Descomplica 2021.0 Data Breach

Descomplica Brazilian EdTech Platform Breach (2021): 4.8 Million Student Records Including Partial Credit Card Data & Purchase History Exposed | ObscureIQ
ObscureIQ Breach Intelligence

Classification Tags

EducationCredit CardEmail AddressFull NamePasswordTransaction History
Low SeverityWebsite / service breach

Descomplica Brazilian EdTech Platform Breach (2021): 4.8 Million Student Records Including Partial Credit Card Data & Purchase History Exposed

Brazilian online education platform.

Verified by ObscureIQ Intelligence
19/100Breach Risk Index
10Data Value
10Market Recency
1897dSince Breach

Breach Intelligence Summary

Entity: Descomplica · Actor: Unknown · Sources: 5 references
Attack: Unknown
Profile: Platform · Online education services · Digital learning platform · Brazil
Timeline: Breach (2021-03-14) · Indexed (Apr 28, 2021) · Year (2021.0)
Exposure: 4.8M records · 5 fields: Credit Card, Email Address, Full Name, Password, Transaction History
Status: Confirmed

Executive Summary

In March 2021, the Brazilian EdTech company Descomplica suffered a data breach posted to a hacking forum, exposing nearly 5 million records. Exposed data included email addresses, names, partial credit-card data (first six and last four digits plus expiry), purchase histories, and password hashes. Additional data such as CPF (national ID), academic records, and phone numbers may also have been leaked.

ObscureIQ assessment: Primary risks include account takeover, phishing, and credential reuse. Educational affiliation and progress data can also be used for targeted scams aimed at students and families.

Breach Impact

Partial card data plus purchase history and identity supports card-fraud reconnaissance and targeted phishing; if the reported CPF/academic data is accurate, identity-fraud risk rises further.

About Descomplica

Descomplica is a major Brazilian education-technology (EdTech) platform offering online courses and exam prep.

Why They Hold Your Data

Digital learning platforms collect student accounts, emails, passwords, progress data, billing information, and educational engagement records tied to online instruction and test preparation.

Data Points Exposed

5 verified field types
Credit Card Critical
Email Address
Full Name High
Password Critical
Transaction History High

Field names are shown in full for clarity and search visibility. Canonical machine keys are emitted only in this page’s structured data.

Exploitation & Downstream Threats

Threat Activity:High
Primary downstream threats:
  • Credential stuffing against reused passwords across other platforms
  • Financial fraud using exposed financial profile data
  • Targeted phishing campaigns using exposed email addresses
Threat vectors:
  • Card-present & card-not-present fraud
  • Card identification & social engineering
  • Phishing, credential stuffing & account takeover
  • Name-based social engineering
  • Credential stuffing & account takeover
  • Lifestyle profiling & targeted fraud

Recommended Actions

If you believe your information may be included:

Change Reused Passwords
Update this account and anywhere you reused the password; use a manager.
Enable MFA Everywhere
Turn on multi-factor authentication on email first, then financial accounts.
Report & Recover
If you spot misuse, start an official recovery plan and report fraud.

Frequently Asked Questions

What happened in the Descomplica breach?

In March 2021, the Brazilian EdTech company Descomplica suffered a data breach posted to a hacking forum, exposing nearly 5 million records. Exposed data included email addresses, names, partial credit-card data (first six and last four digits plus expiry), purchase histories, and password hashes.…

What data was exposed?

Verified fields include Credit Card, Email Address, Full Name, Password, Transaction History.

What should I do if I was affected?

Change reused passwords, enable MFA, and (if identity or financial data is involved) freeze your credit and monitor your accounts.

Sources & References

Every claim on this page is traceable. This breach draws on:

Breach Index
Have I Been Pwned
Record & field corroboration
Cross-source
9ghz
Independent catalogue listing
Cross-source
BreachForums_Official_Index
Independent catalogue listing
Cross-source
Dehashed
Independent catalogue listing
ObscureIQ Intelligence
ObscureIQ proprietary analysis
Risk Index scoring & downstream-threat assessment

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation