Brazil: cybersecurity landscape, June 2026
Brazil closed June with a massive false alert, 15 ransomware cases, and 6 regulatory moves amid high public pressure.
Key findings
- The Defesa Civil Alerta incident was the month’s most serious event and forced the public alert system to be temporarily disabled and redesigned.
- Brazil closed June with 25 unclassified incidents, the month’s largest signal, suggesting a highly frictional operating environment and fragmented visibility.
- Ransomware remained active with 15 cases, but the material requires separating confirmed encryption, exfiltration, leak site mentions, and uncertain classification.
- Health, the public sector, logistics, education, manufacturing, and services were among the affected sectors; the public sector concentrated the greatest strategic relevance.
- ANPD increased regulatory pressure with a process against Claro, monitoring of 56 agents, and referral of 21 organizations for sanction review.
- The Senate advanced changes that expand oversight of data security and discussed the Marco Legal da Cibersegurança, signaling greater institutional scrutiny.
- The month included two critical CVEs in the material, one tied to Oracle PeopleSoft and another to JCE Pro for Joomla, both with immediate remediation value.
Monthly reference modules
These modules are automatically filled with verified dated facts within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. This is the recurring month-by-month reading; the analysis that follows develops the cases without repeating this summary.
Indicator window: 67 dated facts in June 2026 · 1 without confirmed date (excluded from the indicators). Facts from previous months are used only as comparative context in the analysis, never as volume for this period.
Monthly Executive Summary for Brazil
June 2026 was marked by a nationwide incident in the Defesa Civil Alerta system. A false alert sent remotely and classified as "Extreme Alert" woke millions of people, forced the platform offline around 1:30 a.m. on June 20, and triggered a Federal Police investigation. The episode was more than an operational failure. It exposed weaknesses in access control, decentralized panel management, and the resilience of the public notification channel.
The official response was swift. MIDR and the National Civil Defense temporarily centralized operations, restricted state access, and then announced a new framework with forms, Gov.br accounts, additional verification, and VPN use for state and municipal agents. At the same time, Anatel sought to calm public concern, but the reputational damage was already done: the system designed for emergencies had become a vector of distrust.
On the ransomware front, Brazil maintained a steady presence on leak sites and extortion panels. Monthly indicators show 15 cases with ransomware or extortion as the primary focus, although the source does not always make it possible to determine whether there was encryption, exfiltration only, or a simple mention on a leak site. Within that set, there were signals involving public health, logistics, education, manufacturing, the public sector, and services, with at least one confirmed double-extortion case and another in which the source only supports inclusion on the leak site.
The regulatory front also moved forcefully. ANPD advanced on Claro, closed monitoring of 56 data processing agents, and referred 21 organizations for sanction review. The Senate, meanwhile, pushed two core debates, one on data protection and security incidents, and another on a Cybersecurity Legal Framework. The month left the image of a country still under technical, regulatory, and political pressure at the same time.
Brazil’s national intelligence in June
June was defined by incidents, not quiet campaigns or background telemetry. Of 67 verified events, 25 fell into the unclassified incident category, which accounted for most of the material and was led by the Defesa Civil Alerta case. The event carried high public severity because it affected a national service, reached multiple states, triggered public panic, and led to immediate operational changes. At the same time, the ransomware ecosystem remained active, but in a fragmented pattern, closer to persistent leak sites and opportunistic extortion than to a single dominant campaign in the country.
The risk reading for Brazil in June is high. Not because the data show a uniform rise across all metrics, but because of three factors combined: a mass incident that compromised a critical state alert channel, a persistent ransomware base across diverse sectors, and a regulatory front that had to respond to concrete problems involving data sharing, security incidents, and oversight findings. When a public alert system has to be shut down and reconfigured in the middle of a crisis, the impact goes beyond the technical layer and becomes institutional.
The false-alert case also offers a regional signal. In Latin America, digitized public services and mass-notification platforms remain high-value targets, both symbolically and operationally. It does not take a sophisticated intruder to cause damage politically and socially, weak credentials, delayed centralization, or poorly distributed access controls are enough. Brazil showed that clearly in June, and the month ended with changes to the alert channel design, not just an open investigation.
Brazil period indicators
| Indicator | Value |
|---|---|
| Verified facts in the period | 67 |
| Indicator time window | 67 facts dated June 2026 · 1 with unconfirmed date (excluded from indicators) |
| Unclassified incidents (breaches or outages) | 25 |
| Cases with ransomware or extortion as the primary focus | 15 |
| Confirmed encryption of assets | 1 |
| Exfiltration without encryption (pure extortion) | 4 |
| Leak site mention only | 1 |
| Unclassifiable with available material | 9 |
| Documented fraud or phishing cases | 5 |
| Documented regulatory moves | 6 |
| Critical CVEs mentioned | 2 |
| Sectors with at least one documented fact | 7 |
| Predominant threat for the month | Incidents (25 of 67 facts) |
| Facts with direct source confirmation | 61% |
| Comparative baseline | No comparative baseline: this is the first archived period with this indicator format for this country. |
Relevant Incidents in Brazil
Defesa Civil Alerta and the fake extreme alert
The month’s most significant incident was the intrusion into the Defesa Civil Alerta system. The official MIDR source said the platform was taken offline around 01:30 on June 20, 2026, after an unauthorized remote push of extreme alerts. Reuters, Agência Brasil, O Globo, Teletime, and other outlets agreed on the core facts: there was a fake message, the platform was proactively disabled, and the Federal Police opened an investigation. The differences among sources are in the level of detail, not in the substance.
What matters for a security team is not only that there was an intrusion. The incident showed that the risk was not confined to a single jurisdiction or a marginal channel. Messages were reported in several states, at least eight capital cities, and thousands or millions of phones, depending on the source consulted. In addition, the use of the word "misantropia" and distribution through Cell Broadcast and SMS point to a compromise in the system administration chain, not a simple notification delivery issue. The later centralization of the service in Brasília confirms that the previous architecture was too exposed.
Operational changes to the public alert system
The MIDR responded with a new governance and access setup. First it limited direct use by the states, then implemented a semi-automated workflow with forms and a single authority enabled to trigger alerts during containment. Later it announced an automatic scheme with VPN, Gov.br accounts, and an additional code verification step. That sequence matters because it shows how a real incident ends up rewriting the operating process of a critical platform.
From a security standpoint, the problem no longer stops at the initial entry vector. Credential traceability, decentralized panel control, the role of regional users, and the separation between testing and production also come under scrutiny. The fact that the system had to be taken down and then reactivated after new tests confirms that the attack reached a sensitive asset, not a secondary surface.
Security incidents tied to personal data and payments
Outside the alert case, the month also produced other specific signals. The Central Bank confirmed a security incident linked to unauthorized access to a system managed by the Polícia Civil do Maranhão, with exposure of Pix key data, including name, CPF, institution, branch, account, and creation date. The available information makes clear that passwords, balances, and financial transactions were not compromised, which limits the impact, but does not make it trivial.
A report dated but not confirmed also mentioned a ThreeAM ransomware campaign against WS Group Brasil involving double extortion and deletion of shadow copies. Because the date is not confirmed, it is not included in the monthly tally, although it does help frame criminal groups’ interest in Brazilian corporate infrastructure.
Additional material on iFood and Nissan
Two additional items served as context, although they do not drive the monthly assessment. On one hand, a WCYB Digital Radio report said iFood had allegedly disclosed data exposure affecting about 1.2 million users tied to a prior incident. On the other, SecurityWeek reported a breach at Nissan Americas linked to exploitation of CVE-2026-35273 in Oracle PeopleSoft, with possible impact on employees in Brazil among other countries. In both cases, the material is useful for trend analysis, but the direct connection to the country carries less weight than the confirmed local incidents.
Threats and active campaigns in Brazil
Ransomware with confirmed encryption
The only case in the month’s material with confirmed asset encryption was the Mato Grosso State Health Secretariat, linked to LockBit5. The combined sources support the conclusion that there was both exfiltration and system encryption, fitting a classic double-extortion pattern. No verifiable IOCs or technical details were published that would allow anything beyond attribution and the general attack pattern.
Ransomware with exfiltration, no confirmed encryption
The exfiltration-only category includes cases where the source describes data theft or data leaving the environment, but not operational blocking of systems. Coemi Imóveis falls into this group because Krybit claimed to have stolen data and threatened publication if negotiations did not begin. Meta, a Brazilian occupational health provider, was listed by BravoX with an assertion that sensitive information had been exfiltrated. Editora Irmãos Vitale also fits this category more closely, since the material points to data leakage without clear documentation of encryption. The common thread is extortion focused on disclosure of information, rather than technical unavailability.
Cases that cannot be classified from the available material
There are nine cases in which the source does not specify whether there was encryption, exfiltration, or only inclusion on a leak site. This includes several mentions in weekly radars and leak aggregators, such as ws.com.br, MHE9 Logística, Clínica Vida, Silmquinas e Equipamentos, sweetome.com and the reference to gov.br attributed to APT73/Bashe. In those cases, strict interpretation is needed: appearing on an extortion site does not, by itself, prove verified operational impact.
Leak site mention only
In June, at least one case remained, for now, as a leak site mention only. The Gentlemen included Mackay Sugar on its site, but had not yet released data at the time of the cited report. That distinction matters because it separates the publication of a target from evidence of an actual data leak.
Documented fraud and phishing
The month also included five documented fraud or phishing incidents. They are not the main theme, but they do fit the broader pressure on users and credentials. In a period that included discussion of fake alerts, cloned credentials and unauthorized access to panels, social engineering was not a side issue. The material provided does not support building a single phishing campaign, but it does point to an environment favorable to impersonation and abuse of trust.
APT and hacktivism
The only claim that comes close to an APT or hybrid-actor line is the mention of APT73, also identified as Bashe, against gov.br. The claim appeared on extortion sites and in tracking reports, but without official confirmation or public IOCs. From an editorial standpoint, that means it should be treated as an actor claim, not as a settled fact of effective intrusion.
Critical vulnerabilities affecting Brazil
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2026-35273 | Oracle PeopleSoft | Zero-day exploitation in a campaign attributed to employee data theft in several countries, including Brazil; the source describes possible access to payroll, banking, tax, and ID records. | SecurityWeek, The Register |
| CVE-2026-48907 | JCE Pro for Joomla | Pre-auth remote code execution, with a recommendation to update to 2.9.99.6 or later, or uninstall the component if that is not possible. | CISC, Portal Gov.br |
The material reviewed did not record any other critical CVEs with documented impact in Brazil during June. That does not mean other vulnerabilities were not exploited in the region, only that they did not appear in the corpus used for this report.
Regulation and Compliance in Brazil
ANPD and the enforcement front
The ANPD had an active month. It closed monitoring of 56 processing agents, including public agencies and private companies, over the role of the encarregado de dados, and sent 21 organizations for review after they failed to respond. It also opened an administrative proceeding against Claro over alleged irregularities in the sharing of personal data with Serasa. That case matters not only for the specific dispute, but because it confirms the authority is willing to turn governance obligations into potential sanctions.
Federal Senate and data protection
The CCT approved a bill that clarifies the ANPD's authority to oversee security measures and apply penalties when an incident leads to vazamento de information pessoal. The CDH, meanwhile, moved forward with an amendment to the Marco Civil da Internet to require notification when content is removed without a court order. While the issue is not identical to operational cybersecurity, it does affect abuse management, moderation, and traceability in decisions on digital platforms.
Cybersecurity Legal Framework
On June 30, the CCT discussed PL 4.752/2025, which establishes the Marco Legal da Cibersegurança and creates the Programa Nacional de Segurança e Resiliência Digital. ABIN took part in the public hearing. The move does not solve the month's operational problems on its own, but it shows that Brazil's political system is trying to build a more coherent regulatory framework to respond to incidents with national reach.
Internal rules and public administration
Enap approved Resolução 96, which sets internal procedures for reporting security incidents, information access requests, and registro de compartilhamento de dados pessoais. Although it is an internal measure, it adds to a month in which the Brazilian state put its own reporting and custody flows under review.
Most affected sectors in Brazil
The public sector was the most visible, both in volume and intensity. That was not only because of the Defesa Civil Alerta incident, but also because of the buildup of cyber incidents affecting federal bodies and entities, the Pix case handled by a state civil police force, and regulatory debates tied to personal data and institutional security. The state appeared at once as victim, regulator, and the entity responsible for corrective action.
Health also stood out. Mato Grosso’s Health Secretariat appeared in the LockBit5 extortion ecosystem, and Clínica Vida was listed in another weekly radar. This reinforces a familiar pattern in Brazil and across the region: health combines high operational sensitivity with pressure to keep services running, which makes it especially attractive for extortion.
Logistics, business services, education, manufacturing, and consumer services round out the observed distribution. These are distinct sectors, but they share a common exposure, reliance on authentication systems, data exchange, and business continuity. The fact that the material shows seven sectors with at least one documented incident points to a dispersed month, with no concentration in a single vertical, although the public sector clearly ranked highest in strategic relevance.
Trends and signals to watch in Brazil
There is no month-over-month baseline in this format, so it would be wrong to invent a trend for intermonthly variation. June did leave two signals worth watching. The first is the fragility of public notification systems that rely on multiple channels and decentralized administration. The second is the continued use of leak sites as a tool for reputational pressure, even when the operational impact is not clearly verified.
MIDR's announced hardening also deserves attention. The move to VPN, Gov.br accounts and additional verification may reduce risk, but its real effectiveness will depend on how regional credentials are managed and on whether centralization reduces the attack surface or only shifts the single point of failure. At the same time, the regulatory front could become more demanding if the Senate turns what was still debate in June into law.
In ransomware, the most useful signal is not a single group, but the range of sectors targeted and the frequency of mentions with incomplete classification. That points to an active ecosystem, more fragmented than spectacular, where public visibility comes from leak sites and aggregators as much as from victims confirming incidents.
Security guidance for teams in Brazil
First, review privilege administration and access traceability in systems that distribute alerts, notifications, or mass messages. If a panel can be triggered remotely by regional accounts, session control, credential rotation, and separation of duties must be measurable, auditable, and subject to periodic testing.
Second, tighten controls over personal data disclosure flows and third-party sharing operations. The ANPD, Claro and Serasa cases show that the problem is not only external data theft. There is also risk in how information is negotiated, shared, and documented within the commercial ecosystem.
Third, treat leak sites as an early signal, not as final proof. If an organization appears listed, it is advisable to validate the real scope, compromised access, exfiltration, and any published artifacts before communicating or denying it outright. The difference between "mention," "exfiltration," and "encryption" changes the response plan.
Fourth, prioritize patches for the two critical vectors mentioned in the material, CVE-2026-35273 and CVE-2026-48907. In both cases, the operational value of the fix clearly outweighs the cost of a short maintenance window. In public and corporate environments, exposure of collaboration services, ERP, and web components can open very different doors, but equally harmful ones.
Fifth, adjust crisis procedures so a false alert does not turn into prolonged operational confusion. The June incident showed that technical security and public communication must be aligned. If they are not, the attacker or intruder does not only compromise a channel, they also compromise trust in the entire infrastructure.
Material limitations
This report was prepared exclusively from the material provided for June 2026 and from facts dated within that time window. Facts without confirmed dates were excluded from the indicators and were used only, when appropriate, as qualitative context, with that caveat.
A zero indicator, especially for CVEs, means it was not recorded in the material analyzed for this period. It does not mean that critical vulnerabilities exploited in Brazil or the region did not exist during the month, only that they did not appear in the available corpus for this report.
The coverage also excluded aggregated telemetry, blocked attempts, and vendor averages that do not constitute incidents. Likewise, social media posts and promotional or commercial material outside the permitted sources were not used as evidence. When a source described a fact without sufficient confirmation, it was treated as attribution or context, not as a consolidated incident.
Finally, the indicator format has no prior comparative baseline for Brazil, so no artificial month-over-month trend was constructed. The result is a snapshot of June 2026, not a historical series.
Sources
- O falso alerta que revelou uma vulnerabilidade realUFJF – Grupo de Pesquisa em Políticas de Defesa Civil
- Brasil investiga posible ciberataque a su sistema de alertas de emergencia: falsa alarma despertó a miles de personas en la madrugadaEl Universal
- Ciberataque contra sistema nacional de alertas de BrasilPeople’s Daily (español)
- Ataque hacker pudo comprometer sistemas de defensa de Brasil: Defensa Civil explicó los mensajes no autorizadosSemana
- Brasil investiga un presunto ataque cibernético luego de que millones de personas recibieran una falsa alerta de emergenciaInfobae
- Krybit Ransomware Strikes Coemi Imóveis in BrazilDexpose
- La semana en noticias sobre filtraciones: 17 de junio de 2026Kaseya
- June 2026 Ransomware Report: 707 Victims, 63 GroupsBreachsense
- Feed De Noticias De Ciberseguridad [12/06/2026]CronUp Ciberseguridad
- El grupo de ransomware más activo del mundo llegó a ...El Heraldo de Puebla
- Ransomware en mayo de 2026: 95 ataques, Qilin lidera y la sanidad es el sector más golpeadoRevista Ciberseguridad
- Suspected hacker sends unauthorized alert across BrazilReuters
- Hacker hijacks Brazil's national alert system, sending "misanthropy" to millions of phonesBitdefender HotforSecurity
- Brazil begins investigating emergency alert system breachThe Register
- Millions in Brazil Get Fake Government Mobile Alert After HackBloomberg
- Hackers cause panic by sending 'alien invasion warnings' to millions of Brazilians.Gigazine
- Sistemas do governo registram cerca de 6.700 incidentes em 2026, aponta GSIFolha de S.Paulo
- Domain-Wide GPO Deployment, Shadow Copy Erasure, and Double-Extortion Pipeline Subversion — The ThreeAM Ransomware Campaign Against WS Group BrasilBrinzTech
- saude.mt.gov.br Listed by lockbit5 Ransomware GroupGalaxyWarden
- LockBit5 Strikes Brazil's State Secretariat of HealthDeXpose
- Weekly Ransomware Intelligence Report, June 28, 2026Scrutex AI
- Cybercrime Wire For Jun 5, 2026. Breach Hits Brazil's Dominant Food Delivery App. WCYB Digital RadioWCYB Digital Radio
- Nota oficial sobre investigação de incidente cibernéticoMinistério da Integração e do Desenvolvimento Regional (MIDR)
- Sistema de notificação de desastre evoluiu, mas ainda tem fragilidadesAgência Brasil
- Defesa Civil explica: o que sabe sobre o alerta hacker que chegou aos celulares em vários estados do paísO Globo
- Ataque hacker à Defesa Civil expõe fragilidades do governoGazeta do Povo
- Alertas falsos da Defesa Civil começaram a ser enviados do ParanáPoder360
- 'Misantropia': sistemas do governo federal registram 45 incidentes cibernéticos por dia em 2026O Globo
- Ataques digitais explodem no Brasil e governo registra mais de 10 mil incidentes em um anoNovo Notícias
- Defensa Civil de Brasil denuncia un ataque informático contra su red de alertasInfobae
- Se sospecha que hackers están detrás de la alerta no autorizada enviada a teléfonos celulares en todo BrasilCNN en Español
- Novo teste garante segurança no envio de alertasMinistério da Integração e do Desenvolvimento Regional
- Alerta extremo falso da Defesa Civil: o que se sabe sobre o casoG1 (Globo)
- 2026 Brazilian civil defense system false alarmWikipedia
- Victim: gov.brRansomware.live
- gov.br data breach — Apt73 ransomware leak (2026)Darkfield (Orizon)
- saude.mt.gov.br Listed by lockbit5 Ransomware Group Data Breach: What Was Exposed & What To DoRecentBreaches
- Sistema da Defesa Civil é suspenso após invasão e disparo falsoAgência Brasil
- Governo centraliza Defesa Civil Alerta após incidente cibernéticoTeletime
- Ataque hacker impacta alertas de temporal da Defesa Civil do ParanáG1 (Grupo Globo)
- Brazil: Hackers suspected to be behind unauthorized alertCNN
- Brazil probes possible cyberattack on alert systemBSS/AFP
- Falso alerta da Defesa Civil expõe a fragilidade da segurança cibernética estatal no BrasilVeja
- ANPD inicia processo para sancionar Claro por irregularidades no compartilhamento de dados pessoais de clientes com a SerasaAutoridade Nacional de Proteção de Dados (ANPD)
- CCT aprova projeto que amplia medidas de proteção de dados pessoaisSenado Federal
- CCT debate marco legal da cibersegurançaSenado Federal
- Marco Legal da Cibersegurança: Segurança Digital, Proteção de Dados e Resiliência de Serviços Essenciais (PL 4752/2025) – Audiência Pública CCTSenado Federal
- Proteção contra ataques digitais: Senado discute criação de Marco Legal da CibersegurançaSenado Federal
- ABIN debate Projeto de Lei que institui Marco Legal da CibersegurançaAgência Brasileira de Inteligência (ABIN)
- Big techs deverão comunicar retirada de conteúdo sem ordem judicial, aprova CDHSenado Federal
- A ANPD encaminhou 21 organizações para processo sancionador por silêncio…Protegon
- Nissan Employee Data Breached in Oracle PeopleSoft HackSecurityWeek
- Nissan says Oracle PeopleSoft break-in may have spilled payroll records, SSNsThe Register
- Nissan Americas Hit in Global Oracle PeopleSoft Data ...Cyber Defense Magazine
- MIDR apura incidente cibernético que acionou indevidamente o Defesa Civil AlertaMinistério da Integração e do Desenvolvimento Regional (MIDR)
- MIDR aciona Polícia Federal para investigar invasão ao Defesa Civil AlertaMinistério da Integração e do Desenvolvimento Regional (MIDR)
- Novo teste garante segurança no envio de alertasMinistério da Integração e do Desenvolvimento Regional (MIDR)
- Alertas falsos da Defesa Civil: Secretário aponta ataque hacker | G1G1
- Incidente de segurança com Polícia Civil expõe dados de chaves Pix, diz Banco CentralCorreio 24 Horas
- ALERTA 50/2026 — Gabinete de Segurança InstitucionalGSI/CTIR Gov (Gabinete de Segurança Institucional)
- RECOMENDAÇÃO 12/2026 - Portal Gov.brGSI/CTIR Gov (Gabinete de Segurança Institucional)
- ALERTA 48/2026 — Gabinete de Segurança InstitucionalGSI/CTIR Gov (Gabinete de Segurança Institucional)
- RCE Pré-autenticado no JCE Pro — CVE-2026-48907CISC – Portal Gov.br
- Bravox Ransomware Attack on Meta in Brazil - DeXposeDeXpose
- META Data Breach in 2026BreachSense
- Payload Ransomware Strikes Brazilian Publisher Editora Irmãos VitaleDeXpose
- Editora Irmãos Vitale data breach — Payload ransomware leak (2026)DarkField (Orizon One)
- SpaceBears Ransomware Attack on Chebib ControlDeXpose
- APT73/Bashe Strikes Brazilian Government Portal Gov.brDeXpose
- Sistemas do governo registram cerca de 6.700 incidentes em ...Acessa.com / Folhapress
- Open Finance Brasil: nuevas reglas del Banco Central 2026Latam Fintech
