The 2018 report was real, but its most alarming shorthand needs qualification. Researchers said they found an internet-accessible server containing approximately 120 million Brazilian CPF records—about 57% of Brazil’s population at the time. The evidence supports a serious data exposure caused by a web-server misconfiguration; it does not establish that every record was downloaded, that the Brazilian government owned the database, or that criminals used it.
CyberScoop’s account of InfoArmor’s findings and Brazilian technical coverage provide the available basis for what follows.
What a CPF is—and why exposure matters
CPF stands for Cadastro de Pessoas Físicas, Brazil’s federal taxpayer-registration number. It is not merely a tax reference: businesses, banks, government services and other providers commonly request it to identify people and process transactions. In practical terms, it can function as a persistent personal identifier, although its legal and administrative system is not identical to a U.S. Social Security number.
Unlike a password, a CPF generally cannot simply be replaced after exposure. That makes a leaked CPF more useful when combined with addresses, phone numbers, family connections or financial information from other sources.
#1 Best Overall
What happened in 2018?
- March 2018: InfoArmor reportedly found the server while scanning the internet for compromised or vulnerable systems.
- Following weeks: Researchers tried to identify and notify the responsible party while observing that files and databases were still being changed.
- Late April 2018: The server was reportedly changed to show a login page and the observed exposure ended. That does not prove that copies, backups or other access routes were deleted.
- December 11, 2018: CyberScoop published major English-language coverage of the findings.
The strongest available timeline supports an exposure observed for weeks in spring 2018. Descriptions of the incident as lasting “months” generally span discovery to later reporting and should not be read as proof of uninterrupted public access for that entire period.
How the server became publicly browsable
The reported technical chain was relatively basic. A web server hosted data, directory listing was enabled, and its usual index.html file had reportedly been renamed index.html_bkp. Without the expected index file, Apache could display a directory listing, allowing a visitor who knew or discovered the server address to browse and potentially download files. Tecnoblog’s technical explanation describes this behavior.
Restoring an index page would hide the listing, but it would not be a complete security fix. Proper remediation would also require removing sensitive files from public web roots, disabling directory indexing, restricting database access to authenticated applications and controlled networks, reviewing permissions, rotating exposed credentials or keys, examining logs and backups, and preserving evidence for investigation.
How many records were involved?
The reported database contained approximately 120 million CPF records. Tecnoblog characterized that as about 57% of Brazil’s population at the time, while CyberScoop compared it with a population of roughly 210 million. This is a count of records reportedly present—not a confirmed count of unique people whose information was downloaded.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →- It is not proof that half of every valid CPF in Brazil was exposed.
- It is not proof that half of all Brazilian citizens, all living adults or all current residents were represented.
- It is not proof that all 120 million records were readable or copied.
What information was reportedly linked to the CPFs?
InfoArmor’s reported findings associated the CPF records with basic contact information, financial-account data, credit and debit history, voting information, family relationships and other personal data.
Tecnoblog reported seeing database-related names such as:
Rank #3
dados_pessoaisdados_enderecodados_telefonedados_emprestimodados_militares
Those names do not prove that every corresponding dataset was readable. The same report said researchers could access the cpf_temp database but could not open the other listed databases. A filename is evidence of what was present in a directory, not proof of the contents or accessibility of that file.
Was this a hack or a confirmed theft?
| Term | What the reporting supports |
|---|---|
| Data exposure | An internet-connected server reportedly made sensitive information accessible to unauthorized users. |
| Data breach | A broad news term often used for unauthorized exposure; it does not by itself prove copying. |
| Exfiltration or theft | Not established by the available reporting. There is no demonstrated proof that someone downloaded or removed the database. |
| Identity fraud | Not established as a consequence of this server. Risk warnings were predictive, not findings tying particular fraud cases to it. |
Anyone who knew or discovered the server address could potentially have accessed exposed content. InfoArmor warned that criminal or intelligence groups could plausibly have collected it, but the available accounts do not identify a copier or prove misuse.
Free tools Windows power users keep installed
One-click scans. No signup required.
Who owned the server?
The owner was not identified. Researchers associated the infrastructure with alibabaconsultas.com, described in coverage as a Brazilian service related to online credit or payroll-loan inquiries, but they did not establish that the domain was legally responsible for the database. It may have been involved in hosting or another service role.
Rank #4
The similar name should not be confused with Alibaba Group, the Chinese e-commerce company. The reports do not establish that Alibaba Group, the Brazilian government, a particular bank or a named credit bureau owned the exposed server.
Why the exposure created real identity-fraud risk
- Phishing and impersonation: A message containing a real CPF, address or family detail can appear credible.
- Credit and loan fraud: Financial history and identifiers can support fraudulent applications or targeted social engineering.
- Account-recovery attacks: Personal details can help an attacker answer verification questions or persuade support staff.
- Identity correlation: A CPF can be matched with other leaked datasets to build a more complete profile.
- Harassment or extortion: Family and address information can make threats more targeted.
These are plausible consequences of the data categories described in the reporting, not confirmed outcomes of this particular exposure.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What Brazilian readers can do now
There is no verified public list showing exactly which people were included, so sensible precautions are general rather than a promise of individual confirmation.
Recommended Free Tools
Best Value
- Treat unsolicited calls, email, text messages and WhatsApp requests for CPF, banking or authentication details as suspicious.
- Contact a bank through its official app, website or telephone number if you see unexplained credit activity, loan inquiries, account changes or transfers.
- Review credit reports and alerts offered by Brazilian credit bureaus.
- Use unique passwords and multifactor authentication for email, banking and other important accounts.
- Do not treat knowledge of your CPF as proof that a caller or message is legitimate.
- Report suspected identity fraud to the relevant financial institution and Brazilian authorities.
- Avoid entering CPF details into unofficial “leak checker” websites, which can collect more information than they return.
Lessons for organizations
- Keep sensitive records out of public web directories and production web roots.
- Disable directory indexing unless it is explicitly required and controlled.
- Use network segmentation and least-privilege permissions so a web server cannot freely expose database files.
- Maintain an inventory of internet-facing assets, vendors and hosted systems.
- Monitor external attack surface, access logs and unusual file or database changes.
- Define notification and incident-response procedures, including evidence preservation.
- Minimize stored personal data and set retention rules that reduce the impact of one exposure.
Brazil’s data-protection framework is governed by the Lei Geral de Proteção de Dados; legal duties and enforcement timing should be assessed according to the provisions in force at the relevant date, rather than projected backward from later practice.
Bottom line
A credible 2018 report described an extraordinary exposure: roughly 120 million CPF records on a publicly reachable, misconfigured server. The scale justified serious concern, but the evidence stops short of proving that all records were downloaded, that a government agency owned the database, or that the incident caused documented identity fraud. The durable lesson is that a persistent identifier becomes especially dangerous when poor internet-facing configuration combines it with detailed personal and financial data.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




