Brazil Health Database Leak Exposes Biometrics and IDs for 100,000+ Citizens
A publicly accessible SISVISA database leaked 79GB of sensitive data, including fingerprints and national IDs, due to a total lack of encryption.
A critical security failure in Brazil's health surveillance infrastructure has exposed the personal data of thousands of citizens and businesses. Cybersecurity researcher Jeremiah Fowler discovered a publicly accessible database associated with the Health Surveillance Information System (SISVISA) that lacked both encryption and password protection.
The leak involved approximately 102,215 documents, totaling 79GB of sensitive information. According to reports from ExpressVPN and Abijita, the exposed personally identifiable information (PII) included names, physical addresses, contact details, and national identification numbers such as CPF and CNPJ. Most alarmingly, the database contained driver's licenses and documents featuring facial photographs and fingerprints. Beyond personal data, the exposure included business inspection reports, sanitary compliance documentation, and various licensing and permit applications.
The Digital Transition Gap
SISVISA was designed as a modernization effort by the Brazilian government to transition public health surveillance from antiquated paper-based processes to digital workflows. The platform is used by health authorities to manage the regulatory compliance of businesses, including pharmacies, restaurants, and hospitals. However, this transition appears to have prioritized functionality over security, leaving a massive repository of government data open to anyone with an internet connection.
Implications for Identity Security
The exposure of high-sensitivity biometric data, such as fingerprints and facial photos, creates a permanent security risk for the affected individuals. Unlike passwords, biometric markers cannot be changed after a breach, significantly increasing the long-term potential for identity theft, financial fraud, and sophisticated targeted phishing attacks. Fowler described the incident as a "wake-up call for agencies around the world that use digital platforms to provide services to citizens and businesses."
Current Status and Outlook
Public access to the SISVISA database was restricted following a responsible disclosure notice sent by Fowler. While the immediate leak has been plugged, the incident underscores a systemic vulnerability in how government services are digitized. The lack of basic security controls, such as multi-factor authentication and encryption, suggests that the move to digital workflows may have outpaced the implementation of necessary security frameworks. Observers will be watching to see if the Brazilian government implements a comprehensive audit of other digital health platforms to prevent similar exposures.