Brazil Health Surveillance Database Exposed 79GB of Sensitive Records

Brazil’s SISVISA health surveillance system left 102,215 files totaling 79GB open online, including tax IDs and identity documents, without password protection.

Listen to this article

0:00

Press play to start listening

Over 102,000 private records belonging to Brazil’s health surveillance system were left online without passwords or basic encryption. Security researcher Jeremiah Fowler found this publicly accessible database and alerted cybersecurity firm ExpressVPN, which later shared the details with Hackread.com.

According to Fowler, this open database stored exactly 102,215 files (around 79GB). Further probing revealed that these records belong to Brazil’s Health Surveillance Information System (SISVISA). For your information, this is a crucial platform used by Brazilian health authorities to track public health rules, issue business permits, and manage inspections for hospitals, restaurants, and pharmacies.

What Files Were Exposed?

While investigating, Fowler noted that anyone who found the web address could access folders without needing login credentials. These folders were labelled for backups, imports, documents, and uploads. Upon reviewing the files, he found a wide range of sensitive personal and government information, including:

  1. Full names, physical addresses, phone numbers, and contact details.
  2. Tax identification numbers, known locally as CPF for citizens and CNPJ for businesses.
  3. Scanned copies of national driver’s licenses and federal doctor identity cards.
  4. Official documents featuring photos of people’s faces and fingerprints.
  5. Business inspection reports, sanitary compliance forms, complaint records, and two compressed backup files.

Why Going Digital Creates New Risks

The SISVISA platform was originally designed in 2015 to replace slow paper-based record systems, allowing public agencies to approve business applications much faster. Going digital saved a lot of time for the agency, no doubt, but leaving files exposed on the web brings unique problems that paper never had.

Due to such oversights, unsuspecting users can get exposed to a range of scams like phishing, impersonation, identity theft, malware injection, and financial fraud, Fowler noted in the blog post. Scammers can get quick access to sensitive data like tax numbers or photos of driver’s licenses and trick people or steal funds. They may also download the files, add viruses to them, and put them back online or even lock the whole system and demand ransom to return access.

However, Fowler clarified that it is still unclear if government staff ran this database themselves or hired a third party to do it. The researcher sent quick warnings to several government offices after finding the exposed data, and public access was turned off shortly after that. However, no official ever replied to the warnings, so no one knows how long the files were left open or if anyone accessed them already.

In case you think your information may be exposed, please practice caution. Check your bank accounts regularly to detect any unverifiable transactions or charges, never trust unexpected callers asking for personal details, and enable two-step verification for your apps.

Deeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience covering cybercrime, vulnerabilities, and security events. Her expertise and in-depth analysis make her a key contributor to the platform’s trusted coverage.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts