🇧🇷 Brazil: Alleged BACEN Data Leak Advertised on Underground Forum
A threat actor is advertising what they claim to be a 2026 dataset associated with BACEN (Banco Central do Brasil), Brazil's Central Bank.
* The post references multiple database tables, including:
* pessoas_juridicas_ctf
* vw_bacen_mutuarios
* vw_bacen_propriedade
* According to the advertisement, one of the datasets contains more than 1.4 million records.
* Sample records shown in the post appear to include:
* Corporate identifiers (CNPJ)
* Company names (Razão Social)
* Business classification data
* Geographic information
* Property and ownership-related records
* Borrower and financial relationship information
* The actor claims to possess structured database exports and provides example records as proof of access.
* At the time of reporting, the authenticity of the dataset and any direct connection to BACEN infrastructure have not been independently verified.
* If validated, the exposure could affect organizations, financial institutions, and entities whose information is maintained within Brazil's financial ecosystem.
Analyst Note:
Because BACEN plays a central role in Brazil's banking and financial infrastructure, any confirmed compromise involving regulatory, borrower, ownership, or corporate datasets would be of significant interest to cybercriminals, fraud actors, and financial intelligence analysts. Claims involving central bank data should be treated with caution until independently verified.
#DDW #Intelligence #DarkWeb #Brazil
@MJamille Estava ouvindo um podcast hoje sobre perícia criminal em obras de artes e itens De patrimônio Históricos pela PF. É bastante comum haver fraude nos próprio leilão e também só a perícia vai afirmar se é falso ou não, se corresponde ao periodo ou é de outro, analise de material..
Crunchyroll fez o meio de pagamento em vibecode, não é possível. Todo mês bloqueia porque não consegue debitar e qualquer cartão que você ponha da erro. Depois reclamam da pirataria
🚨 STATE OF CYBER-INSECURITY: BRAZIL 2026 🇧🇷
The cybersecurity landscape in Brazil reached critical levels during the first four months of 2026. Government and financial infrastructure are under constant siege.
👥 TOP THREAT ACTORS (Active April 2026)
👑 wh6ami | 7 Incidents (Targeting Gov infrastructure) 🇧🇷
⚡ ByteToBreach | 3 Incidents (Data extraction expert)
🐱 Spirigatito | 3 Incidents (Government focus)
🛠️ m0z1ll4s | 2 Incidents (Banking & Telecom)
💀 Buddha | 2 Incidents (Massive citizen databases)
📊 Key Statistics (January - April 2026)
SMTP Black Market: 1,752 Brazilian corporate email accounts have been identified for sale, intended for phishing and ransomware campaigns.
Compromised Credentials: A total of 3,528 high-profile credentials have been distributed across hacking forums from 2023 to date (April 2026).
Data Volume: Massive leaks exceeding 15.4 TB of sensitive information during this period alone.
📅 TIMELINE: CRITICAL APRIL LEAKS 🇧🇷
Apr 26: 🏦 Banking Sector: 2.3M records exposed (RubiconH4ck).
Apr 26: 📱 Telecom (Oi): Breach at https://t.co/qwNx2ark6B (m0z1ll4s).
Apr 19: 🗺️ Pernambuco DB: Data on 9 million inhabitants leaked.
Apr 18: 📮 Correios (ECT): Massive leak of blueprints and financial records.
Apr 13: 📂 Data Dump: 15.4 TB of miscellaneous Brazilian databases.
Apr 09: 🛡️ Serasa: 223M citizens exposed (1.8 TB full dump).
📈 Timeline and Trends
Activity shows exponential growth. While the average in March was one post per day, during the second half of April, the frequency has risen to 3–4 major incidents daily, primarily affecting .gov.br portals.
⚙️ METHODOLOGY: HOW ARE THEY GAINING ACCESS? 🔍
An analysis of incidents in 2026 reveals three predominant attack vectors:
Infostealer Log Abuse ☣️
The sale of 1,752 Brazilian corporate email accounts on illicit SMTP marketplaces is no coincidence. Attackers are purchasing "logs" (active sessions and credentials) obtained from malware such as RedLine or Lumma to bypass MFA and access internal networks without raising suspicion.
Exploitation of Basic Vulnerabilities 🔓
Many of the 3,528 credentials distributed since 2023 stem from a lack of patching on exposed services (VPNs, RDP). Threat actors are reusing compromised passwords (Credential Stuffing) on systems that have not rotated their keys in years.
API Vulnerabilities (IDOR) 🔗
Widespread exploitation of IDOR (Insecure Direct Object Reference) flaws has been detected. Attackers manipulate identifiers within the APIs of government portals and financial applications to exfiltrate records belonging to other users en masse, without requiring administrative privileges.
#CyberSecurity #ThreatIntel #Brazil #DataBreach #InfoSec #CyberCrime
🚨 BREAKING: The FBI has successfully extracted deleted Signal messages from a suspect's iPhone via notification storage, the place where all your notifications are stored for up to one month.
Notification storage stores data from all messaging apps, it's a big flaw in iOS. But there's a way to turn it off...
@sushicomabacate Fazem 3 anos que cibersegurança se tornou obrigatório pela Anel e mesmo assim, até hoje discutem de quem é o custo e o investimento fica parado
@FellerMarcelo Existem vários tipos de feminicídio,e não precisa ter relação de afeto, ajudar ser o mais comum. O que configura feminicídio é a morte da mulher em razão dela ser mulher. Independente da relação entre o homicida e a vítima.
Se eu fosse a @MotorolaBR@Moto eu transformaria o motorola Razr em uma câmera de ação, adicionando uma estabilização de video e uma resistência melhor ou case decente, para brigar num mercado com a DJI e GoPro. O tamanho é o mesmo e unifica os devices
Foi sancionada a Lei 15.352, de 2026, que institui a Agência Nacional de Proteção de Dados (ANPD). Entre as atribuições da nova Agência está a regulamentação do Estatuto Digital da Criança e do Adolescente (ECA Digital). https://t.co/v6z90XNrcc
The Gentlemen group claims to have breached Universidade Federal de Sergipe 🇧🇷, Amata 🇹🇭, ACFA 🇨🇦, Sando Tech 🇯🇵, and Zabun 🇹🇷. https://t.co/KsdurxGc5e
Brazil 🇧🇷 - Fundação Getulio Vargas (FGV) has allegedly been breached by the Dragonforce ransomware group, which claims to have exfiltrated 1.52 TB of sensitive employee, student, and institutional data. https://t.co/oNNCPmjHYx
Em épocas de vibe coding cada vez mais eu estou convencido que o futuro do cyber vai ser na linguagem de baixo nível que é o latim da programação. Ninguém mais estuda, mas todas as línguas usam 😂
Melhor descoberta da semana foi que o Ublocking consegue bloquear a assistente de IA da @estacio_br que é um pé no saco floodando a tela com uma péssima experiência de usuário e não serve pra nada além de atrapalhar
That's great. @Zoom They put a version limiter on the new version and didn't release it on Google Play or it's still in rollout. In short, they leave the user without access to the application. Congratulations on the user experience.