ALLEGED · UNCONFIRMEDFINANCIAL SERVICES

Brazil's Payment Gateways

pagbank.com.br
1877 Team📍 Brazil (BR)📅 July 12, 2026

Attack Intelligence

Brazil's Payment Gateways was compromised in a ransomware attack attributed to 1877 Team in July 2026. The organization, operating in the Financial Services sector in Brazil, was added to the group's data leak site as part of an extortion campaign.

UNCONFIRMED / ALLEGED. On 12 July 2026 the extortion collective "1877 Team" claimed, on Telegram and on a dark-web leak forum (thread "Databases pagbank.com.br [BR]"), to have fully compromised the core infrastructure of one of Brazil's 14 primary payment-gateway / acquiring providers. The forum thread title and the published sample data point to PagBank (pagbank.com.br). The actor claims 250,000+ active merchants affected and over 1 billion historical transaction records exfiltrated — including transaction metadata, merchant settlement information and POS terminal identifiers — allegedly obtained via a spear-phishing campaign against internal operations staff, reverse engineering of proprietary POS APIs, and evasion of internal DLP controls. These claims are UNVERIFIED: as of 12 July 2026 neither Banco Central do Brasil, CERT.br, nor the major Brazilian acquiring networks have issued any bulletin, and the "sample" records published appear synthetic and sequential. Threat actors routinely exaggerate the scope and sophistication of alleged compromises to pressure victims or attract buyers. CTIWATCH is monitoring the situation; no independent evidence currently confirms the breach or the authenticity of the dataset.

Alleged Evidence

Screenshots published by the threat actor. Unverified — samples may be fabricated or exaggerated. Shown for intelligence purposes only.

Additional Details

threat_group
1877 Team
records_claimed
1,000,000,000+ transaction records
alleged_provider
PagBank (pagbank.com.br)
data_types_claimed
transaction metadata, merchant settlement info, POS terminal identifiers
initial_access_claimed
spear-phishing of internal ops staff + custom malware
regulatory_confirmation
None as of 2026-07-12 (BCB / CERT.br / acquirers silent)
post_exploitation_claimed
lateral movement, POS API reverse engineering, DLP evasion
merchants_affected_claimed
250,000+ active merchants

Quick Facts

CountryBrazil (BR)
SectorFinancial Services
Attack DateJul 12, 2026
Domainpagbank.com.br
Intel SourceTelegram
StatusUnconfirmed

Threat Group

1877 Team

External Links

Data sourced from Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Victim listing does not imply confirmed breach — intelligence based on group claims.