Unverified claim — July 12, 2026: Threat-intelligence accounts flagged cybercrime-forum posts alleging a PagBank data compromise—one of Brazil's largest digital payment platforms. PagBank had not confirmed any matching incident at indexing time. Treat every row count as actor marketing until the company or Brazilian regulators validate scope.
What threat actors claim
DailyDarkWeb summarized a forum post alleging unauthorized access to PagBank core infrastructure, 250,000+ active merchants, and more than one billion historical transaction records, plus merchant settlement metadata and POS terminal identifiers. The post described a Hollywood intrusion narrative—phishing, lateral movement, reverse-engineered internal APIs—without attaching independently verified samples at report time.
Separately, VenariX cited a more specific circulating database allegedly linked to PagBank containing more than 812,000 transaction records with merchant names, payment amounts, payment types, last four digits of payment cards, and authorization codes.
Brazilian OSINT commentators on X noted the posts followed a familiar forum pattern—big numbers, thin proof—common in reputation-building listings. That skepticism matters: PagBank processes enormous legitimate volume; a real leak and a repackaged older merchant export can look identical in a screenshot.
What PagBank has not said
At catalog time PagBank had not published a customer notification, ANPD filing summary, or forensic bulletin matching the forum claims. Without that, BreachHistory indexes the 812,000 transaction-row citation from VenariX as the best specific unverified figure while noting the larger billion-row marketing language remains unconfirmed.
Why payment metadata still hurts merchants
Even without full PANs, transaction metadata trains convincing fraud:
- Merchant name + amount + date powers fake chargeback and settlement emails
- Card last-four + authorization code lends credibility to vishing calls pretending to be PagBank antifraud
- POS terminal identifiers can target specific retail locations with device-swap social engineering
Brazil's retail economy runs heavily on PagBank and PagSeguro rails. A partial transaction leak does not need a billion rows to monetize—thousands of verified recent charges against recognizable merchants are enough for WhatsApp scam campaigns.
What merchants and consumers should do
- Ignore forum download links—archives may contain malware or recycled CPF dumps unrelated to PagBank.
- Log into PagBank only via pagbank.com.br or the official app; reject SMS links citing "urgent settlement review."
- Enable transaction alerts on linked accounts and cards.
- Report suspicious chargeback or terminal-replacement calls to PagBank through official support channels.
Canonical record
PagBank 2026 forum claim on BreachHistory — indexed as unverified.
Sources: DailyDarkWeb, VenariX.