Pular para o conteúdo principal
Close
Security

279 Million CPFs at $10,000: The Leak That Exposes the Absence of Consequences Under Brazil's LGPD

Gabriel Ferraresi· CEO | Tech86August 2, 20264 min
securitylgpdanpdleakcpfdark-webcompliancefraudbrazilprivacy

279 million CPFs. More than the entire population of Brazil — because it includes deceased records. In July 2026, according to a listing on the criminal forum breached.su, a database of 279 million CPF records was offered for $10,000. We followed the case and the signal is clear: personal data became a commodity, the price is in free fall, and the absence of consequence sustains the problem.

The July incident: 279 million CPFs on breached.su

According to the listing on the criminal forum breached.su, the claimed database contained 279 million CPF records, offered for $10,000. Receita Federal denied any compromise of its systems and pointed to an ANCINE server with a legacy 2019 backup. According to ANCINE, there was an attack on its infrastructure, but no tax-protected data was compromised. ANPD did not comment publicly on the case.

This is the third incident of this kind in 2026. In April, according to reported forum listings, MORGUE offered 251 million CPFs for $500. In June, a 248 million record database appeared for $1,300. In July, 279 million for $10,000. Personal data became a commodity. And the price is in free fall.

The price in free fall: 80 times cheaper in five years

In 2021, according to reported dark web data, the Serasa database with 223 million CPFs cost $40,000. Today, 251 million cost $500. The entry barrier dropped 80 times in five years.

Brazil has a recurring pattern of mega-leaks. 2021: Serasa, 223 million. 2026: MORGUE, 251 million. Then 248 million. Then 279 million. The totals always exceed the living population because they include deceased records — which is normal for CPF databases. The problem is not the size of the database. It is that each new leak reduces the market price of data already compromised.

The LGPD on paper and the self-assessment that sustains the problem

The LGPD requires incident notification within 3 business days. But the assessment of "relevant risk or harm" is left to the company itself. The iFood case is the example: in December 2025, according to the reported incident, the company discovered a leak and did not notify ANPD or the data subjects. It interpreted that there was no relevant risk. 1.2 million users affected.

ANPD applied the first financial fine in history in July 2023. Telekall, a micro-enterprise telecom. R$14,400. Until 2026, it is the only private company effectively fined. In 2023 alone, according to reported data, Europe applied €1.78 billion in GDPR fines. The difference is not in the legislation — it is in effective consequence.

The fraud that grows while consequence does not come

Meanwhile, fraud grows. According to reported data, 6.9 million attempts in the first half of 2025 — one every 2.3 seconds. The banking sector accounts for 53.7%. According to the Central Bank, BC Protege+, launched in December 2025, has already blocked 255 thousand fraudulent account openings.

The cyber maturity of Brazilian companies tells the rest of the story. According to survey data, only 5% reached mature level. 77% invest less than 1% of revenue in cybersecurity. 83% have no dedicated security executive. When Tech86 implements security programs for clients in Brazil, the initial diagnosis almost always reveals the same pattern: unclassified personal data, incidents without structured response, boards without cyber risk visibility. The LGPD exists on paper. Practice has not caught up.

Conclusion: the leak exposes the data, the absence of consequence sustains the problem

279 million CPFs at $10,000. The leak exposes the data. The absence of consequence sustains the problem. The entry barrier dropped 80 times in five years, the first fine in history was R$14,400 against a micro-enterprise, and the only private company effectively fined until 2026 remains the same one. The LGPD requires notification within 3 business days, but leaves the definition of "relevant risk" to whoever leaks. The result is what we see: personal data became a commodity, fraud grows once every 2.3 seconds, and 83% of companies do not have even a dedicated security executive. At Tech86, we help companies move beyond paper — classify data, structure incident response, invest proportionate to risk, and give the board visibility. Without consequence, the next leak is only a matter of time and price.

Need expert guidance?

Schedule a consultation with our specialists.

Security and LGPD Program for Companies in Brazil

Frequently Asked Questions

In July 2026, according to a listing on the criminal forum breached.su, a database of 279 million CPF records was offered for $10,000 — more than the entire population of Brazil, because it includes deceased records. According to Receita Federal, there was no compromise of its systems; the agency pointed to an ANCINE server with a legacy 2019 backup. According to ANCINE, there was an attack on its infrastructure, but no tax-protected data was compromised. ANPD did not comment publicly on the case.

ANPD applied the first financial fine in history in July 2023: Telekall, a micro-enterprise telecom, with R$14,400. Until 2026, it is the only private company effectively fined. The LGPD requires incident notification within 3 business days, but the assessment of "relevant risk or harm" is left to the company itself — the iFood case in December 2025, with 1.2 million users affected and no notification to ANPD, showed how self-assessment sustains the absence of consequence.

In 2023 alone, according to reported data, Europe applied €1.78 billion in GDPR fines. In Brazil, until 2026, the only private company effectively fined by ANPD was Telekall, with R$14,400 in July 2023. The difference is not in the legislation — it is in effective consequence. The LGPD exists on paper; practice has not caught up.

Brazil has a recurring pattern of mega-leaks. In 2021, according to reported dark web data, the Serasa database with 223 million CPFs cost $40,000. In 2026, three incidents: in April, MORGUE offered 251 million CPFs for $500; in June, a 248 million record database appeared for $1,300; in July, 279 million for $10,000. The totals always exceed the living population because they include deceased records. The entry barrier dropped 80 times in five years.

According to cyber maturity data, only 5% of Brazilian companies reached mature level, 77% invest less than 1% of revenue in cybersecurity, and 83% have no dedicated security executive. The diagnosis Tech86 performs in security programs for clients in Brazil reveals the same pattern: unclassified personal data, incidents without structured response, boards without cyber risk visibility. The fix is to classify data, establish incident response with always-on notification, invest proportionate to risk, appoint a dedicated executive, and create board visibility.

Blog — Get in Touch

Have a question about our articles or services? Our team is ready to help.

Schedule a Meeting

Book a time slot.

Schedule Now

Email

Send us a message.

[email protected]

WhatsApp

Quick conversation.

Address

Avenida Paulista, 1636 - São Paulo - SP - 01310-200

Tech86 Specialist

Online now

Hello! How can we help scale your business today?

Tech86 Engineering

We Value Your Privacy

We use cookies and similar technologies to optimize your experience, analyze site traffic, and personalize content. By clicking "Accept All", you agree to the use of all cookies. Read our Privacy Policy.