Brazil's Payment Gateways
Attack Intelligence
Brazil's Payment Gateways was compromised in a ransomware attack attributed to 1877 Team in July 2026. The organization, operating in the Financial Services sector in Brazil, was added to the group's data leak site as part of an extortion campaign.
UNCONFIRMED / ALLEGED. On 12 July 2026 the extortion collective "1877 Team" claimed, on Telegram and on a dark-web leak forum (thread "Databases pagbank.com.br [BR]"), to have fully compromised the core infrastructure of one of Brazil's 14 primary payment-gateway / acquiring providers. The forum thread title and the published sample data point to PagBank (pagbank.com.br). The actor claims 250,000+ active merchants affected and over 1 billion historical transaction records exfiltrated — including transaction metadata, merchant settlement information and POS terminal identifiers — allegedly obtained via a spear-phishing campaign against internal operations staff, reverse engineering of proprietary POS APIs, and evasion of internal DLP controls. These claims are UNVERIFIED: as of 12 July 2026 neither Banco Central do Brasil, CERT.br, nor the major Brazilian acquiring networks have issued any bulletin, and the "sample" records published appear synthetic and sequential. Threat actors routinely exaggerate the scope and sophistication of alleged compromises to pressure victims or attract buyers. CTIWATCH is monitoring the situation; no independent evidence currently confirms the breach or the authenticity of the dataset.
Alleged Evidence
Screenshots published by the threat actor. Unverified — samples may be fabricated or exaggerated. Shown for intelligence purposes only.

![Dark-web leak forum thread: 'Databases pagbank.com.br [BR]'](/leaks/pagbank/evidence-2.jpg)




