CRITICAL SEVERITYFinancial

Serasa Experian Data Breach

Serasa Experian Brazilian Credit Bureau Breach (2021): 220 Million SSN & Name Records Exposed

Brazilian credit bureau and analytics company.

Verified by ObscureIQ Intelligence

10.0Severity
223.7MRecords
2Fields
2021Year

ObscureIQ Breach Intelligence Scores
0.0
Breach Risk Index
30
Data Value
0
Market Recency
0
days
Since Breach

Risk Interpretation

Severe risk. This data can support identity theft, fraud, synthetic identity creation, financial manipulation, and long-term exploitation. Credit bureau exposures are especially harmful because the data is persistent and widely reused.

🎯 Impact & Downstream Threats

In January 2021 Brazilian cybersecurity firm PSafe uncovered a dataset of more than 220 million personal records being traded on dark web forums — immediately documented as the largest data breach in Brazilian history. The dataset included CPF numbers, full names, dates of birth, addresses, phone numbers, credit scores, income data, and vehicle records. The record count exceeded Brazil's living population because the dataset also encompassed deceased individuals. Serasa Experian denied its syste

Primary downstream threats:
  • Identity theft and synthetic identity construction using government-issued IDs

🔓 Threat Vectors

Name-based social engineering
Full identity theft & synthetic identity fraud

📋 Breach Intelligence

EntitySerasa Experian
OrganizationPrivate Company • Brazil
Breach Date2021-01-20
DBC Added2025-01-04
Records~223.7M (223,739,216 records)
Attack VectorSocial Engineering
Data SubjectsCitizen
Breach PathwayDirect
SourceDataBreach.com / ObscureIQ
SensitivityStandard
Breach ID1181.0
StatusConfirmed

📝 Executive Summary

Serasa Experian, Brazil's largest consumer credit bureau, became the focal point of what is documented as the largest data breach in Brazilian history when cybersecurity firm PSafe discovered more than 220 million personal records being traded on a dark-web forum in January 2021. The dataset, comprising roughly 1 terabyte of compressed files, was advertised for US $40,000 in Bitcoin and included a searchable web panel. The record count exceeded Brazil's living population because it included deceased individuals. No organisation has been proven liable. Serasa Experian stated that a forensic review found no evidence of unauthorized access to its core systems, though it acknowledged some data may have originated from its marketing systems. The exposed records included CPF numbers (Brazil's national tax identification equivalent to a Social Security Number), full names, dates of birth, addresses, phone numbers, email addresses, salary ranges, credit scores, and facial images. A separate tranche exposed data on 40 million Brazilian companies. Because credit bureau data is comprehensive, persistent, and widely reused across financial systems, the practical harm to affected individuals is severe. The combination of identity, financial, and biometric data in a single dataset creates conditions for identity theft, loan fraud, and synthetic identity schemes that can persist for years. Brazil's national data protection authority, the ANPD, launched a formal inquiry following the discovery. The Federal Police opened Operation Deepwater, a broader investigation that led to arrests in 2024. The Ministry of Justice opened an administrative case under Brazil's data protection law, the LGPD, which could result in substantial fines. A civil legal action was filed in the English High Court in January 2026. Affected individuals face long-term risk of financial fraud and identity exploitation, and should monitor their CPF records and credit activity closely.

🏢 About Serasa Experian

Serasa Experian is Brazil's largest consumer credit bureau and data analytics company, a subsidiary of the global Experian group. The company provides credit scoring, identity verification, fraud prevention, and marketing data services to Brazilian financial institutions, businesses, and government entities. It holds comprehensive financial and identity records on virtually the entire Brazilian adult population, sourced through mandatory credit reporting obligations and commercial data partnerships.

Company | Credit reporting and financial data analytics | Data aggregation and scoring services | Brazil
Private CompanyBrazilserasaexperian.com.br

🗂 Why They Hold Your Data

Credit reporting and analytics firms aggregate highly sensitive identity, financial, contact, and scoring-related data across large populations for risk assessment, lending, and consumer reporting.

📰 Recent Developments

Serasa Experian has faced sustained regulatory pressure in Brazil over its data commercialization practices separate from the 2021 incident. Brazilian courts have at various points ordered the company to restrict data sales, and its practices have been the subject of ongoing scrutiny under the LGPD. In January 2026 London law firm Mishcon de Reya filed a group action in the English High Court against the Serasa Experian group on behalf of affected Brazilians, with registration still open as of early 2026.

🔍 Data Points Exposed

2 verified field types:
Social Security Number
Name

Exposure Categories

CredentialsSSN

Canonical Fields

full_name, ssn

🌐 Dark Web Verification

Confirmed
  • Dataset containing ~223.7M records identified in breach intelligence sources
  • Data indexed and searchable across breach notification platforms
  • Source: serasa-experian-2020

🛡 Recommended Actions

⚠️ Do not assume this is low sensitivity.

1Freeze Your Credit
Place a credit freeze with Equifax, Experian, and TransUnion.
2Expect Targeted Phishing
Watch for emails referencing this breach. Verify through official channels.
3Enable MFA Everywhere
Enable multi-factor authentication on all accounts.
4Monitor Accounts
Watch for unauthorized activity on financial and personal accounts.
5Check Your Exposure
ObscureIQ clients: this breach is indexed in your profile.

Protect Yourself

Check If You’re Affected

Enter your email to check if your data appears in this breach.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed.

High-Risk? Get an Exposure Audit

Full-spectrum exposure audits for executives and public figures.

Request Consultation

ObscureIQ Advisory

We combine proprietary dark web access with commercial and restricted breach intelligence to verify exposure and assess real-world risk.

If you are:
  • A public-facing individual
  • A high-profile executive
  • A customer of Serasa Experian
  • Or concerned about credential reuse
Services
AuditsWipesThreat MonitoringTraining

Classification Tags

Social EngineeringFinancial

Powered by the ObscureIQ Breach Intelligence Database

© 2026 ObscureIQ · All Rights Reserved · Data Licensing

Latest from ObscureIQ

Credit

What Is Credit Monitoring? And Do I Want It? (Answer: Not Really)

July 14, 2025
Every time there’s a major data breach, companies scramble to offer “free” credit monitoring. It sounds like a responsible move.…
breach economycredit freezecredit scoreequifaxexperian
Credible Threats

Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars.

September 2, 2025
Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars. Over 80% of security incidents now start in the browser. Chrome.…
brave browserbreachesbrowser exploitbrowserschrome
Analysis

Sextortion Spam

May 10, 2025
Sextortion scams aren’t new, but they remain one of the most effective forms of cyber-enabled fraud. These scams don’t rely…
bitcoindeadlinefeargoogle maps apiransom