In most WhatsApp scams involving Pix, Pix is the payment method—not the way a criminal secretly extracts your data. The scammer uses impersonation, a fake website, or a request for credentials or verification codes to collect information or persuade you to authorize a transfer. A message that includes your real CPF or other personal details still does not prove it came from a legitimate organization.
How a WhatsApp-to-Pix scam works
A common pattern is a message claiming that you owe a fee, have a delivery waiting, qualify for a refund, or must fix a bank or government account. The sender may use an official-looking logo, formal language, or information about you that is already available to them. They then direct you to a link, QR code, payment request, or conversation where they ask for personal details, login information, a verification code, or money.
For example, a supposed government representative might cite your CPF and claim an unpaid charge will cause a penalty. A link leads to a page requesting more information and a Pix payment. This is a composite example, not a report of a particular victim. The data collection happens through the false identity or page; Pix is used to move the money.
A Brazilian government cybersecurity alert published on February 13, 2026, and modified April 9, 2026, describes fake government profiles on WhatsApp that use real victim details, phishing sites, and fraudulent boleto or Pix payments. The details can include a person’s name, CPF, birth date, address, and family names. The alert explains the impersonation pattern.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
Common forms of the scam
Fake bank or government contact
A profile may copy an agency’s name, logo, or business-account presentation and claim there is a debt, investigation, benefit, refund, or account problem. The Banco Central warns people not to trust links or requests sent through messaging services. It also says it does not contact people to confirm personal data or arrange certain refunds. See the Banco Central’s warning about fake refund and “values to receive” contacts.
Fake delivery, customs, or import fee
A message may say a parcel is being held until you pay a release charge or tax. Even correct tracking or purchase details do not establish that the WhatsApp sender is genuine. The Receita Federal directs users to check through official services and make payments only through official websites or apps. Read its guidance on suspicious WhatsApp shipment messages.
Rank #2
Friend or relative asking for urgent money
A criminal may use a compromised account or a new number with someone’s photo to request an emergency Pix. Verify the request by calling the person using a number you already trust, or by speaking to them another way—not by relying only on the chat. The Banco Central recommends independently checking money-transfer requests. Its general anti-scam advice covers requests through messaging apps.
“Pix sent by mistake” reversal
Someone may claim to have transferred money accidentally and ask you to send it to a different account. First check your actual bank statement. If a payment really arrived, use your bank’s Pix return function so it goes back to the original payer; do not make a separate transfer to another account. The Banco Central explains the safe way to handle a mistaken Pix.
Rank #3
WhatsApp account takeover
A scammer may ask for the code sent when WhatsApp is registered or for another authentication or recovery code. Sharing it can help the criminal take over the account and ask your contacts for money in your name. This is a separate risk from phishing for bank details, and not every Pix scam involves malware or account hacking.
What information might the scammer want?
- Identity details: CPF, full name, birth date, address, identity-document details, or relatives’ names. These can make later impersonation more convincing; a CPF alone does not automatically give someone access to your bank account.
- Account access: bank or email passwords, WhatsApp verification codes, two-factor codes, recovery codes, or approval of a new device or session.
- Payment details: card number and CVV, Pix key, bank balance, transaction confirmation, or screenshots of a banking app.
- Device access: installation of an APK, screen sharing or remote control, or permission to read SMS messages, notifications, or accessibility controls.
Data theft and device compromise are not the same thing. A person can lose money by authorizing a transfer without installing anything, and a fake page can collect data even if no payment is made.
Rank #4
Warning signs to check
- An unexpected message claims to be from a government body, bank, courier, company, or relative.
- It pressures you to pay immediately or threatens account suspension, arrest, a growing debt, or cancellation of a delivery.
- It sends a shortened or unfamiliar link, or a QR code in a chat instead of asking you to check in the official app.
- It asks for a password, one-time code, card security code, recovery code, or an unexplained “test Pix.”
- It tells you to install an app outside the official app store or grant remote access.
- The Pix recipient name or CPF/CNPJ does not match the claimed person or organization, or an institution asks you to pay an individual account.
- It asks you to keep the conversation secret, or to return money to an account other than the one that sent it.
- The message contains accurate personal details but comes from an unverified number.
True personal details are not proof of identity: criminals can use data from leaks, public sources, commercial databases, or earlier interactions. A business-account label or official-looking logo is not authentication either.
How to verify before paying
- Stop interacting with the suspicious message. Do not click its links, scan its QR code, or answer requests for more information.
- Open the official app or type the organization’s known website address yourself. Check the alleged debt, shipment, refund, benefit, or account problem there. Do not use a link or phone number supplied in the message.
- Verify the sender independently. Call a number from the organization’s official site or contact the supposed friend or relative using a number you already have.
- Inspect the payment inside your bank app before confirming. Check the recipient’s name and CPF/CNPJ where shown, the amount, and the payment description. A matching name helps but is not conclusive; confirm the purpose and recipient through a trusted channel too.
- Never share authentication secrets. Do not disclose passwords, one-time codes, card security codes, or recovery codes, and do not approve an unexplained device request or payment.
A Pix QR code is a payment instruction, not proof that a document or sender is legitimate. When scanned and confirmed, it can make an instant Pix to the destination account rather than act like a delayed boleto. Check the recipient shown in your bank app before authorizing it. The Banco Central’s scams FAQ discusses Pix QR codes and payments.
Best Value
If you already sent a fraudulent Pix
- Contact your bank immediately through its official app, website, card number, or branch. Report fraud and ask it to initiate the Mecanismo Especial de Devolução (MED). Request it as soon as possible: the Banco Central says a request can be made up to 80 days after the transaction, but faster action improves the chance of blocking funds that remain available. Recovery is not guaranteed.
- Save the evidence: transaction ID, amount, date and time, recipient name and CPF/CNPJ, bank and Pix key, chat history, phone number, links, QR code, and screenshots. The Ministry of Justice’s post-fraud guidance also recommends preserving details of the contact and loss.
- File a police report with your state police or virtual police station, and follow up with your bank using the report and transaction information.
- Secure exposed accounts from a device you trust: change compromised passwords, revoke unfamiliar sessions, and review email, bank, and WhatsApp security. Tell contacts if your WhatsApp account may have been taken over.
- Monitor for further misuse. Review bank and card activity, credit records, and unfamiliar banking relationships or Pix keys. Banco Central’s Registrato can help you check financial relationships associated with your identity.
- Escalate if necessary. If the bank does not resolve the report, use its complaint channels and contact the Banco Central or consumer-protection authorities.
The Banco Central FAQ describes an evaluation of up to seven calendar days; if a refund is approved, it may be processed within 96 hours after that evaluation. If the receiving account lacks enough money, partial recovery may depend on later funds entering it, with monitoring described for up to 90 days. These are process timings, not a promise that money will be recovered. See the Banco Central’s explanation of the MED process. MED is a fraud-recovery mechanism, not a guaranteed chargeback for ordinary payment disputes or every mistaken transfer. The Banco Central outlines MED and Pix security protections.
If you shared information but did not pay
- If you disclosed bank credentials, card details, or authentication codes, contact the bank immediately through an official channel. Ask whether it should block a card, session, device, Pix key, or beneficiary.
- Change exposed passwords, starting with email and banking accounts, and use unique passwords. Turn on two-factor authentication through the official service and review active sessions.
- If you shared a WhatsApp registration code, use WhatsApp’s official account-security and recovery process and warn contacts through another channel if the account may be compromised.
- If you clicked a link but entered nothing, close it, check for downloaded files or unfamiliar apps, review permissions, update the device, and watch for follow-up attempts. A click alone does not prove malware was installed.
- If you installed an app or granted remote access, stop using that device for banking and contact your bank from another device. If remote control is suspected, disconnect the affected device from the internet. Review unfamiliar accessibility, notification, SMS, device-admin, VPN, and screen-sharing permissions; consider a factory reset after preserving needed evidence.
- If CPF or identity-document details were exposed, monitor credit and account-opening activity and consider notifying relevant financial institutions or established credit-monitoring services. Exposure does not by itself show that Pix suffered a data breach.
Banco Central says financial institutions must notify individual Pix-key holders when a security incident involving personal data occurs in a database, even where the incident does not produce relevant risk or harm. That is different from voluntarily giving information to a scammer. Read the Banco Central’s explanation of Pix personal-data incident notifications.
What Pix protections do—and do not—do
Pix has security controls, and participating institutions must check that Pix-key holder information is consistent with CPF or CNPJ records. Transactions are traceable through the payment system. Those controls can support investigation, but they cannot prevent a person from being deceived into authorizing a payment to an account used by a fraudster, nor do they guarantee that funds will still be available for recovery. The Banco Central describes Pix security measures and the Pix system.
Seeing a recipient’s name during a payment confirmation is not itself a data breach. The greater risk is sharing more information with an impostor, entering credentials into a fake page, approving account access, or confirming a payment without verifying its recipient and purpose.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




