Serasa Experian 2021 Data Breach

Serasa Experian Brazilian Credit Bureau Breach (2021): 220 Million SSN & Name Records Exposed

Company · Credit reporting and financial data analytics · Data aggregation and scoring services · Brazil

Serasa Experian Brazilian Credit Bureau Breach (2021): 220 Million SSN & Name Records Exposed

Brazilian credit bureau and analytics company.

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
58/100
Lower riskHigher risk
Moderate: notable exposure with meaningful misuse potential.
Data Sensitivity i
Elevated
Exposed data raises the risk of fraud, targeting, and impersonation. Proactive steps are warranted.
223.7MRecords
2021Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
SSNSocial Security Number
Classification Tags
Social EngineeringFinancial ServicesCitizen2021

Breach Summary

Serasa Experian, Brazil's largest consumer credit bureau, became the focal point of what is documented as the largest data breach in Brazilian history when cybersecurity firm PSafe discovered more than 220 million personal records being traded on a dark-web forum in January 2021. The dataset, comprising roughly 1 terabyte of compressed files, was advertised for US $40,000 in Bitcoin and included a searchable web panel. The record count exceeded Brazil's living population because it included deceased individuals. No organisation has been proven liable. Serasa Experian stated that a forensic review found no evidence of unauthorized access to its core systems, though it acknowledged some data may have originated from its marketing systems. The exposed records included CPF numbers (Brazil's national tax identification equivalent to a Social Security Number), full names, dates of birth, addresses, phone numbers, email addresses, salary ranges, credit scores, and facial images. A separate tranche exposed data on 40 million Brazilian companies. Because credit bureau data is comprehensive, persistent, and widely reused across financial systems, the practical harm to affected individuals is severe. The combination of identity, financial, and biometric data in a single dataset creates conditions for identity theft, loan fraud, and synthetic identity schemes that can persist for years. Brazil's national data protection authority, the ANPD, launched a formal inquiry following the discovery. The Federal Police opened Operation Deepwater, a broader investigation that led to arrests in 2024. The Ministry of Justice opened an administrative case under Brazil's data protection law, the LGPD, which could result in substantial fines. A civil legal action was filed in the English High Court in January 2026. Affected individuals face long-term risk of financial fraud and identity exploitation, and should monitor their CPF records and credit activity closely.

Full threat analysis, exploitation vectors, and principal guidance below.

10 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

223.7M records analyzed

About Serasa Experian

Serasa Experian is Brazil's largest consumer credit bureau and data analytics company, a subsidiary of the global Experian group. The company provides credit scoring, identity verification, fraud prevention, and marketing data services to Brazilian financial institutions, businesses, and government entities. It holds comprehensive financial and identity records on virtually the entire Brazilian adult population, sourced through mandatory credit reporting obligations and commercial data partnerships.

Why They Hold Your Data

Credit reporting and analytics firms aggregate highly sensitive identity, financial, contact, and scoring-related data across large populations for risk assessment, lending, and consumer reporting.

Recent Developments

Serasa Experian has faced sustained regulatory pressure in Brazil over its data commercialization practices separate from the 2021 incident. Brazilian courts have at various points ordered the company to restrict data sales, and its practices have been the subject of ongoing scrutiny under the LGPD. In January 2026 London law firm Mishcon de Reya filed a group action in the English High Court against the Serasa Experian group on behalf of affected Brazilians, with registration still open as of early 2026.

Data Points Exposed

2 verified field types
Full Name
Social Security Number Critical

Breach Impact

In January 2021 Brazilian cybersecurity firm PSafe uncovered a dataset of more than 220 million personal records being traded on dark web forums — immediately documented as the largest data breach in Brazilian history. The dataset included CPF numbers, full names, dates of birth, addresses, phone numbers, credit scores, income data, and vehicle records. The record count exceeded Brazil's living population because the dataset also encompassed deceased individuals. Serasa Experian denied its systems had been directly compromised, stating its forensic investigation found no evidence of unauthorized access and that some of the data may have originated from its non-sensitive marketing systems. Brazil's ANPD launched a formal inquiry. The Federal Police opened Operation Deepwater, which evolved into a broader investigation resulting in arrests in 2024. The Ministry of Justice opened an administrative case under the LGPD that could trigger significant fines. The Mishcon de Reya English High Court action, filed in January 2026, represents the most recent formal legal consequence of the incident.

Exploitation & Downstream Threats

• Identity theft and synthetic identity construction using government-issued IDs

Principal Risk Advisory

What this means for a principal

A financial-institution breach: account, wealth or payment data supports direct fraud and highly credible financial-impersonation scams. For a high-profile principal the main risk is credible impersonation and enrichment of existing exposure.

What You Should Do

  1. Freeze credit at all three bureaus and monitor for new-account and tax-refund fraud.
  2. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping: cross-reference the exposed identifiers against broker-available data to size and prioritize the principal's wider footprint.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation