Attackers breach Evertec's Sinqia to attempt a $130M heist via Brazil's Pix system
Hackers used stolen IT-vendor credentials to break into the Pix transaction-processing environment of Brazilian fintech Sinqia, a subsidiary of Evertec, and attempted to move more than $130 million in fraudulent real-time payments before the activity was halted.
- Victim
- Sinqia S.A. (Evertec)
On or around 29 August 2026, attackers used stolen credentials from an IT-vendor account to break into the Pix transaction-processing environment operated by Sinqia S.A., the Brazilian subsidiary of Puerto Rico-based payments company Evertec. Once inside, they attempted to push through unauthorised real-time transfers exceeding $130 million across Pix, the Central Bank of Brazil's instant-payment network, in business-to-business transactions tied to two financial institutions that are Sinqia customers. The heist attempt became public through security reporting on 2 September 2026.
Sinqia said it detected the anomalous activity and immediately halted Pix transaction processing, then engaged external cybersecurity experts to investigate. Evertec stated that a portion of the diverted funds had already been recovered, though it did not disclose the exact amount, and stressed that no personal data was leaked and that the impact was strictly limited to the Pix environment rather than customer records or core banking data.
A pattern of real-time payment fraud
The Central Bank of Brazil temporarily suspended Sinqia's access to Pix while the fintech demonstrated that its systems were secure โ the same regulatory reflex the bank had applied to other providers caught up in a run of instant-payment fraud. The case underscored a recurring theme in Pix-related attacks: rather than defeating the payment network's own controls, criminals compromise the software providers and service intermediaries that connect banks to it, using stolen credentials to originate fraudulent transfers at machine speed.
Because Sinqia stopped processing on detection, recovered part of the funds, and reported no leak of personal or customer data, the incident was assessed as contained, even as it renewed scrutiny of third-party access controls across Brazil's real-time payment ecosystem.
Timeline
Attackers use stolen credentials from an IT-vendor account to access Sinqia's Pix transaction-processing environment and attempt unauthorised transfers exceeding $130 million between financial institutions.
Evertec confirms the fraud attempt at its Brazilian subsidiary Sinqia; the company says it halted Pix processing on detection and that a portion of the funds has been recovered.
The Central Bank of Brazil temporarily suspends Sinqia's access to Pix pending security assurances; Evertec says no personal data was leaked and the impact was confined to the Pix environment.
Sources
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/hackers-breach-fintech-firm-in-attempted-130m-bank-heist/
- infosecurity-magazine.comhttps://www.infosecurity-magazine.com/news/brazilian-fintech-giant-sinqia/
- bankinfosecurity.comhttps://www.bankinfosecurity.com/hackers-grab-130m-using-brazils-real-time-payment-system-a-29352
- americanbanker.comhttps://www.americanbanker.com/news/brazilian-heist-highlights-real-time-payment-fraud-concerns