[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fzDwIxgQKHi_Q13fDMtDB--LfWmE-jMUWAbAnFH3rgDY":3},{"article":4,"iocs":45},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":32},"3bce5eb2-c797-4ba1-bbe3-9a1113426213","Brazil Health Surveillance Database Exposed 79GB of Sensitive Records","brazil-health-surveillance-database-exposed-79gb-of-sensitive-records-f9027a","Brazil's SISVISA health surveillance system left 102,215 files totaling 79GB open online, including tax IDs and identity documents, without password protection.","Brazil's SISVISA health surveillance system left over 102,000 files, totaling 79GB, publicly accessible online without password protection. The exposed data includes sensitive personal information such as names, addresses, phone numbers, tax IDs (CPF\u002FCNPJ), scanned driver's licenses, and doctor identity cards. While public access was reportedly shut off after discovery, it remains unknown how long the data was exposed or if it was accessed by malicious actors.","Brazil's SISVISA health database exposed 79GB of sensitive records online.","Security LeaksBrazil Health Surveillance Database Exposed 79GB of Sensitive Records Brazil’s SISVISA health surveillance system left 102,215 files totaling 79GB open online, including tax IDs and identity documents, without password protection. byDeeba AhmedAugust 5, 20262 minute read Listen to this article 0:00 — ← 10s ▶ Play 10s → Speed 0.75× 1× 1.25× 1.5× 2× Voice Loading voices… Press play to start listening Over 102,000 private records belonging to Brazil’s health surveillance system were left online without passwords or basic encryption. Security researcher Jeremiah Fowler found this publicly accessible database and alerted cybersecurity firm ExpressVPN, which later shared the details with Hackread.com. According to Fowler, this open database stored exactly 102,215 files (around 79GB). Further probing revealed that these records belong to Brazil’s Health Surveillance Information System (SISVISA). For your information, this is a crucial platform used by Brazilian health authorities to track public health rules, issue business permits, and manage inspections for hospitals, restaurants, and pharmacies. What Files Were Exposed? While investigating, Fowler noted that anyone who found the web address could access folders without needing login credentials. These folders were labelled for backups, imports, documents, and uploads. Upon reviewing the files, he found a wide range of sensitive personal and government information, including: Full names, physical addresses, phone numbers, and contact details. Tax identification numbers, known locally as CPF for citizens and CNPJ for businesses. Scanned copies of national driver’s licenses and federal doctor identity cards. Official documents featuring photos of people’s faces and fingerprints. Business inspection reports, sanitary compliance forms, complaint records, and two compressed backup files. Screenshots of exposed data shared by the researcher (Source: ExpressVPN) Screenshots of exposed data shared by the researcher (Source: ExpressVPN) Screenshots of exposed data shared by the researcher (Source: ExpressVPN) Why Going Digital Creates New Risks The SISVISA platform was originally designed in 2015 to replace slow paper-based record systems, allowing public agencies to approve business applications much faster. Going digital saved a lot of time for the agency, no doubt, but leaving files exposed on the web brings unique problems that paper never had. Due to such oversights, unsuspecting users can get exposed to a range of scams like phishing, impersonation, identity theft, malware injection, and financial fraud, Fowler noted in the blog post. Scammers can get quick access to sensitive data like tax numbers or photos of driver’s licenses and trick people or steal funds. They may also download the files, add viruses to them, and put them back online or even lock the whole system and demand ransom to return access. However, Fowler clarified that it is still unclear if government staff ran this database themselves or hired a third party to do it. The researcher sent quick warnings to several government offices after finding the exposed data, and public access was turned off shortly after that. However, no official ever replied to the warnings, so no one knows how long the files were left open or if anyone accessed them already. In case you think your information may be exposed, please practice caution. Check your bank accounts regularly to detect any unverifiable transactions or charges, never trust unexpected callers asking for personal details, and enable two-step verification for your apps. Deeba Ahmed Deeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience covering cybercrime, vulnerabilities, and security events. Her expertise and in-depth analysis make her a key contributor to the platform’s trusted coverage. View Posts BrazilCybersecurityExpressVPNHealthcareJeremiah FowlerLEAKSPrivacySISVISA Leave a Reply Cancel reply View Comments (0) Related Posts Read More Security Cyber Attacks Cyberattack Disrupts Airport Check-In Systems Across Europe Cyberattack on Collins Aerospace check-in system disrupts major European airports, causing flight delays and cancellations across hubs. byWaqas Read More Security Malware RIG Exploit Toolkit Distributing CeidPageLock Malware to Hijack Browsers A previously discovered browser hijacker malware dubbed as CeidPageLock has resurfaced again, in a bigger and better avatar,… byWaqas Read More Security Privacy How ID Scanning Apps Can Prevent Fraud Businesses today are highly concerned about preventing fraud in this age. As technology advances, so do activities, making… byWaqas Read More Cyber Crime Hacking News Security Russian Pair Charged with JFK Airport Taxi System Hack for Over 2 Years A cybersecurity incident apparently involving collaboration between Russians and Americans... byWaqas","https:\u002F\u002Fhackread.com\u002Fbrazil-health-surveillance-database-exposed-records\u002F","https:\u002F\u002Fhackread.com\u002Fwp-content\u002Fuploads\u002F2026\u002F08\u002Fbrazil-health-surveillance-database-exposed-records.png","2026-08-05T10:21:27+00:00","2026-08-05T12:00:13.955104+00:00",7,[18,21,24],{"name":19,"type":20},"SISVISA","product",{"name":22,"type":23},"ExpressVPN","vendor",{"name":25,"type":26},"Jeremiah Fowler","threat_actor","2e06f76c-d5b9-4f54-9eef-4d3447b10730",{"id":27,"icon":29,"name":30,"slug":31},null,"Breaches","breaches",[33,35,40],{"category":34},{"id":27,"icon":29,"name":30,"slug":31},{"category":36},{"id":37,"icon":29,"name":38,"slug":39},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":41},{"id":42,"icon":29,"name":43,"slug":44},"c5c77cdb-f7d7-4990-9436-c81dcbff1163","Policy","policy",[]]