Recommended Free Tools
Brazil’s data-protection authority said in January 2021 that a research lab had reported a breach that may have affected approximately 220 million people. That figure was an estimate cited during an open technical investigation—not a final count of confirmed victims—and the notice did not establish Serasa or any other organization as the source.
What happened in January 2021?
On 29 January 2021, Brazil’s Autoridade Nacional de Proteção de Dados (ANPD) issued a note about a widely reported personal-data security incident. The authority said the approximate figure of 220 million people came from information reported by the dfndr research lab, linked to PSafe Tecnologia S/A.
The ANPD described its work as a technical investigation. It said it had received information from Serasa and had contacted the Federal Police, PSafe, the Brazilian Internet Steering Committee and the Institutional Security Office of the Presidency for information or assistance with investigation and risk mitigation.
Those contacts do not amount to an attribution of responsibility. The notice did not identify a confirmed source, publish a definitive data set or certify that 220 million distinct living Brazilians had been exposed.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
How certain is the “220 million” figure?
The number should be read as an early reported estimate. It was supplied by a research lab and repeated in the ANPD’s notice while inquiries were under way. The notice itself does not turn that estimate into a final impact count.
Large leaked databases can contain duplicates, records for people who have died, outdated information or data about individuals outside the population implied by a headline. Without a final technical finding identifying the data set and matching records to individuals, the number of unique affected people cannot be inferred from the estimate alone.
The sources available for this account do not establish whether a later ANPD decision or case document resolved the incident’s source, exact contents or definitive scope. Treat the final count and attribution as unresolved unless a later official case record says otherwise.
Was Serasa confirmed as the source?
No. The ANPD said it received information from Serasa as part of its inquiry. That is different from saying Serasa caused the incident, held the leaked database or was legally responsible for it. The authority also sought information from several other institutions, and none was named as the proven source in the January notice.
A separate 2022 fact-check
A 2022 Electoral Justice fact-check addressed a different claim involving a suspect arrested for sharing information such as CPFs and addresses. It clarified that the arrest was not for invading the Superior Electoral Court (TSE). That clarification should not be used as proof of the January 2021 leak’s source or final reach.
Can you find out whether your information was included?
The ANPD’s guidance, published on 10 February 2021 and modified on 25 July 2022, says most sources of the large databases reported at the time were still unknown. In the authority’s words, “A maioria das fontes desses dados ainda é desconhecida.” (Most sources of this data are still unknown.)
If you know which organization collected or used the information involved, ask that data controller directly whether your records were among those supposedly exposed and which categories of data were involved. A controller—not a general ANPD incident tally—is the party that can answer an individual case.
The ANPD’s current fiscalization-results page explains that public incident information is presented in aggregate and that the authority does not receive individual lists of affected people. Its yearly notification totals therefore cannot tell you whether you were in this particular leak.
Use care with “breach checker” services
Do not reply to unsolicited emails claiming that your data were exposed, and do not enter additional personal information into a suspicious website offering to check. The ANPD warns that these services can collect more information and increase your exposure. Use a verified channel for the relevant controller instead.
What to do now
| Situation | Safer response | Avoid |
|---|---|---|
| You know the likely data controller | Contact it through its official website or customer-service channel and ask whether your information was involved and what data categories were affected. | Relying on an unverified lookup page or an unsolicited message. |
| You are concerned but have no sign of fraud | Change passwords and other access credentials for affected services, use two-factor authentication where available, and monitor accounts and related services. | Reusing an old password or sharing one-time codes with a caller or website. |
| You detect fraudulent use | Contact the relevant bank, platform or service provider promptly and report the incident to police. | Continuing to communicate with the suspected fraudster or deleting evidence before reporting. |
1. Secure accounts
Prioritize accounts that use the same password, contain financial information or can reset other services. Create a unique password for each important account and turn on two-factor authentication when the service offers it.
2. Watch for follow-on attacks
Monitor bank, payment, email, mobile and social-media accounts for unfamiliar logins, password-reset notices, new beneficiaries, transfers or changes to contact details. A leaked identifier can make later phishing messages look convincing, so verify requests through an app or phone number you already trust.
3. Escalate confirmed fraud
If money, an account or an identity document is misused, notify the affected provider immediately, preserve messages and transaction records, and make a police report. Follow the provider’s instructions for freezing access, reversing transactions or replacing credentials.
Best Value
What the ANPD numbers do—and do not—mean
The ANPD reports authority-wide incident notifications in aggregate. The results page lists 186 notifications in 2021, 275 in 2022, 352 in 2023 and 95 through April 2024. These are counts of reported incident cases across the authority’s work, not the number of people affected by the January 2021 episode and not a substitute for an individual confirmation.
Brazil’s data-protection framework requires a controller to communicate a security incident to the national authority and to the data subject when it may create relevant risk or harm. The ANPD reproduces that requirement in its guidance as: “o controlador deverá comunicar à autoridade nacional e ao titular a ocorrência de incidente de segurança que possa acarretar risco ou dano relevante aos titulares”. Whether that duty applies to a particular person depends on the controller’s assessment and the facts of the incident.
Bottom line for people in Brazil
Take the report seriously as a reason to improve account security, but do not treat “220 million” as a confirmed list of victims. Ask a known controller through an official channel, ignore suspicious checking sites, use unique passwords and two-factor authentication, and contact providers and police if you find fraudulent activity. The January 2021 notice did not settle the leak’s source or final scope.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.

