[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5oc1q2aodi5h":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":28,"seoTitle":15,"seoTitleEn":29,"seoDescription":15,"seoDescriptionEn":30,"logoUrl":31,"isVerified":4,"isSensitive":4,"isSpamList":32,"isMalware":32,"company":33},"68e3266eda11adda4882517e","descomplica","Descomplica Data Breach","descomplica.com.br","2021-03-14T00:00:00.000Z","2021-04-28T08:37:04.000Z","2026-07-02T12:26:55.059Z","2026-07-18T23:49:33.790Z","Third party breach","",[],4845378,"known",null,"unknown","Critical",[23,24,25,26,27],"Email addresses","Names","Partial credit card data","Passwords","Purchases","\u003Cp>Descomplica is a Brazil-based online education and exam preparation platform. The breach in March 2021 affected approximately 4.8 million unique email addresses, along with full names, partial payment card information, purchase history, and password hashes.\u003C\u002Fp>\u003Cp>This record should be evaluated in the context of the educational platform; however, fields such as unverified CPF, educational background, or student grades should not be portrayed as if they have been leaked. Partial card information refers to limited fields such as the first six and last four digits and the expiration date, and should not be considered sufficient on its own for making a full payment.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The data classes tracked in Descomplica records should be treated as email addresses, name-surname information, partial payment card information, password data, and purchase records. Email addresses can be used for targeted phishing, password reset schemes, and account matching across different services. Name-surname information makes fake support, fake delivery, fake invoice, and customer service messages more convincing. Partial payment card information, although not sufficient on its own to make a payment, can be used to gain trust in fake card verification or refund messages. Password data, especially if the same password is reused on other services, directly increases the risk of account takeover. Purchase records can make messages using past orders, returns, warranty, or product support as pretexts more convincing.\u003C\u002Fp>\u003Cp>When the context of education and payment is combined, messages about fake subscriptions, exam preparation packages, refunds, payment verification, or student support become more convincing. Password hashes pose a risk to other accounts when weak passwords are reused.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>This record is associated with the descomplica.com.br domain and an incident in March 2021. The scope is limited to email addresses, full names, partial payment card information, password hashes, and purchase records. Full card numbers, CPF, educational grades, or identity documents are not verified data classes for this record.\u003C\u002Fp>\u003Cp>Areas not present in this record should not be described as if they have leaked. Full payment cards, official identification, private messages, health data, bank information, device content, or data belonging to other platforms should only be included in the risk assessment if they are explicitly present in the record. The text is based on verifiable data classes and the known boundaries of the incident.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Descomplica users, students who use the same email address on other educational services, account holders who repeat old password patterns, and users who respond quickly to payment or subscription messages are at higher risk.\u003C\u002Fp>\u003Cp>Users who use the same email address on different services, reuse their old passwords, keep their nicknames the same across many communities, or do not separate their work and personal accounts are at higher risk. The risk in profile and data broker records arises from the combination of very different domains from a single account, creating detailed context about the person.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users should renew their Descomplica password and any other accounts where the same password is used. Payment, refund, or education package update messages should be verified from the official account; full card information or verification codes should not be shared.\u003C\u002Fp>\u003Cp>Users in the positive match area should renew their passwords on accounts where they use the same or similar passwords, enable two-factor authentication where possible, and check their recent sessions. Records that do not contain passwords but include contact, billing, address, or profile data should be monitored for unexpected calls, offers, support, billing, and verification messages.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>In the long term, the habit of using a password manager, unique passwords, two-factor authentication, and removing unnecessary personal information from accounts reduces risk. Reusing the same email address across different platforms makes it easier to combine data from different breaches; using a separate email or alias for critical accounts can be considered.\u003C\u002Fp>\u003Cp>Email addresses used on educational platforms can remain active for a long time. Users should consider using unique passwords, separate emails, and two-step verification for their educational and payment accounts.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>LeakData check indicates whether the queried email address is present in this record. A positive result does not necessarily mean that all data fields definitely belong to that user; however, it is a sufficient warning for precautionary measures. A negative result only indicates that there is no match in this dataset and does not eliminate the possibility of appearing in other breaches.\u003C\u002Fp>\u003Cp>A positive result indicates that the email address is found in the Descomplica dataset. Partial card information requires caution regarding both account security and payment fraud due to purchase and password context.\u003C\u002Fp>","Descomplica Data Breach (4.8 Million Reported Records)","Descomplica Data Breach. 4.8 Million reported records were reported. Reported data: Email addresses, Names, Partial credit card data. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Fdescomplica_com_br.webp",false,{"name":34,"sector":35,"country":36,"website":9,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"Descomplica","EdTech \u002F Online Education","Brazil"]