CiberLATAMbywhalemate

Brazil Tightens Pix Rules

Brazil’s central bank is putting cyber risk on par with capital and liquidity in Pix oversight, while regular users see no changes.

Whalemate Labs · AI-assisted researchJul 14, 20263 min read

Brazil’s central bank has tightened Pix fraud and security rules, but regular end users should not see any operational changes. Transfers, keys, QR payments and other functions will keep working as usual, while the pressure shifts to institutions that fail to meet the new requirements.

Brazil’s central bank has tightened Pix’s fraud and security framework, but regular end users should not see any visible operational changes. Transfers, the use of keys, QR payments and other transactions will keep working as usual, while the impact falls on institutions that do not adapt to the new requirements.

More weight for cyber risk

According to press coverage, the central bank will begin treating cyber risk with the same supervisory weight as capital and liquidity. That would allow preventive suspension or restrictions on banks and fintechs operating in Pix when significant vulnerabilities are identified.

The move comes in response to losses estimated at more than R$ 1.5 billion from attacks recorded over the past 12 months. In that context, the regulator is also studying a differentiated access model for the system based on each institution’s security level.

Entities with stronger standards would keep full access. By contrast, those with controls considered insufficient could face limits on value, hours of operation and the ability to register new keys. In the most serious cases, the system provides for full suspension.

Audits, reporting and prior controls

The tougher regulatory stance also rests on more rigorous audits and a higher duty to report digital security incidents to the central bank, including events that were previously considered minor. According to the coverage cited, when audits reveal irregularities, institutions may face additional audit rounds before they can remain in Pix.

At the same time, the stronger anti-fraud framework makes it mandatory to check the BC Protege+ system before opening accounts or adding account holders and representatives. That control allows citizens to proactively block accounts from being opened in their name. The check must be available continuously, 24/7, and becomes mandatory on December 1, 2025.

A more restrictive access regime

Other reports say the central bank plans time, day and value limits, along with blocks on registering new keys and functional restrictions for institutions that fail to meet minimum cybersecurity requirements or show significant weaknesses. Those measures can be applied before a final exclusion from the system.

The reporting also attributes the regulatory shift to hacker attacks recorded in 2025 against PSTIs and other system intermediaries. According to those notes, the incidents generated multimillion-real losses and led the central bank to clarify in the rules that supervision can adopt rapid preventive measures, such as limiting transactions, operating hours and the creation of new keys, when an institution poses a risk to the financial system’s security.

Sources

View all