Gabriel Galípolo: Central Bank announces measures to restrict Pix from institutions with precarious digital security after deviations

Pix
Photo: Pix - Diego Thomazini/Shutterstock.com

The Central Bank (BC) plans to implement restrictions on access to payment platforms, such as Pix, for banks and fintechs that present weaknesses in their cybersecurity systems. The measure comes after losses of more than R$1.5 billion due to hacker attacks against financial institutions last year, seeking to encourage the strengthening of internal defenses and curb the actions of criminals.

The Central Bank’s attention to cyber vulnerabilities has intensified since June last year, following an incident that resulted in the diversion of around R$800 million from financial institutions through Pix, known as the “theft of the year”. At that time, the attack targeted C&M Software, a technology provider that connects smaller banks to BC systems.

In 2024, a survey showed that only 15% of cyber incidents reported by banks and fintechs were direct frauds (9 out of 59 cases). Most of the others were categorized as failures in IT systems or leaks of non-sensitive data, information often used to plan future scams against customers.

However, in the previous year, there was an increase of almost 30% in the total number of incidents, reaching 76 occurrences. Notably, fraud gained significant prominence, corresponding to more than half of these cases, totaling 39 records.

Regulator had already intensified requirements for the sector

Gallipolo

Although cybersecurity standards were reinforced by the Central Bank in 2025, the number of incidents continued to rise. By the end of May, 43 incidents had been recorded, with 34 of them (79%) being classified as fraud. The regulatory body now plans to implement a series of sanctions for institutions that do not meet the established minimum security criteria.

To implement this initiative, the Central Bank is developing a detailed mapping of the IT infrastructure of the entire financial system. In May, a comprehensive questionnaire was distributed to the 1,745 authorized institutions, requesting information on the application of regulatory controls, including the Pix security manual, and additional measures depending on the risk profile of each entity.

If the Central Bank identifies discrepancies between the responses provided and its daily monitoring, it may request additional documents or take other supervisory actions to validate the information. This rigorous assessment process will allow the monetary authority to apply penalties to entities that fail to comply with the minimum mandatory guidelines.

Regulations allow banks and fintechs to face restrictions such as time or value limits for Pix operations, or even the temporary suspension of the service. Examples include the imposition of a cap of R$15,000 per transaction, a measure already applied to some institutions last year, or the ban on night-time operations. Furthermore, companies may be prevented from attracting new customers, forced to pay fines and subject to sanctioning processes.

The perception is that any bank or fintech with deficiencies in its control systems represents a systemic risk for the financial market. Although the sector is one of those that invests the most resources in security, the migration of crime from the physical to the digital scenario requires that investments in protection grow in proportion to the risk inherent to this new context.

Expansion of technology contributions and increase in penalties

Data from a survey on banking technology, carried out by the Brazilian Federation of Banks (Febraban), indicate a constant growth in investments in technology, with special attention to cybersecurity. In 2025, the budget allocated to this area reached R$46.8 billion, with a projected increase to R$50.4 billion in the current year. The entity representing banks also highlights the need to toughen punishments for fraud, including in the criminal sphere.

From the complete mapping, the Central Bank will have more input to assess the need for new regulations. Although the agency hopes that the recent guidelines will contribute to reducing the impact of attacks, the increase observed in incidents this year is partially attributed to a “more accurate radar” by the BC itself, which began to require institutions to notify all incidents, even the smallest ones.

Additionally, the Central Bank intensified its alerts to its own institutions about unusual activities identified in Pix monitoring, signaling potential fraud. When an attack is confirmed, the event is treated with the utmost seriousness, compared to a “plane crash”.

Affected banks or fintechs should hire forensic companies to investigate digital crimes and identify the root causes of the problems. The report of this investigation, accompanied by a containment plan, needs to be submitted to the regulator. The purpose is to prevent the recurrence of incidents, support future regulatory decisions and apply appropriate sanctions to those involved.

According to the analysis of Aylton Gonçalves, lawyer and professor of financial regulation, the Central Bank’s actions in the field of sanctions were the missing piece for cybersecurity. In his view, it is not necessary to change current standards, but rather a more rigorous stance in monitoring and applying penalties, modulated by the performance of institutions.

He adds: “I don’t see a gap or absence of regulation, but rather a sanctioning action by the Central Bank that should intensify in the coming periods. This approach has a clear deterrent in the face of negligence in cybersecurity.”

Security failures were targets of criminal actions

After the impact caused by the previous year’s attacks, the Central Bank identified patterns in the vulnerabilities exploited by criminals and reacted, strengthening controls at banks and fintechs. Cybersecurity policies were implemented in two stages for greater rigor.

The initial phase, in September, required basic controls on institutions without prior licenses or those that depended on technology providers, then considered the most critical points of vulnerability.

In two incidents of major embezzlement, institutions that employed technology providers kept digital certificates essential to authorizing transactions with the Central Bank in their custody. Such certificates operate as security keys, validating to the regulator that any transfer order signed by them must be processed.

Despite regulations requiring that certificates remain with regulated entities, many chose to leave them with third parties. Industry professionals compare this practice to handing over an already signed checkbook or signing a check without checking the amount. When these institutions were attacked and transfer orders were sent to the BC, they were initially accepted, and only later was the fraud identified.

However, it quickly became apparent that the guidelines put in place in September were not sufficient. The attacks persisted and also began to affect larger banks and fintechs, which did not use technological intermediaries to access Central Bank systems, revealing that the vulnerabilities were not limited to smaller-scale or outsourced entities.

Therefore, in December, the Central Bank was forced to extend the regulations, previously applicable only to unauthorized institutions or those dependent on technology providers, to all regulated entities, effective from March.

See Also Latest News (EN)

Islam Makhachev confirms unanimous decision victory over Ian Machado Garry at UFC 330
Latest News (EN) • 16/08/2026

Islam Makhachev confirms unanimous decision victory over Ian Machado Garry at UFC 330

Amazon guarantees 17% discount on advance purchases of Grand Theft Auto VI
Latest News (EN) • 16/08/2026

Amazon guarantees 17% discount on advance purchases of Grand Theft Auto VI

UFC 330: Mackenzie Dern defends title and keeps Brazil with only belt
Latest News (EN) • 16/08/2026

UFC 330: Mackenzie Dern defends title and keeps Brazil with only belt

Kenta Takasaki advances to Koshien quarterfinals after 12 years and coach celebrates rare feat
Latest News (EN) • 16/08/2026

Kenta Takasaki advances to Koshien quarterfinals after 12 years and coach celebrates rare feat

Intense fires in Croatia cause one death and leave 40 injured
Latest News (EN) • 16/08/2026

Intense fires in Croatia cause one death and leave 40 injured

Neighbors rescue 4-year-old child after fall from 5th floor in Poland
Latest News (EN) • 16/08/2026

Neighbors rescue 4-year-old child after fall from 5th floor in Poland

Horoscope of the day: Predictions for Libra show a period of decisive agreements and professional success
Latest News (EN) • 15/08/2026

Horoscope of the day: Predictions for Libra show a period of decisive agreements and professional success

Munich: Boeing 787 Vietnam Airlines scrapes its tail on takeoff and makes an emergency landing after taking off off the runway
Latest News (EN) • 15/08/2026

Munich: Boeing 787 Vietnam Airlines scrapes its tail on takeoff and makes an emergency landing after taking off off the runway

Advance of Cyclone Lala paralyzes airports and raises alert in Hawaii
Latest News (EN) • 15/08/2026

Advance of Cyclone Lala paralyzes airports and raises alert in Hawaii

Hurricane Lala arrives in Hawaii with winds of 120 km/h and closes airports
Latest News (EN) • 15/08/2026

Hurricane Lala arrives in Hawaii with winds of 120 km/h and closes airports

Lucas, singer of the country duo Lucas & Matheus, died in Portugal after a heart attack
Latest News (EN) • 15/08/2026

Lucas, singer of the country duo Lucas & Matheus, died in Portugal after a heart attack

Workers from seven professions guarantee INSS retirement in 15 years
Latest News (EN) • 15/08/2026

Workers from seven professions guarantee INSS retirement in 15 years

Find out if your WhatsApp has been hacked and apply security blocks
Latest News (EN) • 15/08/2026

Find out if your WhatsApp has been hacked and apply security blocks

Uber expands global reach with 2,000 Pony.ai robo-taxis in Europe
Latest News (EN) • 15/08/2026

Uber expands global reach with 2,000 Pony.ai robo-taxis in Europe

Former boxing promise Prichard Colón loses his life at age 33 due to trauma in the ring
Latest News (EN) • 15/08/2026

Former boxing promise Prichard Colón loses his life at age 33 due to trauma in the ring