Simultaneous cyberattack hits Caixa lottery outlets across several Brazilian states
Boleto payments made without authorization, terminals taken offline, and transfers nobody recognizes: on Tuesday afternoon (21/7), lottery shop owners across Brazil reported intrusions into Caixa Econômica Federal’s banking systems inside their outlets. The incident matters for high-risk PSPs because the affected network is centralized: when the provider pulls the plug, or the attacker gets in, the damage hits a lot of merchants at once.
- First signs of unusual activity started circulating around 3 p.m. in category messaging groups. Reported amounts ranged from R$ 4,500.00 to R$ 5,000.00, while one unit said unauthorized boleto payments reached R$ 500,000 in a single outlet.
- At least hundreds of lottery outlets were affected simultaneously in at least three states, according to reports exchanged among business owners. A São Paulo shop alone said it had processed more than R$ 300,000 in boletos since the irregular activity began.
- An internal message sent to partners said “the automatic monitoring of the TFLs detected an atypical volume of transactions in several UL” and that there was “a crisis room at the moment to identify what is happening.” It also confirmed “general intermittency” and service “unavailable in the UL,” without giving any timeline for normalization.
- In response, lottery outlets in several states started shutting down all equipment, “even the unaffected ones,” according to one business owner. Reports mentioned compromised units in Rio Grande do Sul, Minas Gerais, Santa Catarina, and São Paulo.
- Caixa Econômica Federal had not issued any official statement by the time of publication. Lottery owners said Caixa later centralized the blocking of boleto receipt across the network, which stopped new transactions but did not reverse those already processed. Owners were also instructed to check the “Conexão Parceiros” system for consolidated terminal activity and cash-flow reports.
The thing high-risk PSPs will recognize here is the operational shape of the problem: a centralized banking layer serving hundreds of outlets can turn one incident into a network-wide event in minutes. When the provider does not immediately confirm scope, remediation, and reimbursement, every merchant is left reconciling losses on its own.
Weekly high-risk digest
Regulation, sanctions and payment news across your verticals — once a week, free.
Please check your inbox and click the link to confirm your subscription.
Please enter a valid email address!