More than 102,000 records tied to Brazil’s Health Surveillance Information System (SISVISA) were exposed online through a publicly accessible database that lacked authentication or other security protections. Security researcher Jeremiah Fowler discovered the instance and reported that anyone with the URL could browse roughly 102,215 files totaling about 79 GB, exposing sensitive personal and government-related information including names, addresses, phone numbers, CPF and CNPJ tax identifiers, identity documents, inspection records, complaint files, and backup archives.
The leaked data also reportedly included scans of driver’s licenses, doctor identification cards, photos, and fingerprints, raising risks of phishing, identity theft, and financial fraud for affected individuals. Public access to the database was revoked after Fowler alerted multiple government offices, but officials had not publicly clarified how long the system was exposed, whether the database was managed by government personnel or a third party, or whether unauthorized users accessed or copied the information.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
SISVISA replaced paper-based workflows to digitize approvals and compliance tracking for Brazilian health authorities.
Public access to the database was revoked or disabled shortly after Fowler's disclosure and warnings. The sources say it remains unclear how long the database had been exposed or whether anyone accessed the data.
After discovering the exposure, Fowler alerted ExpressVPN and sent urgent warnings to several government offices about the exposed SISVISA database.
Security researcher Jeremiah Fowler found a publicly accessible SISVISA-linked database with no authentication or basic security protections, exposing 102,215 files totaling about 79 GB. The data included personal, tax, biometric, and regulatory records.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.