnerabilities 7 Incidents 6
Threat-axis distribution — Each incident is assigned to one axis based on its classification; the total reconciles to the 69 incidents in the period.
MONTHLY FIXED MODULE Sector breakdown of signal August 2026 · Brazil Base: 69 incidents in the period · total 82 because 10 incidents fall into more than one sector. Other / no sector ident… 33 Public sector / OIV 21 Technology 8 Finance 7 Education 4 Telecom 3 Health 3 Energy 3
Sector breakdown of signal — Heuristic sector classification by victim. One incident may affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Critical Infrastructure in Brazil August 2026 · Brazil 7 of 69 incidents during the period involve critical infrastructure. One incident may appear in more than one category. Public sector / government 21 Energy / utilities 3 Telecom / connectivity 3
Critical Infrastructure in Brazil — Verified incidents in public sector, energy, telecom, and essential services

Executive monthly summary for Brazil

August 2026 brought Brazil a mix of tougher regulation, data incidents in sensitive sectors, and sustained pressure from banking fraud, with ANPD, the Central Bank and the Federal Police at the center of the agenda. The month’s clearest signal was the R$ 153.7 million fine against ByteDance in the TikTok case, alongside new rules for Pix and virtual assets, while operational risk was concentrated in government, finance, health care and telecommunications.

The month closed with 69 verified events within the analysis window, 17 cases with ransomware or extortion as the primary focus, 9 documented fraud or phishing episodes, and 11 regulatory moves. The dominant threat was classified as unclassified, with 19 of 69 events, reflecting a mix of breaches, regulatory pressure, fraud campaigns and leak site activity without a single dominant pattern.

On the incident front, Brazil saw disclosures and claims of data breaches involving LATAM Pass, Mobilemed, SISVISA, Intranet Gov Brasil, Grupo Rái, ICN and city governments in Espírito Santo and Minas Gerais. Not all of them were confirmed with the same level of evidence, and in several cases the source only records the claim made by the actor or an aggregator, but the accumulation of signals pointed to a broad, cross-sector attack surface, with emphasis on digital services, health care, education and public administration.

The most consistent part of the month was the anti-fraud front. The Central Bank advanced a centralized fraud probability indicator for Pix, plus tracing of subsequent transfers, analysis windows for virtual assets and a 24-hour precautionary hold on certain crypto transactions. In parallel, the Federal Police dismantled banking fraud networks, and regulation kept adding compliance obligations for digital platforms and financial providers.

CVE and fraudPix in the spotlightSISVISAexposedOperationKlonenLatam PassnotifiesANPDANPD finesto TikTokMED 2.0 inPixPefisa and28 thousand keysVerified milestones for the month
Brazil, August 2026: monthly highlights — A concise timeline of the most relevant verified events in the period, focusing on regulation, fraud, incidents, and ransomware.

Monthly national overview in Brazil

Brazil showed high risk pressure in August, not from a single attack type, but from the overlap of fraud, ransomware, leaks, and tighter state controls. The alert level rose because of the number of verified events, the exposure of critical sectors, and the frequency of regulatory moves responding to an abuse environment that is already well established.

The qualitative reading remains high because severity was uneven but steady. There was a major data protection fine, a restructuring of the Pix and cryptoasset framework, a cross-border criminal investigation into bank fraud, and several incidents involving sensitive information in health care, transportation, government, and payment systems. At the same time, the month did not show one campaign that explains all the noise, but several active fronts in parallel.

The regional picture also helps explain the moment. Reports from Check Point, Exame, TI Inside, and Folha placed Brazil among the countries hardest hit by ransomware and with thousands of weekly attacks per organization, although those figures come from telemetry and not confirmed incidents. In that context, the country stands out as one of Latin America's main exposure hubs, with greater tension in finance, government, and digital services.

Sectors with the strongest presence in the materialFinanceGovernmentHealthTransportationTelecomEnergyOthermost exposed
Brazil, August 2026: sectors with documented incidents — Sector coverage map based on the seven sectors with at least one documented incident in the period.

Brazil period indicators

Indicator August 2026 value Previous month Change
Verified facts for the period (base for all indicators) 69 64 +5
Indicator time window 76 facts dated August 2026, 2 from previous months (comparison frame, not monthly volume) Same No change
Unclassified incidents (breaches or outages) 6 10 -4
Cases with ransomware or extortion as the primary focus 17 25 -8
Non-encrypted exfiltration (simple extortion) 2 Not reported N/A
Leak site mention only 2 Not reported N/A
Classification could not be determined from the material 13 Not reported N/A
Documented fraud or phishing cases 9 0 +9
Documented regulatory moves 11 13 -2
Critical CVEs mentioned 4 5 -1
Sectors with at least one documented fact 7 7 No change
Predominant threat of the month Unclassified (19 of 69 facts) Ransomware (25 of 64 facts) Shift in focus
Facts with direct source confirmation 81% Not reported N/A
Aggregated telemetry figures excluded from volume 7 aggregated attempts or blocks, not incidents with confirmed impact Not reported N/A

Relevant incidents in Brazil

ANPD fines ByteDance in the TikTok case

The ANPD fined ByteDance R$ 153.7 million and ordered the deletion of data collected improperly after finding irregularities in the handling of children’s and teenagers’ data. The case cemented the regulator’s role as a central player this month and renewed debate over age verification, platform design, and responsibility for minors’ data.

The penalty was based on five violations of the LGPD and came with specific corrective measures. Among them, the authority required the deletion of data from teenagers whose legal guardians do not regularize the situation within the deadline, and left open the possibility of administrative appeals. The case was also read as a sign of tougher enforcement against large-scale platforms.

LATAM Pass incident reported to the ANPD

LATAM confirmed an unauthorized access incident that affected a limited portion of LATAM Pass members and notified the ANPD. The company said it applied containment and additional cybersecurity measures, while media coverage detailed exposure of personal data, loyalty data and, according to some sources, partial card data.

The case stood out because of the type of data exposed and the potential volume of users, although the company itself kept the exact scope limited. It fit into a month in which sensitive data incidents received high public visibility, but did not all lead to major operational disruption.

SISVISA database exposure

A database linked to the SISVISA system left 102,215 records and about 79 GB of Brazilian health information exposed without authentication. The material included identifiers, tax data, regulatory documents, licensing records and other sensitive files, making it one of the month’s most significant healthcare leaks.

The exposure was discovered by a researcher and later removed from public access, but the lack of a clear official response left questions about how long the exposure lasted and whether third parties accessed it. It was a clear example of availability and confidentiality risk, with no signs of a sophisticated attack.

Attack on Itaguaí Construções Navais

ICN confirmed a ransomware attack that encrypted data in its IT environment. The company operates in the Itaguaí naval complex, and the episode was treated as a significant incident by the defense sector, with coverage linking the case to a possible LockBit 5.0 claim.

The available material shows operational impact through encryption, not just a mention on a leak site. However, the full scope of the intrusion and any exfiltration was not clearly documented, so the most cautious reading is that the event caused confirmed damage, but with only partial technical detail.

Pix instability and Central Bank response

On August 23, the Central Bank reported a temporary instability in Pix, ruled out a cyberattack, and said the service was quickly restored. Although there was no evidence of intrusion, the episode sharpened public attention on operational resilience and on dependence on the instant payments system.

At the same time, the regulator announced and explained a new defense layer for Pix, with a fraud probability score, standardized alerts, automated information sharing and expanded precautionary measures. From a risk perspective, the message was clear, fraud had become a top regulatory front.

Financial fraud and extortion campaign against TAG

TAG, a receivables registrar controlled by Stone, faced a fraud attempt involving about R$ 350 million in card payments. The operation was blocked and did not cause financial loss or data exposure, according to the company and later coverage.

The value of the case lies in the sophistication of the attempt, not in the damage it caused. The scheme included changes to receivables ownership and the use of sector alerts to stop the maneuver, which again shows that financial fraud in Brazil increasingly relies on coordination among platforms, registrars and shared monitoring mechanisms.

Operação Klonen and cross-border banking fraud

The Federal Police dismantled an organization tied to electronic banking fraud, money laundering and asset concealment, in an investigation that began with an attack on a German financial institution. The operation included arrest warrants and asset seizures, and showed the link between digital fraud, crypto assets and laundering structures.

The case matters because it goes beyond Brazil’s borders and shows how the country can serve both as the origin of the operation and as the place where judicial measures are carried out. It also confirms that banking fraud is not limited to social engineering, but can scale into transnational schemes with their own technical and financial infrastructure.

Active Threats and Campaigns in Brazil

Ransomware and simple extortion

There were 17 cases in August where ransomware or extortion was the primary focus, but the source only allowed a clear classification for a minority. In two cases, exfiltration without encryption was documented, in two there was only a mention on a leak site, and in 13 it was not possible to determine the exact impact from the available material.

That split matters because it prevents treating the whole block as if it were the same thing. A site listed by an actor is not the same as a data theft without encryption, or an attack with confirmed downtime. All three modes were present in Brazil, with preliminary signals outnumbering full confirmations.

Grupo Rái and LockBit 5.0

LockBit 5.0 claimed Grupo Rái in early August, and several aggregators showed it as data leaked or as a victim listed on a leak site. The recovered material did not allow a firm confirmation of operational damage, so the case should be read as an extortion claim with partial public evidence.

The significance of the case is not only the company targeted, but also LockBit 5.0's continued visibility in Brazil. This month's coverage again shows that the country remains among the markets most targeted by ransomware operators focused on data publication.

Mobilemed and Kazu

Mobilemed was claimed by Kazu as a victim in the health sector, with accounts that mention exfiltration and a ransom demand, but no official confirmation from the company. Some coverage describes it as an attack with possible broad impact on medical imaging and diagnostics, while other reports only repeat the actor's claim.

The taxonomy matters here. The available evidence supports describing it as a ransomware claim and, in some records, an alleged exfiltration, but not confirmed encryption. For the country report, that means keeping the case in the category of extortion with impact that cannot be verified in detail.

Intranet Gov Brasil and The Gentlemen

Intranet Gov Brasil was listed by The Gentlemen on leak sites and by incident aggregators as a claimed victim. There was no public confirmation from the federal government or from the state-owned companies mentioned in the material, so the case remains a leak site mention without corporate corroboration.

Even so, the claim matters because of the type of asset targeted, a portal and internal network for public services. The appearance of this name alongside other campaigns against municipal entities confirms that the government sector remained in the crosshairs of extortion groups throughout the month.

Fraud and phishing

The month showed a clear expansion in fraud, with nine documented cases and a strong bias toward banking, payments, and impersonation. The fake bank call center, social engineering against bank customers, deepfakes used for identity verification, and the TAG scheme point to the same abuse pattern, exploiting trust, urgency, and automation.

Fraud against crypto assets and payment methods also appeared, with the Central Bank accelerating controls to curb abuse of transfers and the PF disrupting electronic fraud networks. The operational takeaway is that attacks on identity and payment sessions carried more weight than classic intrusion.

APT, hacktivism and critical infrastructure

Brazil did not record a single local APT campaign in the material that dominated the month, but it was affected by the Lazarus context, the Siemens S7 advisory, and the debate over critical infrastructure. Added to that were disinformation lures and public-facing interface campaigns, such as the attempts against Rondônia portals and Flávio Bolsonaro's site.

In energy, water, government, and telecommunications, the risk was more closely tied to exposure and reconnaissance than to confirmed sabotage. The underlying threat was the combination of exposed attack surfaces, outdated critical software, and opportunistic campaigns seeking credentials, remote access, or public visibility.

Critical vulnerabilities with impact in Brazil

CVE Software Exploitation Source
CVE-2026-68820 Windows Ancillary Function Driver for WinSock (AFD.sys) Active exploitation, privilege escalation, used as a zero-day in observed campaigns CTIR Gov.br, Tenable, SecurityWeek
CVE-2026-8037 Progress LoadMaster Active real-world exploitation, command injection CTIR Gov.br, SecurityOnline.info, Decryption Digest
CVE-2026-34486 Apache Tomcat Active exploitation, exposure of sensitive traffic in Apache Tribes clusters CTIR Gov.br, CISA cited by f4n6 and Cybersecurity News
CVE-2026-48907 Joomla Content Editor (JCE) Active exploitation, web shells and persistence in institutional sites Mallory.ai and CTIR Gov.br

The month's vulnerability readout was limited, but significant. The material identified four critical CVEs, and all four show either active exploitation or direct operational impact. This does not mean there are no other relevant flaws outside the material, only that August's corpus prioritized these four as the verifiable signal.

Regulation and compliance in Brazil

Brazil tightened a regulatory agenda in August focused on data, fraud, and platform oversight. The clearest example was ANPD’s sanction against ByteDance, which showed the regulator is no longer limited to educational warnings and is willing to impose steep fines and specific data-deletion orders.

At the same time, the Central Bank moved ahead with Resolução BCB nº 584, which extends anti-fraud rules to virtual assets and sets a 24-hour precautionary hold for certain transfers. It also introduced authorization deadlines for virtual asset service providers, with a deadline of October 2026 and parts of the framework taking operational effect in January 2027.

In Pix, the regulator deepened its intervention with a centralized fraud-probability score, tracing of the money trail, and additional precautionary measures, including restricting new keys in cases of risk. This regulatory architecture is not cosmetic, because it responds to fraud already observed and to the need to coordinate banks, registries, and payment systems.

ANPD also kept expanding its compliance agenda. It published its semiannual report on the regulatory agenda, reviewed inspection and sanction rules, regulated transparency reporting, and maintained monitoring of platforms and AI tools to protect minors. In parallel, the Senate and the Chamber continued discussing texts on data protection, public security, and algorithmic transparency.

Most Affected Sectors in Brazil

The month hit at least seven sectors, but not evenly. Financial services were hit hardest in terms of both intensity and variety, with banking fraud, Pix, card payments, open finance, crypto assets, and police operations against money laundering networks. Government and public administration remained highly exposed, through both leaks and extortion campaigns and defacement.

Healthcare and pharmaceuticals also stood out. SISVISA, Mobilemed, and the Bahia case involving health data show that health information remains an attractive target, both for its regulatory sensitivity and its value in extortion. The logic is familiar, but the month confirmed that it remains active.

Telecommunications, logistics, and digital services added incidents or risk signals. LATAM, Uber Freight, Vivo, and various platform providers reflected a common pattern, dependence on identities, remote access, customer data, and third-party chains. The surface is fragmented, but the vector repeats.

In energy and utilities, the material did not show confirmed OT incidents in Brazil, but it did include alerts on critical infrastructure, campaigns against Siemens S7 PLCs, and references to sector-specific risk. That is enough to justify heightened vigilance, but not enough to make the vertical a focus of confirmed incidents for the month.

Compared with the previous month, ransomware as the primary focus fell from 25 cases to 17, and unclassified incidents dropped from 10 to 6. At the same time, documented fraud and phishing rose sharply from 0 to 9, while regulatory moves declined from 13 to 11. The main shift was qualitative, the month moved away from being dominated by ransomware and instead combined fraud, regulation, and leaks.

That shift matters because it points to a more diversified visible risk. In July, the narrative was more centered on system hijacking. In August, the agenda moved toward data protection, identity, payments, virtual assets, and platform oversight. Ransomware did not disappear, but it lost relative centrality to other vectors.

Another clear signal is the consolidation of fraud as a cross-cutting problem. The mix of social engineering, deepfakes, fake portals, mule accounts, and attacks on registrars points to a more professional criminal ecosystem. The Central Bank and the PF responded with tougher tools, which will likely drive more behavioral controls and traceability.

On vulnerabilities, the month showed fewer critical CVEs mentioned than in July, from 5 to 4, but each carried real operational weight. The repeated presence of active exploitation and urgent patches in widely used software indicates that technical risk remains heavily concentrated in edge products, web platforms, and identity and access components.

Security recommendations for teams in Brazil

Five priorities stand out. First, banks, fintechs, and PSPs should review anti-fraud controls in Pix, identity checks, transfer monitoring, and detection of account ownership changes or mule accounts. The month showed that fraud is shifting toward automated, coordinated flows, not just isolated scams.

Second, organizations that handle sensitive data, especially in health, education, and government, should strengthen segmentation, backups, and public exposure controls. The SISVISA, Mobilemed, and municipal portal cases show that leak exposure does not depend only on ransomware, but also on weak configurations and accessible repositories.

Third, patch prioritization should be reviewed for the month’s four critical CVEs, with special focus on products exposed to the internet. Apache Tomcat, LoadMaster, Windows AFD, and JCE concentrate the type of exploitation that turns into a real incident fastest when exposure is public.

Fourth, compliance teams should treat the new regulatory wave as a security issue, not only a legal one. ANPD and the Central Bank are pushing controls on transparency, retention, traceability, consent, and reporting, so privacy, fraud, and cybersecurity now operate as one management block.

Fifth, the third-party chain should be reviewed. Several stories this month relied on vendors, registrars, cloud platforms, loyalty services, and third-party software, which makes it necessary to audit access, contracts, logging, and shared response capacity.

FAQ

What changed most between July and August in Brazil: ransomware, fraud, or regulation?

In August, ransomware lost relative weight compared with July, while fraud and phishing cases increased and the number of regulatory moves edged down slightly. The clearest shift was toward payments, identity, and personal data, which becomes clear when the period indicators are read alongside the trends section.

Which sector was most exposed based on confirmed incidents, and why?

The financial sector was the most exposed by the variety of events, followed by government and health. The combination of TAG, Pix, cryptocurrencies, Operação Klonen, LATAM Pass, SISVISA, and Mobilemed shows that pressure came from several fronts, not a single vector, and those fronts touched payments, identity, and sensitive data.

Do the 4 critical CVEs for the month mean there were four incidents in Brazil?

No. They mean that four critical vulnerabilities were mentioned in the material analyzed, several of them with active exploitation, but not that each one produced a separate Brazilian incident. The vulnerabilities table and the limitations section make clear that the absence of more CVEs in the month does not mean there was no regional exposure.

How confirmed was the Intranet Gov Brasil case?

It remained a leak site claim without public confirmation from the Brazilian government or the technical entities cited. That sets it apart from ICN, where an attack with encryption was confirmed, and from other cases where the material allows only a preliminary attribution.

What was the main regulatory signal for banks and fintechs?

The main signal was the tightening of oversight on fraud, Pix, and virtual assets. The Central Bank advanced on fraud probability scoring, money tracing, and precautionary crypto retention, while ANPD kept hardening sanctions and transparency. The two agendas appear separately in the body, but they converge in operational compliance.

Was there activity in Brazilian critical infrastructure without confirmed OT incidents?

Yes. There were alerts and signs of exposure, especially in energy, water, and industrial control, but no confirmed Brazilian OT incident appeared in the material. The risk was documented through international advisories and local coverage, so monitoring must continue even though the month did not register a completed OT operational impact.

Material limitations

This report was built exclusively from the material provided for Brazil in August 2026. The time window for the indicators includes 76 dated events in August 2026 and 2 events from prior months used only as a comparative frame, not as part of the month's volume. No internet or external material was used.

The table indicators are reproduced exactly as provided and describe what happened in the country, not the research process. A zero value, especially for CVEs or comparative categories, means that element did not appear in the material analyzed for the period, not that it did not exist in Brazil or the region.

Aggregated telemetry figures, such as attack attempts, blocks, scans, and weekly vendor averages, were also excluded from the count because they are not incidents with confirmed impact. When those figures are mentioned in the report, they are used only as context and always with the source and measurement window identified.

Primary sources were prioritized, including official agencies, CSIRTs, technical advisories from affected vendors, and regulatory statements. Promotional, sponsored, or low-verifiability sources were excluded from the main narrative as a sole basis for trend analysis, and undated events were not included in the counts. When a story depended only on a leak site or an aggregator, it was treated as an unconfirmed claim.

Sources