279 million CPFs. More than the entire population of Brazil — because it includes deceased records. In July 2026, according to a listing on the criminal forum breached.su, a database of 279 million CPF records was offered for $10,000. We followed the case and the signal is clear: personal data became a commodity, the price is in free fall, and the absence of consequence sustains the problem.
The July incident: 279 million CPFs on breached.su
According to the listing on the criminal forum breached.su, the claimed database contained 279 million CPF records, offered for $10,000. Receita Federal denied any compromise of its systems and pointed to an ANCINE server with a legacy 2019 backup. According to ANCINE, there was an attack on its infrastructure, but no tax-protected data was compromised. ANPD did not comment publicly on the case.
This is the third incident of this kind in 2026. In April, according to reported forum listings, MORGUE offered 251 million CPFs for $500. In June, a 248 million record database appeared for $1,300. In July, 279 million for $10,000. Personal data became a commodity. And the price is in free fall.
The price in free fall: 80 times cheaper in five years
In 2021, according to reported dark web data, the Serasa database with 223 million CPFs cost $40,000. Today, 251 million cost $500. The entry barrier dropped 80 times in five years.
Brazil has a recurring pattern of mega-leaks. 2021: Serasa, 223 million. 2026: MORGUE, 251 million. Then 248 million. Then 279 million. The totals always exceed the living population because they include deceased records — which is normal for CPF databases. The problem is not the size of the database. It is that each new leak reduces the market price of data already compromised.
The LGPD on paper and the self-assessment that sustains the problem
The LGPD requires incident notification within 3 business days. But the assessment of "relevant risk or harm" is left to the company itself. The iFood case is the example: in December 2025, according to the reported incident, the company discovered a leak and did not notify ANPD or the data subjects. It interpreted that there was no relevant risk. 1.2 million users affected.
ANPD applied the first financial fine in history in July 2023. Telekall, a micro-enterprise telecom. R$14,400. Until 2026, it is the only private company effectively fined. In 2023 alone, according to reported data, Europe applied €1.78 billion in GDPR fines. The difference is not in the legislation — it is in effective consequence.
The fraud that grows while consequence does not come
Meanwhile, fraud grows. According to reported data, 6.9 million attempts in the first half of 2025 — one every 2.3 seconds. The banking sector accounts for 53.7%. According to the Central Bank, BC Protege+, launched in December 2025, has already blocked 255 thousand fraudulent account openings.
The cyber maturity of Brazilian companies tells the rest of the story. According to survey data, only 5% reached mature level. 77% invest less than 1% of revenue in cybersecurity. 83% have no dedicated security executive. When Tech86 implements security programs for clients in Brazil, the initial diagnosis almost always reveals the same pattern: unclassified personal data, incidents without structured response, boards without cyber risk visibility. The LGPD exists on paper. Practice has not caught up.
Conclusion: the leak exposes the data, the absence of consequence sustains the problem
279 million CPFs at $10,000. The leak exposes the data. The absence of consequence sustains the problem. The entry barrier dropped 80 times in five years, the first fine in history was R$14,400 against a micro-enterprise, and the only private company effectively fined until 2026 remains the same one. The LGPD requires notification within 3 business days, but leaves the definition of "relevant risk" to whoever leaks. The result is what we see: personal data became a commodity, fraud grows once every 2.3 seconds, and 83% of companies do not have even a dedicated security executive. At Tech86, we help companies move beyond paper — classify data, structure incident response, invest proportionate to risk, and give the board visibility. Without consequence, the next leak is only a matter of time and price.