← PagBank

2021 PagBank MoIP — Wirecard Brazil server breach; ~1M customer records exposed

2021 1.0M records affected Share on X

Data compromised

Per PagSeguro customer notice and trade press: names, RG, CPF, mother's name, ID document photos, self-declared income and asset data; forum sample also included addresses, phones, and password hashes per Syhunt—company stated no access to passwords, card data, or transactions

Technical writeup

Verified subsidiary data breach — disclosed October–November 2021. MoIP, PagSeguro's Brazil payment platform (formerly Wirecard Brazil, acquired by PagSeguro in 2020), discovered unauthorized access to customer registration data stored on one of its servers and emailed affected MoIP customers on October 21, 2021. PagSeguro stated the incident had no relation to core PagBank/PagSeguro systems, reported the case to Brazil's ANPD data-protection authority, and said its investigation found no evidence of access to passwords, card data, or customer transactions and no financial harm to clients. In early November 2021, actor ShinyHunters offered a ~1 million-row sample on a cybercrime forum attributed to Wirecard/MoIP; Syhunt's independent analysis of the sample found names, addresses, phones, document images, hashed card references, and password hashes—potentially exceeding one million people across split dumps. PagSeguro maintained sensitive payment credentials were not accessed. Trade press and Syhunt cite at least one million affected registration records in the circulated sample.

Root cause

Unauthorized access to MoIP (Wirecard Brazil) registration-data server; PagSeguro/PagBank subsidiary notified affected MoIP customers Oct 21, 2021 and reported to Brazil's ANPD

References