Leaked Online Data May Contain Entire Population Of Brazil’s Info

Leaked Online Data May Contain Entire Population Of Brazil’s Info

Tyler Cross Tyler Cross
Published on: January 11, 2024

The information of hundreds of millions of Brazilians was found online. Researchers with Cybernews discovered a public Elasticsearch instance that contained entries for over 223 million individuals (this happens to be larger than the entire population of Brazil).

Elasticsearch is a tool that various companies use to search, analyze, and visualize stored data. The company provides users with an AI program that helps organize large quantities of data. In this case, the publicly accessible data happened to be extremely sensitive and contained a lot of Brazillian citizen’s personal information.

This included but wasn’t limited to full names, date of birth, sex, gender, taxpayer numbers, and Cadastro de Pessoas Físicas (CPF) numbers. CPF numbers are an 11-digit code that tracks citizens’ identities.

As of now, none of the leaked data is correlated with any specific company or government agency, so no one knows who is responsible for the leak. It’s also unknown if any threat actors were able to obtain the data before Cybernews researchers discovered it.

The instance has since been made private and can’t be accessed. If threat actors were able to obtain any of the data, the scale would be similar to the MOVEit attack from June 2023 and put millions of Brazil’s citizens in danger of having their identity stolen. In the MOVEit attack, hackers managed to exploit the MOVEit file transfer service and steal data from hundreds of millions of people around the world.

“This could have resulted in financial losses, unauthorized access to personal accounts, and other severe consequences for the individuals affected,” Cybernews reported.

Always be cautious when giving a company your information. When companies use third-party services that handle data for them, they run the risk of threat actors exploiting those services and stealing any of the sensitive info you may have given them.

Time Stamp:

More from Safety Detectives