[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2kqjcdem3o92d":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":14,"contentUpdatedAt":15,"source":16,"sourceUrl":17,"sourceUrls":18,"pwnCount":24,"affectedCount":24,"affectedCountStatus":25,"affectedCountLowerBound":13,"affectedCountUnit":26,"hasEnglishDescription":4,"contentLocale":27,"availableLocales":28,"translations":30,"severity":33,"dataClasses":34,"description":39,"seoTitle":8,"seoDescription":40,"logoUrl":41,"isVerified":42,"isSensitive":4,"isSpamList":42,"isMalware":42,"company":43},"6a469e59553ca41c9dce5f47","SerasaExperianBrazil2020","Serasa Experian Brazil (2020) Alleged Data Exposure","serasa-experian-brazil-2020","serasaexperian.com.br","2020-12-01T00:00:00.000Z","2021-01-20T00:00:00.000Z",null,"2026-09-17T16:27:41.515Z","2026-07-19T00:10:03.667Z","Unverified breach record","https:\u002F\u002Fwww.zdnet.com\u002Farticle\u002Fmassive-data-leak-in-brazil-exposes-all-citizens\u002F",[17,19,20,21,22,23],"https:\u002F\u002Fsynscan.net\u002Fbreaches\u002Fserasa-experian","https:\u002F\u002Ftecnoblog.net\u002Fnoticias\u002Fmegavazamento-de-cpfs-tinha-algo-que-nao-e-normal-ser-organizado-demais\u002F","https:\u002F\u002Fportal.fgv.br\u002Fartigos\u002Fmaior-vazamento-dados-pessoais-historia-brasileira-e-quais-licoes-devemos-aprender","https:\u002F\u002Fdatabreaches.net\u002F2021\u002F02\u002F22\u002Fexperian-challenged-over-massive-data-leak-in-brazil\u002F","https:\u002F\u002Fwww.opendemocracy.net\u002Fen\u002Flargest-personal-data-leakage-brazilian-history\u002F",223739215,"known","email_identifiers","en",[27,29],"tr",{"en":31,"tr":32},{"slug":9},{"slug":9},"Critical",[35,36,37,38],"Names","Dates of birth","Genders","Government issued IDs","\u003Cp>The Serasa Experian Brazil 2020 data breach is a large-scale personal data leak associated with the identity data of Brazilian citizens, reported to have affected 223,739,215 people. The incident dates back to late 2020 and became publicly visible in January 2021. The dataset has been referred to under the name Serasa Experian, which operates in the credit bureau and data brokerage sector; however, it has not been definitively confirmed that the incident originated directly from company systems. The company stated that there is no evidence that their systems were compromised, whereas consumer agencies and security researchers have indicated that due to the scope of the data, the incident needs to be seriously investigated. Therefore, the record should be considered a high-risk data breach for user security, but with a limited level of verification.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>Verified data classes are name information, dates of birth, gender information, and government-issued identification numbers. In the context of Brazil, identification numbers like CPF are the most critical area because they serve as the primary identifier in a person's financial, administrative, and digital transactions. When combined with name, date of birth, and gender information, a strong profile is created for identity verification, fraud, and fake application scenarios. Even if password or payment card data is not verified, such identity data poses a long-term risk because it does not change over the years.\u003C\u002Fp>\n\u003Cp>Data breaches containing identification numbers are different from classic account password leaks. Passwords can be changed, but identification numbers and birth dates are permanent for most people. This information can be used in attacks such as fraudulent credit applications, account opening, financial fraud, social engineering, fake customer service calls, and impersonation of official institutions. In addition, when combined with other datasets, information such as name, birth date, and gender increases the likelihood of matching a person's address, phone number, income, or social profile information. Therefore, the Serasa Experian Brazil 2020 record carries sensitive personal data risk even if it does not contain passwords.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified scope at the record level is related to 223,739,215 individuals. The data date was considered as the end of 2020, and the public reflection date was evaluated as January 2021. The verified main fields are name, date of birth, gender, and identity number. In some news and research assessments, address, phone, credit score, income, vehicle information, and other personal fields were mentioned; however, in this data class list, only fields that can be verified at the record level are retained. This approach was a conscious choice to avoid presenting unverified fields to the user as definite data.\u003C\u002Fp>\n\u003Cp>The citation limit should also be kept open. The dataset has circulated under the name Serasa Experian, and many observers have pointed to this institution due to the nature of the data. Nevertheless, it has not been confirmed that the company's systems were compromised or that the data came directly from the company's database. Therefore, the source field should be marked as an unverified breach record. For the user, this distinction does not mean that the risk is low. In cases involving permanent information such as identity numbers and birth dates, the source being disputed is not a justification for delaying defensive measures.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>The highest risk group includes individuals in Brazil who have an identity number, credit profile, or consumer record. It has been reported that the dataset may contain records of deceased individuals as well as living ones; this situation can increase the risks of inheritance, family, telephone line, and financial fraud. Since the identity number and date of birth can still be asked as auxiliary identifiers during support line calls or online verification processes, it can strengthen the attacker’s position. Fake applications in a person's name, fake debt notifications, or messages impersonating official institutions can become more convincing.\u003C\u002Fp>\n\u003Cp>The second risk group consists of individuals whose identity information can be matched with other datasets through email, phone, or address. Even if the email or phone field in this dataset is not kept as a definite data class, a broader profile can emerge when the name and identity number are combined with other leaks. Therefore, those using financial services, applying for credit, owning a mobile line, and citizens benefiting from public services should be careful. Additionally, messages themed around payments, debts, parcels, health, or official notifications sent on behalf of family members may also attempt to appear trustworthy by being supported with identity data.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>The first step is to increase the level of scrutiny against unexpected messages that come with identification numbers and personal information. Users should not directly trust messages themed around credit, debt, payment, government aid, taxes, banks, phone lines, or official documents. The fact that the name, date of birth, or identification number in the message is correct alone is not proof of reliability. Requests coming on behalf of financial institutions, telecom operators, or public agencies should be verified through a separate channel via the official website or verified call center.\u003C\u002Fp>\n\u003Cp>The second step is the regular monitoring of financial and administrative activities. Credit applications, bank notifications, phone line transactions, and official institution alerts should be tracked. If a suspicious application or transaction is noticed, quick contact should be made with the relevant institution, and if possible, an official objection process should be initiated. Users should not share details such as identity numbers, birth dates, or family information over the phone. At the same time, the security of email accounts and mobile lines should be strengthened, and multi-factor authentication should be enabled for critical accounts that support it.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>A long-term strategy for this type of identity data leak goes beyond just changing passwords. Users should regularly review their financial transactions, credit applications, and identity verification processes. Strong passwords, multi-factor authentication, and transaction notifications should be used on bank and telecom accounts. Immutable information such as ID numbers or birth dates should not be preferred as security elements in account recovery questions. Where possible, additional passwords, security keys, or app-based authentication should be used.\u003C\u002Fp>\n\u003Cp>For institutions, the lesson is clearer: datasets containing identity data should be protected with the principle of least access, the data retention period should be reduced, and unnecessary copies should be eliminated. In relationships with providers and data intermediaries, it should be regularly audited which information is stored where, for how long, and who has accessed it. Users, on the other hand, should question data sharing with every new service that requests their personal information, avoid filling in unnecessary fields, and keep notification systems open whenever possible. Mitigation for permanent identity data requires constant attention and regular monitoring.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>Serasa Experian Brazil 2020 check on LeakData helps you understand whether your information is linked to this data breach. If the result is positive, first monitor financial and administrative transactions related to your ID number more frequently. Do not click on links in unexpected credit, debt, phone line, tax, courier, or utility messages; verify the request through a separate and reliable channel. Do not share your personal information over the phone or in messages. Use strong passwords and multi-factor authentication on your bank, email, and mobile accounts.\u003C\u002Fp>\n\u003Cp>Since this breach did not involve a password, simply changing the password is not an adequate response. The main risk is that identity data can be used for fraud and social engineering for a long time. Information such as name, date of birth, gender, and ID number can be used in fake applications or identity impersonation attempts even years later. Therefore, keeping financial notifications open, reporting suspicious transactions quickly, being cautious against messages impersonating official institutions, and reducing personal data sharing are the foundations of long-term protection.\u003C\u002Fp>","Serasa Experian Brazil (2020) Alleged Data Exposure. 223.7 Million email identifiers are reported. Reported data: Names, Dates of birth, Genders. Review the…","\u002Fuploads\u002Flogo\u002Fserasa-experian-brazil-2020.svg",false,{"name":44,"sector":45,"country":46,"website":10,"websiteArchiveUrl":47,"websiteStatus":47,"websiteCheckedAt":13},"Serasa Experian","Credit bureau \u002F Data broker","Brazil",""]