986,237 Records From Brazil 9: Who Was Exposed and What Was Taken
HEROIC analysts tracked the Brazil 9 stealer log file shared on Telegram in February 2023. The breach exposed 986,237 records from Brazilian user accounts, including email addresses, plaintext passwords, and URL data collected from compromised devices across multiple platforms.
The Brazil 9 File Joins a Pattern of Targeted Brazilian Data Theft
The Brazil 9 breach is part of a recurring pattern of stealer log files specifically targeting Brazilian users. Attackers repeatedly focus on Brazil's large digital economy, collecting credentials from Brazilian banking apps, e-commerce accounts, and popular local platforms for use in financial fraud.
What the Brazil 9 Leak Exposed
- Email Addresses
- Plaintext Passwords
- URLs (endpoint context)
How Nearly 1 Million Stolen Brazilian Credentials Enable Mass Fraud
With close to a million credential pairs, the Brazil 9 breach gives attackers an enormous pool for automated account takeover campaigns. Brazilian banking portals, Pix payment accounts, and popular local e-commerce sites are primary targets for fraud when this scale of regional credentials is compromised.
How Stealer Log Breaches Work
Stealer logs are produced by malware silently installed on victims' computers. The malware captures usernames, passwords, and browser session data before sending it to criminals, who then package and sell the data on Telegram channels and dark web markets.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches over 400 billion+ leaked records to tell you if your email was part of this or any other stealer log dump. Check your exposure now at no cost.
Breach Breakdown
986,237 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds