RIO DE JANEIRO, BRAZIL – More than 10 million Brazilians’ e-mail passwords have been disclosed on the internet in a 3.2 billion global leak that occurred in early February.

Among the Brazilian credentials are more than 70,00 passwords from government institutions or companies, such as the Chamber of Deputies, the Federal Supreme Court (STF) and Petrobras. The figures were collected after an exclusive study for the newspaper O Estado de S. Paulo by Syhunt, a cybersecurity company.
The leak occurred in early February and contains 3.28 billion passwords for about 2.18 billion individual email addresses. The 100 GB file was published in the same forum where in January hackers put up for sale databases that compromised 223 million CPFs (Individual Tax ID), 40 million CNPJs (Legal Entity Tax ID) and 104 million motor vehicle drivers licenses.
Unlike the January mega-leak, in which Brazilians’ information was for sale, the whole password leak was released for free – anyone may download it.
Among Brazilians’ data are at least 10 million passwords. This is the number of credentials referring only to e-mails from the “.br” domain – about 26 million domains worldwide were affected. This means that the number of Brazilians affected could be higher. The study did not include very popular email services in Brazil, such as Gmail and Hotmail, because they are under the “.com” domain.
Although the January leak contained considerably more data about Brazilians, the new leak also poses significant risks to digital security. “In the January leak, there were millions of emails. This data can be linked to the password database and allow criminals to have access,” says Felipe Daragon, Syhunt’s founder. In the January mega-leak, the hacker put up for sale e-mails from 77.8 million people and 15.8 million companies.
In addition, several emails had more than one password leaked, which helps identify the pattern of password creation. Moreover, with this pattern in hand, it is possible to try to predict future new passwords created for the addresses. In the leak, many addresses had between 3 and 30 passwords associated to them.
Government
The leak involved thousands of government passwords. In total, 68,535 email passwords for the domain “gov.br” used by the federal government were affected. Another 4,589 passwords for the domain “jus.br” were made available, which includes STF passwords. The report found at least one email directly linked to the office of Justice Dias Toffoli. A total of 98 passwords were found for the “stf.jus.br” domain.
In addition, 218 passwords for the “camara.leg.br” domain of the federal Chamber of Deputies are listed. In this database, president Jair Bolsonaro’s e-mail address when he was a deputy can be found – showing that the file includes data from several different years. In addition, e-mails of other deputies can be found in the “camara.gov.br” database. There are 985 passwords, including names that are no longer in Brasília, such as that of ex-deputy Jean Wyllys.
The Senate domain “senado.gov.br” has 547 leaked passwords. Addresses linked to the presidency of the republic are also listed. The domain “presidencia.gov.br” had 28 leaked passwords.
Among the 200 most affected “gov.br” domains are email passwords for the Federal Treasury, the Attorney General, the Brazilian Health Regulatory Agency, Caixa (Federal Savings Bank), the Butantan Institute, FUNAI (National Indian Foundation), IBGE (Brazilian Institute of Geography and Statistics), Infraero (Brazil’s airport management company), INPI (Patent and Trademark Office), and the State Police in several states, including São Paulo and Paraná.
The report also found in the leak 8,863 passwords linked to Petrobras – no address, however, is linked to presidents who have been in charge of the company. An address possibly linked to Minister of Economy Paulo Guedes was also found, from the time he worked at BR Investimentos.
However, Daragon alerts: “The ‘gov.br’ passwords do not mean that the government systems have been hacked. These addresses and passwords seem to have been used in internet services that have been compromised.”
Read More from The Rio Times