A significant data breach involving Brazil’s Health Surveillance Information System, known as SISVISA, has resulted in the exposure of 102,215 sensitive records. According to Security Affairs, the vulnerability originated from a publicly accessible database that lacked authentication, allowing unauthorized users to view, download, or potentially alter critical government files.
Security researcher Jeremiah Fowler discovered the unprotected server, which contained approximately 79 GB of data. Following the discovery, the findings were disclosed to ExpressVPN and subsequently reported to the public. The database was not a temporary testing environment but an active system used by Brazilian health authorities for regulatory compliance, managing business permits, and tracking health inspections across sensitive sectors, including pharmacies, hospitals, and restaurants.
Data Breach Summary
| Attribute | Detail |
|---|---|
| Total Files Exposed | 102,215 |
| Total Data Volume | 79 GB |
| System Affected | SISVISA (Health Surveillance Information System) |
| Data Types | Personal IDs, Tax Records, Photos, Fingerprints, Reports |
The exposed directory structure included folders labeled "backups," "imports," "documents," and "uploads." Without the requirement for login credentials, the database leaked highly personal information, including full names, home addresses, phone numbers, CPF and CNPJ tax identification numbers, as well as scans of driver’s licenses and federal doctor ID cards. Furthermore, the repository contained photographic evidence, fingerprint records, and internal inspection documentation.
Why It Matters
The SISVISA incident highlights a critical vulnerability in the digitisation of public administrative workflows. By migrating from legacy paper-based systems to digital infrastructure—a transition initiated for the state in 2015—public bodies often introduce new attack surfaces. Beyond simple data theft, the nature of the compromised records poses a severe risk for identity theft and financial fraud. Attackers could utilize the exposed tax IDs and identification documents to bypass security protocols in other systems, open fraudulent lines of credit, or engage in long-term impersonation. Additionally, the ability for an intruder to modify files suggests that threat actors could re-upload malicious documents, effectively poisoning the integrity of the government's regulatory documentation. This event serves as a warning regarding the necessity of rigorous access controls and encryption for all public-sector digital archives.

Reader Discussion & Insights