CiberLATAMbywhalemate
Intelligence report

Brazil: Cybersecurity Situation, September 2026

Brazil ended September with more incidents, ransomware, and AI-enabled fraud; the focus was judicial

Oct 1, 202618 min read
Brazil: Cybersecurity Situation, September 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Reference monthly modules

These modules are completed automatically using verified dated facts within the period. Each one states its source basis and counting method so the figures reconcile across modules. They are the recurring month-to-month readout, and the analysis that follows expands on the cases without repeating this summary.

Indicator window: 76 dated facts in September 2026 · 1 from prior months (comparative context, not monthly volume) · 2 without confirmed dates (excluded from the indicators). Facts from prior months are used only as comparative context in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified signal monthly dashboard September 2026 · Brazil Main threat: Incidents (21 of 73 events). Coverage: 76 dated events in September 2026 · 1 of months an… VERIFIED EVENTS 73 period base: all counts the scale below is measured against this total RANSOMWARE / EXTORTION 15 1 asset encryption confirmed · 3 only mentioned in leak site · 11 unclassified UNCLASSIFIED INCIDENTS 21 breaches or outages without declared threat type FRAUD / PHISHING 6 documented fraud campaigns REGULATIONS 7 rules, resolutions, or sanctions UNIQUE CVEs 6 CVE-2026-20079 / CVE-2026-62911
Verified signal monthly dashboard — Base: 73 verified dated events in the period for Brazil.
MONTHLY FIXED MODULE Threat axis distribution September 2026 · Brazil Each event counts under only one axis, so the total is exactly 73. "Unclassified incidents" is the remainder. Incidents 21 Unclassified 18 Ransomware 15 Regulation 7 Fraud 6 Vulnerabilities 6
Threat axis distribution — Each event is assigned to a single axis based on its classification; the total reconciles to the 73 events in the period.
MONTHLY FIXED MODULE Sectoral Distribution of Signals September 2026 · Brazil Base: 73 incidents in the period · total 87 because 12 incidents are classified in more than one sector. Other / no identifiable sector… 26 Public sector / OIV 23 Telecom 13 Technology 9 Retail / Consumer 6 Finance 5 Energy 3 Healthcare 2
Sectoral Distribution of Signals — Heuristic classification by victim sector. One incident may affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Critical infrastructure in Brazil September 2026 · Brazil 4 of 73 events during the period affect critical infrastructure. One event may appear in more than one category. Public sector / government 23 Telecom / connectivity 12
Critical infrastructure in Brazil — Verified incidents in the public sector, energy, telecom, and essential services

Executive summary for the month in Brazil

Brazil closed September 2026 with a mix of operational incidents, extortion campaigns, AI-supported fraud, and tighter regulation that reshaped priorities across the financial system and data protection. Across 73 verified events during the period, incidents were the main focus, with 21 cases, followed by 15 episodes where ransomware or extortion was the primary theme, 6 documented fraud or phishing cases, 7 regulatory moves, and 6 critical CVEs mentioned.

The month produced two high-impact breaches or disruptions in the judicial public sector. The Mato Grosso Court of Justice suspended deadlines, hearings, and sessions after taking its systems offline because of a security incident, with credential access and password resets. At the same time, BRBJUS, the platform used for judicial deposits in Bahia, suffered an outage that led to a reported diversion of R$ 43 million and forced partial, then full restoration, with additional controls and an ongoing review.

On the financial front, the Central Bank issued BCB Resolutions 587, 588, and 589, which strengthened how fraud flags are handled in Pix, expanded reporting to Coaf on transfers involving self-custodied wallets, and set restrictions for dealing with unauthorized counterparties. The regulatory tightening unfolded alongside a wave of increasingly synthetic digital fraud, with deepfakes, voice cloning, and credential theft fueling campaigns against banks, e-commerce operations, and payment systems.

The risk picture for Brazil this month is high. Not because of a single large cross-sector intrusion, but because of the accumulation of confirmed incidents in justice, finance, transport, and health, along with active exploitation of critical vulnerabilities and a fraud surface that keeps expanding. The material also shows sustained pressure on technology vendors, digital platforms, and agencies handling sensitive data, with the public and financial sectors absorbing much of the impact.

Sep 01CVE and PixSep 08 SEO.gov.brSep 10KEV alertsSep 18 PixtightensSep 23BRBJUSSep 28 NewCVEsSeptember 2026Key events: regulation, incidents, extortion, and active exploitation
Brazil, September 2026: operational and regulatory milestones — Brief timeline of incidents, regulation, and critical vulnerabilities in Brazil during September 2026.

National snapshot for the month in Brazil

Brazil saw an unusual concentration of operational and extortion incidents in September, with direct impact on sensitive services, while the financial regulator and the data authority continued closing regulatory gaps. The dominant trend was incidents, not informational noise. Judicial systems went offline, a court deposits platform was affected, a transport incident potentially exposed data, and a sustained wave of financial fraud and synthetic identity abuse continued.

The severity observed can be explained by three tracks moving in parallel. First was the operational track, with TJMT and BRBJUS as the most visible cases. Second was the fraud track, where Pix, e-commerce and facial biometrics concentrated identity abuse, altered QR codes and unauthorized payments. Third was the institutional track, with ANPD expanding oversight and the Central Bank rewriting rules for virtual assets and the Pix arrangement.

The regional signal was also intense. Brazil continued to appear as the main Latin American target in several reports, both for attack volume and for the centrality of its financial system and public agencies. In that context, the month exposed not only concrete victims, but a pattern of sustained pressure on critical infrastructure, personal data and payment channels.

The comparison with the previous month reinforces that reading. Unclassified incidents increased, documented fraud and phishing declined, and regulatory moves were reduced, but the number of critical CVEs mentioned went up. That shift does not point to less risk, but to a rebalancing, more operational impact and more technical exposure within the same monthly window.

Period indicators in Brazil

Indicator September 2026 August 2026 Change
Verified events in the period 73 69 +4
Time window for the indicators 76 events dated in September 2026 1 from prior months, 2 without confirmed date Comparative frame, not monthly volume
Uncategorized incidents, breaches or outages 21 6 +15
Cases with ransomware or extortion as the primary focus 15 17 -2
Confirmed asset encryption 1 n/a n/a
Leak site mention only 3 n/a n/a
Unclear classification based on available material 11 n/a n/a
Documented fraud or phishing cases 6 9 -3
Documented regulatory actions 7 11 -4
Critical CVEs mentioned 6 4 +2
Sectors with at least one documented event 7 7 No change
Predominant threat of the month Incidents (21 of 73 events) Unclassified (19 of 69 events) Change in dominance
Events with direct source confirmation 74% n/a n/a
Aggregated telemetry figures excluded from the volume 3 n/a Not incidents with confirmed impact
Signal by sectorThe visualization is qualitative, based on the frequency of verified events this monthPublic sectorFinancial sectorRegulationTransportation and healthMore incidents and breachesFraud, Pix, deepfakesPix, crypto, ANPDÁguia Branca, CAPES
Brazil, September 2026: sectors with the strongest signal — Qualitative distribution of the verified signal by sector based on this month’s material, with events that may affect more than one sector.

Relevant incidents in Brazil

Mato Grosso Court, system outage and credential breach

The Tribunal de Justiça de Mato Grosso was the clearest case of operational disruption in Brazil’s public sector this month. The court took its systems offline, suspended procedural deadlines, hearings, and trial sessions, and later confirmed that user network credentials had been accessed during the incident. Recovery was gradual, with password resets and technical testing before a partial return.

The available material does not allow the initial vector to be identified precisely, but it does show that the impact was real and sustained. The outage affected Processo Judicial Eletrônico and other institutional systems, and the court ultimately brought in the Federal Police and the Civil Police. Operationally, the case fits as a breach with confirmed service disruption.

BRBJUS and Banco de Brasília, fund diversion in court deposits

The second most significant incident affected BRBJUS, the platform used to manage judicial deposits in Bahia. Available coverage reported a diversion of R$ 43 million and partial, then full, service unavailability, with staggered restorations and additional controls. The TJBA clarified that the affected environment was external to the court and administered by BRB.

Here, the material does allow for both financial and operational impact. The issue was not limited to an extortion claim or a mention on a leak site, but to a service outage with concrete consequences for judicial deposits. The subsequent coordination between the court and the bank to restore the environment was also documented.

Viação Águia Branca, ticketing incident

Viação Águia Branca reported a cybersecurity incident on its official ticket sales sites and said 7.883 customers may have had their data exposed. The company said the issue was contained the same day, did not affect the app or the Zap Passagens channel, and did not alter issued tickets or travel data.

The case falls into the category of a limited breach, although with reputational and compliance impact. The material does not confirm exfiltration or specific techniques, but it does confirm notice to the ANPD and individual communication to potentially affected users.

CAPES, unauthorized access to the Meus Dados Platform

CAPES confirmed a security incident on the Plataforma Meus Dados that allowed unauthorized access to personal data available in the system. The technical investigation was still ongoing, but the agency identified CPF, email address, phone number, and banking data as potentially accessible, while restricting the affected functionality and strengthening monitoring.

This incident matters because it combines data exposure with a formal institutional response. The material does not include an external attribution for the attack or an exact number of affected users, but it does include a clear breach notification and containment measures, making it material for the monthly public sector tally.

Court of Justice of Bahia, partial restorations of BRBJUS

The BRBJUS sequence should be seen both as an incident and as a recovery process. The court reported an initial outage, then a partial restoration with functions such as guide registration and balance inquiries, and finally the full return of the system with electronic payment of alvarás. At all times, it stressed that the incident occurred in an external technology environment.

That timeline shows a pattern repeated in Brazil when a critical platform fails, containment, testing, staged restoration, and a review of contractual or technical governance. The case did not only affect judicial deposits, it also exposed public service dependence on third party managed infrastructure.

Active Threats and Campaigns in Brazil

Ransomware and Extortion in Brazil

Ransomware and extortion activity in Brazil remained high, but this month’s material shows a mix of confirmed encryption, leaks, and unverified claims. The only case with confirmed asset encryption in the period’s reporting was the one involving judicial and service incidents, while most other events stayed at the level of group claims or leak site listings without complete independent proof.

Among the cases mentioned only on leak sites are K3G Solutions Brazil, Camorim Serviços Marítimos, and Receita Federal, each with different degrees of verification and with the caveat that the source does not always specify whether encryption occurred. In the K3G Solutions case, for example, the material refers to a publication threat and estimated exfiltration, but not to encryption confirmed by the victim.

There were also extortion incidents targeting manufacturing, technology, transportation, and education organizations, but in several cases the public evidence was limited to trackers or aggregators. For this report, that points to clear extortion pressure, but not to a uniform tally of technical impact.

Case Impact type Status in the material
K3G Solutions Brazil, Panzer Exfiltration and extortion, the source does not specify whether encryption occurred Claim and tracking on a leak site, with no public confirmation from the company
Receita Federal do Brasil, Emperador Leak site mention only, with a data claim No official confirmation of intrusion
Camorim Serviços Marítimos, LockBit 5.0 Leak site mention only, with a disclosure threat Group claim, without independent validation
Vexy targeting Brazilian manufacturing Data-broker style extortion Tracker entry, with no public impact details

Fraud, Phishing, and Synthetic Identity in Brazil

Fraud was one of the densest threat areas of the month, especially across the financial system. Pix drew multiple signals, from altered QR codes and copy-paste codes in online stores to new Central Bank rules for flagging suspicious CPFs and CNPJs, rejecting associated transactions, and notifying the user. At the same time, the courts and police continued documenting schemes built around stolen credentials, fake sites, and identity impersonation.

The clearest development was the consolidation of deepfakes and voice cloning as fraud tools. The material cites the theft of R$ 80 mil through facial recognition fooled by AI, campaigns that already account for 1 in every 15 fraud cases detected in Brazil in 2026, and estimated losses of R$ 1,8 mil millones between July 2025 and April 2026. That places synthetic identity among the top operational and financial risks.

There were also more traditional phishing campaigns, but more coordinated ones. The fake exam case for the police, which used the Cebraspe brand to carry out fraudulent Pix payments, shows a mix of social engineering, institutional impersonation, and abuse of trust in APIs or automated checks.

APT, AI-Assisted Intrusion, and Hacktivism in Brazil

There was no major classic state APT case in the September material, but there were several campaigns with persistent intrusion traits, automated tooling, and impact on public infrastructure. The most visible was the SEO poisoning operation against .gov.br domains, attributed to a Chinese-speaking actor, which compromised public servers and used search authority to redirect traffic to gambling and phishing.

In parallel, Unit 42, Cloud Security Alliance, and other sources described campaigns in Latin America with AI support, tunneling, custom RATs, and SOCKS5 proxies, with a financial focus in Brazil. Case CL-CRI-1163, in particular, involved phishing with a resume attachment, RATs, and SockTz to create a reverse SOCKS5 proxy. The material does not frame it as a state APT, but it does present it as organized and sustained intrusion.

There were also signs of hacktivism or broader abuse of public infrastructure. The Gambling Goblin campaign against .gov.br sites did not seek espionage or encryption, but rather reputation manipulation and monetization through gambling, with direct impact on Brazil’s public attack surface.

Critical vulnerabilities affecting Brazil

CVE Software Exploitation Source
CVE-2026-20079 Cisco Secure Firewall Management Center and Security Cloud Control Firewall Management CTIR Gov reported it as critical and listed in CISA KEV CTIR Gov, Alert 81/2026
CVE-2026-62911 Microsoft Exchange Server 2016, 2019 and Subscription Edition Authentication bypass through credential capture and replay CTIR Gov, Recommendation 15/2026
CVE-2026-85706 GitLab Community Edition and Enterprise Edition self-managed Arbitrary file read, active exploitation and use in ransomware attacks ITShow, Censys, Rapid7
CVE-2026-76460 Cisco Identity Services Engine Vulnerability with potential impact on confidentiality, integrity or availability, listed in KEV CTIR Gov, Alert 87/2026
CVE-2026-85880 Microsoft Windows 10 1607, 1809, 21H2 and 22H2 Issue listed in KEV with recommendation for immediate patching CTIR Gov, Alert 84/2026
CVE-2026-93616 Multiple products, not specified in the excerpt Critical vulnerability included in KEV CTIR Gov, Alert 89/2026

September’s technical pattern was clear, nearly all of the critical issues arrived with active exploitation or inclusion in KEV. That makes patching priority in Brazil depend not only on theoretical severity, but on real exposure and the presence of infrastructure with exposed edge systems, cloud identity, remote access or collaboration and commerce software.

Regulation and compliance in Brazil

Brazil had an intense regulatory agenda in September, with two main fronts, virtual assets and oversight of digital platforms. The Central Bank issued Resolutions BCB 587, 588 and 589, which tightened the regime for Pix, reporting to Coaf, and the relationship with unauthorized virtual asset providers. Implementation was also phased, with some provisions taking effect in October 2026 and others slated for 2027.

The most visible regulatory effect was on fraud and traceability. The new rules allow suspicious CPFs or CNPJs to be flagged, related transactions to be rejected, and participants to be required to retain the grounds and notify the user. At the same time, automatic reporting was expanded for transfers involving self-custodied wallets, and restrictions advanced for institutions that operate with unauthorized counterparties.

ANPD also made moves. It opened a public consultation on the oversight rule and the administrative sanctioning process, called a public hearing, and continued applying measures to platforms such as Discord. The Digital ECA framework sits in the background, because the data authority is already acting on services and platforms with likely impacts on minors and data protection.

Measure Authority Operational scope Date or effective date
Resolution BCB 587 Central Bank Fraud suspicion flag, review, notification and participant liability September 2026, with blocks effective from 18/09/2026, February 2027 and July 2027
Resolution BCB 588 Central Bank Reporting to Coaf of self-custody transfers from US$ 10,000 In force since 1/10/2026, with specific supervisory effects from 1/1/2027
Resolution BCB 589 Central Bank Restriction on operating with unauthorized counterparties and new reporting obligations In force since 1/10/2026, with later milestones in November 2026 and January 2027
ANPD public consultation ANPD Review of the oversight process and sanctioning process Open during September 2026
ANPD oversight of Discord ANPD Requirement for explanations over alleged noncompliance with suspension 21/09/2026

The compliance reading is that Brazil is pushing regulated entities toward greater traceability, documentation of decisions and faster incident response. That applies to banks, fintechs, exchanges, digital platforms and, increasingly, public agencies with exposed services.

Most affected sectors in Brazil

The public sector felt the biggest impact this month in terms of disruption and exposure. Justice, federal agencies, data platforms, and bodies with shared infrastructure concentrated the most sensitive incidents. The issue was not just the number of events, but their ability to suspend deadlines, block hearings, take systems offline, or expose credentials and personal data.

The financial sector remained a structural target, driven by both fraud and technical exploitation. Pix, banks, fintechs, BRB, BRBJUS, and the deepfake cases show that money remains the strongest incentive and the fastest extraction channel. Regulatory pressure also fell on that ecosystem, a sign that the regulator sees sustained tension between innovation, availability, and fraud control.

Transport and logistics saw fewer cases, but they were no less relevant. Águia Branca showed that an incident in the sales channel is enough to trigger notification, containment, and access review. In health care, the picture was more about operational continuity and extortion than mass exposure, although Brazil's history in the sector and the mention of incidents at clinics and hospitals point to a persistent attack surface.

Compared with August, September saw a sharp rise in unclassified incidents, a drop in documented fraud or phishing, and fewer regulatory moves, but more critical CVEs were cited. That mix suggests September was not a lower-risk month, but one with more operational and technical activity materializing in specific verticals.

The leading threat shifted from "unclassified" in August to "incidents" in September. That change matters because it points to more events with verifiable impact and less noise from complaints that were not categorized. Put another way, the September material makes it easier to see where the risk is hitting, even if it does not mean the ecosystem is any less hostile.

Two signals are still worth tracking. The first is the convergence of financial fraud and synthetic identity, which no longer appears as a lab-side trend but as behavior embedded in real campaigns. The second is the link between exploitation of critical CVEs and exposure of edge, identity, and collaboration services, a pattern that could keep affecting government, telecom, and the financial sector.

At the regional level, Brazil remains the main threat pressure point in Latin America. That does not mean everything is happening in Brazil, but rather that a disproportionate share of activity, especially financial and extortion-related activity, continues to concentrate there.

Recommendations for security teams in Brazil

  1. Prioritize identity and access containment in judicial, financial, and government systems. If credentials were accessed or services became unavailable, the immediate focus should be reset, revocation, traceability, and session monitoring.

  2. Review fraud rules in payment channels, especially Pix, QR, and transfers with strengthened authentication. This month’s material shows abuse of suspicion labels, fake accounts, voice cloning, and manipulation of receipts and payment confirmations.

  3. Accelerate patching for the critical CVEs listed by CTIR Gov and for vulnerabilities with confirmed active exploitation in KEV. The most exposed surfaces are email, firewalls, remote access, collaboration tools, and self-managed software.

  4. Review third-party exposure and the governance of external platforms. The BRBJUS and Águia Branca cases show that dependence on vendors or outside environments can turn a technical outage into an operational and reputational incident.

  5. Strengthen fraud detection with non-biometric signals. This month made it clear that facial biometrics alone are not enough against deepfakes, face swaps, and voice cloning.

  6. Keep notification and evidence procedures ready for ANPD, the Central Bank, and sector authorities. The cost of delay is no longer only reputational, it can also become a regulatory compliance issue.

  7. Validate SEO poisoning controls, web hardening, and integrity monitoring on public or high-reputation sites. The campaign against .gov.br showed that a compromised site can be used as distribution and monetization infrastructure.

Frequently Asked Questions

What September clash tied justice, fraud, and operational continuity in Brazil?

The month linked two areas often analyzed separately, service disruption and financial fraud. The TJMT lost availability and credentials, while BRBJUS suffered downtime and funds diversion. Both cases show that a technical breach in Brazil can end up affecting court processes and money at the same time.

How are the Central Bank's new rules connected to Pix scams and deepfakes?

The Central Bank's new resolutions focus on suspicious markers, CPF and CNPJ traceability, and tighter controls over transfers involving self-custody. They respond to fraud that already uses deepfakes, voice cloning, altered QR codes, and stolen credentials, so regulation and technical controls are now aligned on the same front.

The critical vulnerabilities affected the very surfaces most often seen in Brazilian incidents: email, remote access, identity, collaboration, and exposed public services. The clearest case was GitLab, with active exploitation, while CTIR Gov prioritized Cisco and Microsoft flaws that could affect government, finance, and critical operations.

Why does the report separate ransomware, extortion, and simple mention on a leak site?

Because they are not the same. In September there was one case with confirmed operational impact, several extortion claims, and several mentions on leak sites without public confirmation. Treating them as one would erase important differences for a CISO, especially when the source does not specify whether there was encryption or only the posting of the claim.

Which sectors should keep the closest watch on the compliance agenda?

Finance, the public sector, and digital platforms should keep the closest watch. The Central Bank tightened Pix and controls over virtual assets, while the ANPD expanded oversight of platforms and imposed measures on services affecting minors. That requires banks, fintechs, exchanges, and agencies handling sensitive data to coordinate legal, security, and operations teams.

Material limitations

This report was built exclusively from the material provided for September 2026 and from facts dated within that window. Facts from earlier months were used only as comparative context when the material allowed it, and any facts without a confirmed date were left out of the period indicators, although they may have been cited as qualitative context.

A zero value or an absence in the table does not mean the event did not occur in Brazil or in the region, only that it did not appear in the material analyzed for this month or could not be confirmed with the available evidence. This is especially important for CVEs, because the count reflects only what was recorded in the corpus, not the full set of vulnerabilities exploited in the country.

Aggregated telemetry on attempts, blocks or weekly vendor averages was excluded from the incident volume and can only be mentioned as background internet noise, not as confirmed impact. Promotional material, advertorials and some commercial releases were also left out as counting inputs, although they could still serve as context if corroborated by stronger sources.

Finally, the regulatory section includes decisions, consultations and rulings that fell within the time window, but it does not assume that every secondary press claim is equivalent to a rule already published. When the material did not allow us to determine whether there was encryption, exfiltration or only a claim on a leak site, that limitation was stated explicitly rather than forcing a classification.

Sources