Serasa Experian Data Breach
Serasa Experian Brazilian Credit Bureau Breach (2021): 220 Million SSN & Name Records Exposed
Brazilian credit bureau and analytics company.
Risk Interpretation
Severe risk. This data can support identity theft, fraud, synthetic identity creation, financial manipulation, and long-term exploitation. Credit bureau exposures are especially harmful because the data is persistent and widely reused.
Impact & Downstream Threats
In January 2021 Brazilian cybersecurity firm PSafe uncovered a dataset of more than 220 million personal records being traded on dark web forums — immediately documented as the largest data breach in Brazilian history. The dataset included CPF numbers, full names, dates of birth, addresses, phone numbers, credit scores, income data, and vehicle records. The record count exceeded Brazil's living population because the dataset also encompassed deceased individuals. Serasa Experian denied its syste
- Identity theft and synthetic identity construction using government-issued IDs
Threat Vectors
Breach Intelligence
Executive Summary
Serasa Experian, Brazil's largest consumer credit bureau, became the focal point of what is documented as the largest data breach in Brazilian history when cybersecurity firm PSafe discovered more than 220 million personal records being traded on a dark-web forum in January 2021. The dataset, comprising roughly 1 terabyte of compressed files, was advertised for US $40,000 in Bitcoin and included a searchable web panel. The record count exceeded Brazil's living population because it included deceased individuals. No organisation has been proven liable. Serasa Experian stated that a forensic review found no evidence of unauthorized access to its core systems, though it acknowledged some data may have originated from its marketing systems. The exposed records included CPF numbers (Brazil's national tax identification equivalent to a Social Security Number), full names, dates of birth, addresses, phone numbers, email addresses, salary ranges, credit scores, and facial images. A separate tranche exposed data on 40 million Brazilian companies. Because credit bureau data is comprehensive, persistent, and widely reused across financial systems, the practical harm to affected individuals is severe. The combination of identity, financial, and biometric data in a single dataset creates conditions for identity theft, loan fraud, and synthetic identity schemes that can persist for years. Brazil's national data protection authority, the ANPD, launched a formal inquiry following the discovery. The Federal Police opened Operation Deepwater, a broader investigation that led to arrests in 2024. The Ministry of Justice opened an administrative case under Brazil's data protection law, the LGPD, which could result in substantial fines. A civil legal action was filed in the English High Court in January 2026. Affected individuals face long-term risk of financial fraud and identity exploitation, and should monitor their CPF records and credit activity closely.
About Serasa Experian
Serasa Experian is Brazil's largest consumer credit bureau and data analytics company, a subsidiary of the global Experian group. The company provides credit scoring, identity verification, fraud prevention, and marketing data services to Brazilian financial institutions, businesses, and government entities. It holds comprehensive financial and identity records on virtually the entire Brazilian adult population, sourced through mandatory credit reporting obligations and commercial data partnerships.
Why They Hold Your Data
Credit reporting and analytics firms aggregate highly sensitive identity, financial, contact, and scoring-related data across large populations for risk assessment, lending, and consumer reporting.
Recent Developments
Serasa Experian has faced sustained regulatory pressure in Brazil over its data commercialization practices separate from the 2021 incident. Brazilian courts have at various points ordered the company to restrict data sales, and its practices have been the subject of ongoing scrutiny under the LGPD. In January 2026 London law firm Mishcon de Reya filed a group action in the English High Court against the Serasa Experian group on behalf of affected Brazilians, with registration still open as of early 2026.
Data Points Exposed
Exposure Categories
Canonical Fields
full_name, ssn
Dark Web Verification
- Dataset containing ~223.7M records identified in breach intelligence sources
- Data indexed and searchable across breach notification platforms
- Source: serasa-experian-2020
Recommended Actions
⚠️ Do not assume this is low sensitivity.
Protect Yourself
Check If You’re Affected
Enter your email to check if your data appears in this breach.
Get Free Breach Alerts
Be the first to know when new breaches are disclosed.
High-Risk? Get an Exposure Audit
Full-spectrum exposure audits for executives and public figures.
ObscureIQ Advisory
We combine proprietary dark web access with commercial and restricted breach intelligence to verify exposure and assess real-world risk.
- A public-facing individual
- A high-profile executive
- A customer of Serasa Experian
- Or concerned about credential reuse
Powered by the ObscureIQ Breach Intelligence Database
© 2026 ObscureIQ · All Rights Reserved · Data Licensing
Latest from ObscureIQ
What Is Credit Monitoring? And Do I Want It? (Answer: Not Really)
Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars.
Sextortion Spam
