Article Details
Central Bank Alerts to New Attack Hacker against Payment Company
Published on September 7, 2025
The Central Bank (BC) issued a security warning on Saturday to identify a hacker attack against the E2 Pay payments company, which is not allowed to operate in the national financial system.According to the statement, there was improper subtraction of values and banks should reinforce the monitoring of all transactions, including internal.With information from Folha de S.Paulo
The episode is the fourth cyber attack recorded in 2025. In previous cases, which involved the companies C&M Software and Sinqia, the deviations reached about R $ 1.5 billion, operating flaws in the protection of intermediates that operate outside the direct regulation of the BC.Until Saturday night, the BC had not publicly commented on the incident, and E2 Pay was not located by the report.
Faced with the escalation of attacks, the BC recently announced measures to close gaps exploited by criminals.Among them are the limit of R $ 15,000 for operations via Pix and TED done by unauthorized payment institutions and stricter rules for accreditation of Information Technology Services (PSI).It was also defined that no company can start operations without prior permission of the monetary authority.
Another front of concern is the use of so-called-Ballass Accounts, often associated with fintechs.The Secretary of the IRS, Robinson Barreirinhas, admitted that Coaf cannot track the volume of illicit resources circulating through these channels.BC studies restricting or even extinguishing this instrument to reduce risks.
Also in debate is the regulation of the Banking model A Service (Baas), which allows the outsourcing of banking services.The proposal is to create specific rules to ensure fraud security, solidity and prevention.According to BC's director of regulation, Gilneu Vivan, the expectation is to complete later this year the new normative, which should impose adjustments on existing contracts.