Brazil Health Surveillance Database Leaked: 79GB Sensitive Data Exposed
A critical security vulnerability was identified in Brazil’s health surveillance infrastructure, exposing 102,215 files containing 79GB of sensitive data.
What Data Was Compromised?
The exposed files were stored in publicly accessible directories, requiring no login credentials to access. These folders contained backups, uploads, and administrative files. Analysis revealed the following categories of information:
Categories of Information
- Personal details such as full names, addresses, phone numbers, and contact information
- Tax identification numbers for individuals (CPF) and businesses (CNPJ)
- Scanned copies of driver’s licenses, medical professional credentials, and federal identification cards
- Official documents featuring facial photographs and biometric data
- Business inspection reports, compliance records, and complaint logs
- Compressed backup files containing additional operational data
Why Digital Systems Introduce New Vulnerabilities
SISVISA was implemented in 2015 to streamline paper-based processes, enabling faster approvals for health-related business applications. However, the lack of proper security measures highlighted the inherent risks of digital infrastructure. Fowler noted that the database’s exposure could have been prevented through basic safeguards such as password protection, encryption, or restricted access controls.
“The database’s exposure could have been prevented through basic safeguards such as password protection, encryption, or restricted access controls,” said Jeremiah Fowler.
Recommendations for Affected Individuals
Individuals advised to monitor their financial accounts for unauthorized activity and avoid sharing personal information with unsolicited callers. Enabling multi-factor authentication for online services was also recommended to reduce the risk of account compromise.
The incident underscores the importance of robust security protocols in public health systems, particularly as digital transformation accelerates globally. Organizations handling sensitive data must prioritize access controls, regular audits, and incident response planning to prevent similar breaches.
