Data protected by bank secrecy, such as balances, passwords and statements, were not exposed; leak occurred on September 24th and 25th
O (Central Bank) this Friday (November 8, 2024) that 644 Pix keys from customers of were leaked. This was the 16th incident involving data from the instant payment system since its launch in November 2020.
According to the BC, the exhibition took place on September 24th and 25th and covered the following information: user name, CPF, relationship institution, agency, account number and type, account opening date, Pix key creation date , date from which the user has possession of the Pix key.
The leak occurred due to specific failures in the payment institution’s systems and registration data, which do not affect the movement of money. Data protected by bank secrecy, such as balances, passwords and statements, were not exposed.
Although the case did not need to be reported because of the low potential impact on customers, the BC said it decided to publicize the incident because of its “commitment to transparency”.
All people whose information was leaked will be notified through the Caixa app or internet banking. The Central Bank said that these will be the only means of warning for the exposure of Pix keys and asked customers to disregard communications such as phone calls, SMS, warnings via messaging apps and email.
Data exposure does not necessarily mean that all information was leaked, but that it was visible to third parties for some time and may have been captured. The BC informed that the case will be investigated and that sanctions may be applied. The legislation provides for a fine, suspension or even exclusion from the Pix system, depending on the severity of the case.
In all 16 incidents with Pix keys recorded so far, registration information was leaked, without exposing passwords and bank balances. As determined by the LGPD (General Data Protection Law), the BC maintains a page where citizens can monitor incidents related to the Pix key or other personal data held by the authority.
With information from .