← Blog

PagBank Data Breaches: Full Timeline Through 2026

Share on X

People search PagBank data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 3 PagBank-linked incidents (1 company-confirmed), with headline counts up to 1M+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.

Why PagBank breach history matters

PagBank operates in Financial Services / Fintech (Brazil). Across indexed rows, recurring themes include cloud and database misconfiguration, unverified actor or scraping claims. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.

Full timeline through 2026

2026 — hacking-forum database claim; 812k transaction records (unverified)

Unverified claim — treat actor counts cautiously. Unverified breach-forum / database sale claim — observed July 12, 2026. Threat-intelligence firm VenariX reported on X that a database allegedly linked to Brazilian fintech PagBank was circulating on a hacking forum, citing more than 812,000 transaction records with merchant names, transaction amounts, payment types, last four digits of payment cards, and authorization codes. PagBank (PagSeguro Digital Ltd.), a major Brazil digital bank and payment network under the UOL Group, had not issued a matching public breac Exposed categories include Threat-intelligence reporting (VenariX, Jul 12, 2026) described actor-claimed 812,000+ transaction records including merchant names, amounts, payment types, last four digits of pay. BreachHistory cites approximately 812K+ affected records in this row. See the pagbank-forum 2026 record and canonical BreachHistory entry.

2026 — forum transaction-database claim; 812k+ rows cited (unverified)

Unverified claim — treat actor counts cautiously. Unverified criminal-forum claim — observed July 12, 2026. DailyDarkWeb documented a threat actor claiming unauthorized access to PagBank, one of Brazil's largest payment service providers, alleging compromise of core infrastructure, 250,000+ active merchants, and more than one billion historical transaction records with merchant settlement metadata and POS terminal identifiers—marketing language without independent sample verification at report time. Separately, VenariX cited a forum database allegedly linked to Pa Exposed categories include Threat-intel reporting cites actor-claimed transaction records including merchant names, amounts, payment types, last four digits of payment cards, and authorization codes; separat. BreachHistory cites approximately 812K+ affected records in this row. See the pagbank-forum-transactions 2026 record and canonical BreachHistory entry.

2021 — Wirecard Brazil server breach; ~1M customer records exposed

Verified breach. Verified subsidiary data breach — disclosed October–November 2021. MoIP, PagSeguro's Brazil payment platform (formerly Wirecard Brazil, acquired by PagSeguro in 2020), discovered unauthorized access to customer registration data stored on one of its servers and emailed affected MoIP customers on October 21, 2021. PagSeguro stated the incident had no relation to core PagBank/PagSeguro systems, reported the case to Brazil's ANPD data-protection authority, and said its investigation found no evidence of access to pass Exposed categories include Per PagSeguro customer notice and trade press: names, RG, CPF, mother's name, ID document photos, self-declared income and asset data; forum sample also included addresses, phones,. BreachHistory cites approximately 1M+ affected records in this row. See the pagbank-moip2021 and canonical BreachHistory entry.

Patterns and analysis

  • Cloud and database misconfiguration — appears across multiple PagBank catalog entries; prioritize controls that address this class of failure.
  • Unverified actor or scraping claims — appears across multiple PagBank catalog entries; prioritize controls that address this class of failure.
  • Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
  • 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.

What to do if you may be affected

  1. Step 1: Enable phishing-resistant MFA on every account tied to this brand.
  2. Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
  3. Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
  4. Step 4: Bookmark the PagBank company page for new 2026+ disclosures.

Canonical BreachHistory hub

Explore every indexed row: breachhistory.com/pagbank · Latest: pagbank-forum2026.

Sources: BreachHistory catalog (3 rows for PagBank), company and regulator disclosures cited in individual breach records.