[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3ey4glo3nphhh":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":14,"contentUpdatedAt":15,"source":16,"sourceUrl":17,"sourceUrls":18,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":13,"affectedCountUnit":21,"hasEnglishDescription":4,"contentLocale":22,"availableLocales":23,"translations":25,"severity":28,"dataClasses":29,"description":39,"seoTitle":40,"seoDescription":41,"logoUrl":42,"isVerified":43,"isSensitive":4,"isSpamList":43,"isMalware":43,"company":44},"6a46d22d0f7da8d662ce5f47","Engrenagem Virtual 2020","Engrenagem Virtual (2020) Data Breach","engrenagem-virtual-2020","engrenagemvirtual.com.br","2020-07-01T00:00:00.000Z","2026-07-02T21:03:41.953Z",null,"2026-09-19T17:08:19.658Z","2026-07-19T00:10:05.841Z","Third party breach","",[],430936,"known","email_identifiers","en",[22,24],"tr",{"en":26,"tr":27},{"slug":9},{"slug":9},"High",[30,31,32,33,34,35,36,37,38],"Email addresses","Names","Phone numbers","Dates of birth","Genders","Marital statuses","Password salts","Password hash metadata","Passwords","\u003Cp>The Engrenagem Virtual data breach is a critical account security incident dated July 2020, associated with the domain engrenagemvirtual.com.br, which is linked to Brazil-based online education, marketing, and digital business development services. This record was added as a unique incident supported by a volume of 430,936 records. The record contained email addresses, names, phone numbers, dates of birth, gender information, marital status fields, password salt information, password hash information, and passwords; unsupported claims regarding official identification documents, payment cards, or bank accounts were left out to avoid misleading the user.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>In the verification assessment, the name Engrenagem Virtual, the domain engrenagemvirtual.com.br, the time of July 2020, a record volume of over 430 thousand, and the appearance of password hash information in salted SHA-256 format along with personal profile fields were taken into account. Heavier claims such as the CPF or official identity field were not consistently supported, so they were not added to the record. This record was maintained as an account security and personal profile data incident; it was not expanded with unsupported financial or official document claims.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The Virtual Gear data breach creates risks for users including account takeover, education\u002Fmarketing-themed phishing, and targeted social engineering. When email, name, phone number, date of birth, gender, and marital status fields are combined, attackers can tailor messages for individual-specific training, business development, subscriptions, certifications, or campaigns. Since there is a hashed password field, there is also a risk of the same or weak passwords being tried on other services. Therefore, the incident should not be considered merely as a contact list.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>In this incident, visible data classes are important in terms of personal profile and account security. The date of birth can be misused in support desk verifications. The phone number facilitates targeting via SMS and calls. Profile fields such as marital status and gender can be used to personalize messages. The salted SHA-256 password hash information does not completely eliminate the risk of offline guessing in weak or reused passwords.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>People who have a Virtual Gear account or use the same email address should reset their passwords on the relevant account and on other accounts where the same password is used. Email, education platforms, social media, shopping, payment, and work accounts should be checked first. Multi-factor authentication should be enabled wherever possible, old sessions should be closed, and unexpected login alerts should be reviewed. Certificate, course, subscription, or campaign links should be verified directly through known official channels.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>For institutions, the Engrenagem Virtual data breach shows that profile data and password security should be protected together on educational and digital marketing platforms. Support teams should not make account changes using only a name, phone number, or date of birth. Additional verification is required for actions such as email changes, account recovery, subscription updates, and certificate access. Institutions should clearly explain to users how to distinguish fake training invitations or campaign messages and encourage them to discontinue the use of old passwords.\u003C\u002Fp>\u003Cp>In the Virtual Gear data breach record, the scope was limited to supported fields. The record was kept as 430,936 entries; no claim of official ID, payment card, or bank account being present was added. The data classes are limited to email, name, phone, date of birth, profile fields, and hashed password information. Nonetheless, the combination of personal profile data and password hash fields presents a critical account security risk. If the same password is used on other accounts, the impact may not be confined to the relevant platform.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>The overall risk level has been assessed as critical because the Engrenagem Virtual data breach combines personal profile fields with phone and hashed password risk. The most practical steps for users searching for the Engrenagem Virtual data breach are to reset passwords, avoid reusing the same password, enable additional verification on email and important accounts, independently verify training\u002Fcampaign links, and not trust messages coming with correct personal information. The record has been prepared to explain the actual account security impact without adding unsupported data types.\u003C\u002Fp>","Engrenagem Virtual (2020) Data Breach (430.9 Thousand Email Identifiers)","Engrenagem Virtual (2020) Data Breach. 430.9 Thousand email identifiers are reported. Reported data: Email addresses, Names, Phone numbers. Review the scope…","\u002Fuploads\u002Flogo\u002Fengrenagem-virtual-2020.svg",false,{"name":45,"sector":46,"country":47,"website":10,"websiteArchiveUrl":17,"websiteStatus":17,"websiteCheckedAt":13},"Engrenagem Virtual","Education \u002F Digital marketing","Brazil"]