CiberLATAMbywhalemate

Brazil’s BCB 766 updates Pix MED

Brazil updated the Pix DICT manual with deeper tracing, an 80-day response window, and new MED 2.0 adjustments.

Whalemate Labs · AI-assisted researchPublished:38 min read

Brazil’s Central Bank issued Normative Instruction BCB No. 766, publishing version 8.5 of the Pix DICT Operational Manual and, through Instruction No. 767, resetting the rollout calendar for its changes. The core update is security-focused: the Special Return Mechanism (MED) now traces funds through layered transfers beyond the first receiving account, while the deadline to respond to suspected fraud refunds expands from 30 to 80 days, with staggered effective dates on August 10, September 1, and, for some notification changes, October 26, 2026.

The documentation and specialized coverage agree that the change does not alter the basic experience for the user who files a complaint, but rather the internal work of the institutions participating in Pix. MED 2.0, already in production since May 2026 according to press-cited clarifications, centralizes information on the CPFs and CNPJs involved, maps the "tree" of transfers derived from a root transaction, and allows partial blocks across different institutions in an effort to recover amounts split up by criminal networks. It also adds new attributes to infraction notifications, including transaction graph depth.

The backdrop is operational pressure. Different reports citing Febraban, sector studies, and court records point to a sharp rise in financial fraud in Brazil, with Pix and WhatsApp as the dominant vectors. Documented tactics include fake bank call centers, ghost rentals, the Desenrola scam, phishing campaigns that imitate Receita Federal charges, AI used to mimic the voices and images of political leaders, the creation of Pix accounts in victims’ names, and Android banking trojans capable of intercepting credentials and SMS messages. The report reconstructs that regulatory and operational sequence and connects it to the regulator’s effort to raise recovery rates, reduce false positives, and strengthen traceability in a system where transaction volume keeps growing.

Executive summary

Brazil’s Central Bank updated the technical core of Pix in July 2026 through Normative Instruction BCB No. 766, which publishes version 8.5 of the DICT Operational Manual and repeals the prior rule, No. 752. The central change is twofold: on one side, it extends the tracing of values under the Special Return Mechanism, known as MED 2.0, into successive layers of transfers derived from a root transaction; on the other, it expands the deadline to respond to suspected fraud refunds from 30 to 80 days, with a staggered rollout later adjusted by Instruction No. 767.

The record shows that the regulator did not add new fees or change the victim’s initial request flow. What changed is the ability of participating institutions to respond to fraud with more technical information, more time for analysis in certain cases, and greater traceability of accounts and holders. At the same time, the Central Bank said MED 2.0 was already in production as of May 2026, while some of the operational changes tied to infraction notifications and communication between institutions will move to October 2026.

Pix Regulatory Timeline 202611 MayMED 2.0 inproduction27 JulIN 766 version8.530 JulIN 767 adjustseffective datesAug 10Tracking startsSep 1MED 80 days goesinto effectOct 26Notice perbatch

Pix Regulatory Timeline 2026 — Sequence of publication, effective-date adjustments, and operational rollout for DICT version 8.5 and MED 2.0.

The context behind the adjustment is clear. The consolidated material describes a fraud ecosystem with heavy exposure to Pix, WhatsApp, social engineering, phishing, and mobile malware. The figures cited by Febraban, O POVO+, Jundiagora, Fenasbac, and other outlets show growing losses, millions of attempted scams, and a refund rate that remains low relative to what is stolen. Added to that is a broader criminal playbook, ranging from fake bank hotlines and ghost rentals to campaigns that use AI to impersonate voices, fake ads with alleged benefits, counterfeit Receita Federal charges, and Android trojans that intercept credentials and SMS messages.

The technical effect of version 8.5 of the DICT Operational Manual and Instruction No. 767 is defensive. The Central Bank aims to improve fund recovery, map transfers fragmented across multiple banks, centralize signals on CPFs and CNPJs tied to fraud, and force institutions to review Pix keys and refund responses more carefully. The update also sits alongside other regulatory and operational measures, such as scam alerts to customers, discussion of controls over offensive or threatening messages inside transactions, and the development of a centralized fraud-probability indicator using machine learning.

Context and background

Pix’s recent evolution has to be read against a fraud baseline that was already high before the 2026 rules. The material attributes to Febraban more than 1.8 million non-Pix scam attempts in 2022, a 200% increase from 2021, and more than R$ 2.5 billion in losses from financial fraud in 2023. Later, another set of reports cited by Jundiagora speaks of R$ 10.1 billion in banking losses in 2024, of which R$ 2.7 billion came from Pix fraud, and a more recent pool of more than 24 million Brazilians affected by Pix or boleto scams between July 2024 and June 2025, with total losses of R$ 29 billion.

Specialized coverage agrees that recovering money is far from automatic. O POVO+ cited a survey showing that for every R$ 100 stolen in Pix scams, institutions return on average only R$ 8.90. The Central Bank, in an explanatory note reproduced by Diario do Comércio, emphasized that MED is the official mechanism for trying to recover values sent in fraud, scams, or crime, but that repayment is not guaranteed. That point is central to understanding why the rule change focuses on greater tracing capacity and better coordination among participants.

The logic of MED 2.0 broadens the analytical horizon. Migalhas describes DICT as a core part of Pix’s security net because it identifies fund-diversion routes through infraction notifications between institutions and coordinates sequential blocks and refunds. That same coverage explains that the Value Recovery function is not limited to the bilateral relationship between payer and first recipient, but covers the full flow of transfers derived from a root transaction. Finsiders Brasil adds that the design seeks to reduce false positives, trace straw accounts, and centralize information on CPFs and CNPJs linked to fraud.

Technical chain of MED 2.0Root Pixfraud or scamDICT and notificationbetween institutionsLayered tracingsecond, thirdBlocksfragmentedRecoveryfundsInitial accountreceives the PixRecord ofinfractionsFollow the flowof moneyRetention andpartial reversalRestitutionpossible

Technical chain of MED 2.0 — From suspicious Pix to layered traceability and staggered inter-institutional blocks.

In parallel with the regulatory layer, the Central Bank has also been testing complementary responses. Valor Econômico reported that the BC intends to develop a real-time fraud-probability indicator calculated with machine learning and made available to participating institutions. Folha de S.Paulo tied that initiative to the 2023-2025 Pix Management Report, which also mentions measures to prevent the Pix message field from being used for threats and insults. Terra specified that, in 2025, the system processed nearly 80 billion Pix transactions worth more than R$ 35 trillion, with about 148 million individuals and 12.8 million companies sending or receiving at least one transfer.

Key facts table

Date Fact Source Confidence
2026-07-27 IN BCB No. 766 publishes version 8.5 of the DICT Operational Manual and repeals IN No. 752. LegisMap, Cadoc.ai Confirmed
2026-07-27 Version 8.5 introduces new attributes in infraction notifications, such as TransactionDepth, and adjustments to MED and Value Recovery. Cadoc.ai Confirmed
2026-07-27 The manual updates operational flows, API limits, security protocols, and refund request mechanisms. RegAlert.today Confirmed
2026-07-30 IN BCB No. 767 amends IN No. 766 and adjusts the effective dates of part of the package. LegisMap, Okai, Cadoc.ai Confirmed
2026-07-31 Finsiders reports that MED 2.0 was already in production as of May 2026. Finsiders Brasil Confirmed
2026-08-06 TechTudo reports that Pix adds new tracing for laranja accounts and changes MED. TechTudo Confirmed
2026-08-06 O Hoje reports that the MED response deadline rises from 30 to 80 days. O Hoje Confirmed
2026-08-11 Diario do Comércio clarifies that MED is official but does not guarantee repayment. Diário do Comércio Confirmed
2026-08-11 The BC explained that from October 26, 2026, some infraction notifications will include information about the layer of the flow. Diário do Comércio Confirmed
2026-08-10 Valor Econômico reports that the BC is evaluating a centralized fraud-probability indicator with AI. Valor Econômico Confirmed
2026-08-10 Folha de S.Paulo links the indicator to the 2023-2025 Pix Management Report. Folha de S.Paulo Confirmed
2026-08-22 CERT.br recommends cutting contact, preserving evidence, and opening MED after a Pix scam. CERT.br, M2Works Confirmed

Operation timeline

Date Event Actor/vector Verified source
2026-05-11 MED 2.0 enters production, according to a clarification cited by the press. Central Bank, MED 2.0 Diário do Comércio
2026-07-27 IN BCB No. 766 and version 8.5 of the DICT Operational Manual are published. Central Bank, DICT LegisMap, Okai, Detectei
2026-07-30 IN BCB No. 767 is issued to change effective dates for part of the package. Central Bank LegisMap, Okai, Cadoc.ai
2026-08-10 New monitoring tied to laranja account tracing begins to apply. Pix, participating institutions TechTudo, TV Sim Brasil
2026-09-01 The deadline to respond to MED refunds is extended to 80 days. MED, recipient participants LegisMap, O Hoje, Diário do Comércio
2026-10-26 Some infraction notifications begin including the layer of the flow linked to the notification. Central Bank, institutions Diário do Comércio

Attack chain and TTPs

The Pix rule update is not explained by a single abuse technique, but by a set of vectors that repeat and overlap. The dominant pattern that emerges from the research is social engineering backed by instant messaging, fake calls, sponsored ads, cloned sites, and, increasingly, AI used to make the scam more credible. The chain often ends in a Pix transfer, but the setup varies. Sometimes it is a fake bank hotline. In other cases, it is an nonexistent rental, debt renegotiation, fake public benefits, or counterfeit charges from official agencies.

MED 2.0 was designed precisely to deal with a reality in which the money does not always stay in the first account that receives the fraudulent Pix. Finsiders Brasil and Folha Jundiaiense explain that the new architecture allows the mapping of the "tree" of transactions derived from a root transaction and allows partial blocks across several banks, so the total can reach the original amount even when the money has been spread out. That matters because criminals split funds to make tracing and restitution harder.

Pix Fraud TTPsSocial engineeringPhishing and domainsAI and impersonationMalware and accountsFake call center, scamswith phone pressureReceita, linksand cloned sitesVoice and imageto build trustAndroid trojansand rental accountsCERT.br, Migalhas, FolhaBVTecmundo, StartupiMetropoles, Super Rádio TupiMalwarebytes, Livecoins

Pix Fraud TTPs — Documented tactics from the material, from impersonation to malware and rented accounts.

Infraction notifications are the coordination mechanism. Migalhas notes that DICT allows the identification of fund-diversion routes and the coordination of sequential blocks and refunds between institutions. Version 8.5 adds a graph-depth field, TransactionDepth, to indicate the layer to which the notification belongs. Diario do Comércio reported that this information will appear starting October 26, 2026, in notifications sent to the participant holding the potentially fraudulent account.

The criminal tactic, by contrast, still relies heavily on the human factor. Correio do Povo cites studies that attribute about 40% of financial fraud in Brazil to social engineering, with variants such as fake bank hotlines, impersonation of bank employees, and fake police operations. Super Rádio Tupi added that criminals buy online traffic, purchase databases, and use AI to refine messages and ads before closing the capture with a financial payment. The material also reports cases where real personal data, such as CPF and date of birth, are used to simulate individualized service.

TTP Description Source
Social engineering with fake bank hotlines Calls or contacts that pretend to be from the bank to induce credentials or transfers. CERT.br, FolhaBV, Migalhas
Phishing with cloned domains Fake sites that imitate agencies such as Receita Federal and generate charges via Pix. Tecmundo
AI-assisted impersonation Manipulation of the image and voice of political leaders to gain trust. Metropoles
Ghost rental scam Listings priced well below market value, fake contracts, and advance payment via Pix. Metropoles, Brasil em Folhas
Rental and mule accounts Opening or using accounts in victims’ names to move money and hide the real beneficiaries. Pagamentos Pix
Android banking trojans Malicious apps that steal credentials, intercept SMS, and enable fraudulent transfers. Pagamentos Pix, Malwarebytes, Livecoins
Fund fragmentation Splitting the money into multiple transfers to make tracing harder, then blocking in layers. Finsiders Brasil, Folha Jundiaiense

Regional impact

Regional overview

The regional impact of the change is concentrated in Brazil, because that is where Pix, DICT, and MED form a unique operating ecosystem. No additional verifiable facts are available in the supplied material for the rest of the bloc’s countries. Within Brazil, the reform affects banks, fintechs, acquirers, payment service providers, merchants with high Pix volume, and antifraud teams that will need to adjust reconciliation, notification response, and identity validation.

Factual coverage by countryRelative amount of verifiable facts in the provided materialBrazilHighArgentinaNo factsChileNo factsPeruNo factsMexicoNo events

Factual coverage by country — Verifiable material is concentrated in Brazil; the rest of the region has no additional confirmed facts.

Brazil

Brazil is where the regulatory change sits, and the rest of the countries in the report do not have additional factual coverage in the research. Normative Instruction BCB No. 766 and its later adjustment, No. 767, reorganize the effective dates for changes to the DICT Operational Manual in two broad blocks: August 10, for initial tracing and monitoring, and September 1, for the expansion of the MED response deadline. Some of the operational changes tied to infraction notifications move to October 26.

The reading of the sources separates three layers. The first is the regulatory layer, with version 8.5 of the manual and the repeal of IN No. 752. The second is the technical layer, where tracing attributes, CPF and CNPJ validation against Receita Federal, rules for Pix Automático in the event of operational errors, and a notification structure capable of reflecting transaction depth are added. The third is the antifraud layer, with MED 2.0, the ability to trace funds in layers, and centralized signals to support block or refund decisions.

At the same time, fraud pressure is national and concrete. The data gathered by the business press and sector studies shows sharp growth in losses, a low effective recovery rate, and a range of scams that no longer rely only on phone impersonation. There is Pix fraud in fake debt renegotiations, rental listings, charges for nonexistent benefits, messages exploiting public programs, stores that receive altered payment receipts, WhatsApp-based contagion, and attacks that use malware to capture credentials or SMS messages. That is why the BC is also pushing scam alerts to customers and a centralized fraud-probability indicator with AI.

The practical consequence is that risk management is no longer just transactional. Institutions will need to consolidate key verification, atypical-pattern analysis, detailed reconciliation, request traceability, and response to infrastructure and recovery notifications. Revista Empreende warns that merchants and platforms also need finer records because the tracing flow can reach later accounts, not just the first receiving one. Finsiders adds a legal point: if institutions do not structure the accept-or-reject flow for refunds well, they may face actions from victims and from recipients affected by chargebacks.

Technical indicators

No classic IOCs, such as hashes, IPs, or unique domains tied to a single actor, were published in the consolidated material. What is verifiable in this research are operational and regulatory indicators that are useful for fraud monitoring and compliance.

Type Value Source
Effective date 1 August 10, 2026 LegisMap, TechTudo
Effective date 2 September 1, 2026 LegisMap, O Hoje
Effective date 3 October 26, 2026 Diário do Comércio
Prior MED deadline 30 days O Hoje, Diário do Comércio
New MED deadline 80 days O Hoje, Diário do Comércio, Finsiders Brasil
Institutional analysis window up to 7 days Finsiders Brasil, Conta Azul
Possible refund deadline with available balance up to 11 days after the response Conta Azul
New notification field TransactionDepth, graph depth Cadoc.ai

Analysis for security teams

The Pix update forces a separation between prevention, detection, and response. On prevention, the first adjustment is identity. Version 8.5 of the DICT Operational Manual incorporates CPF and CNPJ validation against Receita Federal databases when registering or changing Pix keys, which makes directory hygiene stricter. For banks, fintechs, and PSPs, that means cleaning up onboarding and key-change processes, because poor validation can open the door to accounts used as intermediate steps in fraud.

On detection, the focus can no longer stay on the individual transaction alone. The material shows that fraud is fragmented across several institutions and several accounts. MED 2.0 and layered tracing make it possible to follow the money trail and request partial blocks, but that capability depends on teams operating alert rules for unusual behavior, unusual concentration of recipients, the speed of fund dispersion, and matches with known scam patterns. The court cases cited in RRR Advogados and Correio Braziliense show that the absence of preventive blocks or timely reaction can end in judgments against banks.

On response, the operational priority is to coordinate timing. The system is entering a phase in which some rules already apply from August 10, others from September 1, and certain notifications change only on October 26. That means mapping dependencies between technology, legal, customer service, and fraud prevention. If an institution updates only the customer-facing front end, but not its internal blocking and refund workflows, it will face a double burden, from the victim seeking recovery and from the recipient challenging a reversal.

The attack surface is also human. The CERT.br and M2Works guides are explicit: after a suspected scam, cut contact, open the official app, locate the transaction, register the dispute as fraud or social engineering, request MED activation, and preserve evidence. For security and fraud teams, that turns into two concrete tasks. The first is educating users and call centers so they do not validate requests through unofficial channels. The second is ensuring that evidence reaches the back office intact, including messages, links, receipts, and access traces.

At the prioritization level, three vectors stand out as most urgent. One is fake hotlines and institution impersonation, because they still account for many cases and rely on low-cost social engineering. Two is attacks using real data and visual props, such as the Desenrola scam or AI-based campaigns, because they increase the victim’s trust rate. Three is mobile malware and compromised accounts, because they leave a harder-to-reverse footprint and can enable real-time transfers. In all three cases, the operational goal should be to contain fund fragmentation and improve response quality in the first hours.

Frequently asked questions

What exactly changed in Pix between August and October 2026?

The DICT and MED operating framework changed on three dates. On August 10, the new monitoring tied to laranja account tracing began. On September 1, the deadline to respond to MED refunds was extended to 80 days. And on October 26, more detail will be added to certain infraction notifications, according to the Central Bank.

Does the new MED version give victims more time to request a refund?

No. According to Revista Fórum and Finsiders Brasil, the up to 80-day period for the victim to request MED activation already existed. What was extended to 80 days was the time for the recipient or institution to respond to a suspected fraud refund. The difference affects the system’s internal response.

What is the connection between layered tracing and WhatsApp scams?

Layered tracing addresses fraud that does not end with the first transfer. The material shows that many scams use WhatsApp as the initial vector and Pix as the final step, and that the money is often split across multiple accounts. That is why MED 2.0 seeks to follow the full path, not just the first transfer.

What should banks and fintechs do under the new rules?

They need to validate CPF and CNPJ better in Pix keys, respond to notifications within the new deadlines, prepare detailed reconciliation, and support partial blocks across multiple institutions. They also need to work with scam alerts and with processes that can stand up in legal disputes involving victims and recipients if they identify unusual transactions.

What types of fraud appear most strongly in the material?

The strongest patterns are fake bank hotlines, ghost rentals, Desenrola scams, phishing that imitates Receita Federal, AI-based ads, and Android banking trojans. All of them share the same end point, either prompting the user to transfer via Pix or enabling fraudulent transfers from compromised devices or accounts.

Does the Central Bank consider Pix’s central infrastructure compromised?

No, according to Olhar Digital, the Central Bank said Pix’s central infrastructure never suffered a successful attack. The issue addressed by IN No. 766 is not a system outage, but the fraudulent exploitation of its flows through social engineering, rental accounts, phishing, and malware.

Material limitations

The research does not include the full text of Normative Instruction BCB No. 766 or No. 767, so this report reconstructs their effects from specialized coverage and secondary technical descriptions. There are also no classic IOCs attributable to a single actor, and not enough data to state with precision how each technical validation is implemented internally across all participants.

No additional facts were verified for Argentina, Chile, Paraguay, Bolivia, Peru, Colombia, Mexico, the United States, or Uruguay. The available factual coverage is concentrated in Brazil and its Pix infrastructure. The centralized fraud-probability indicator with AI appears as a project under development, with no confirmed deployment schedule in the material.

As for MED 2.0, some sources present it as already in production since May 2026, but the available excerpt does not detail the specific regulatory devices that activate each phase. For that reason, this report preserves the exact timing attribution when it was verified and treats the difference between prior production and the staggered enforcement of later changes as an operational distinction.

Sources

View all