Report: data of 243M Brazilians was exposed for at least six months after the password for a database was left inside source code of a health ministry website
Context & Ripple Effects
This lands one week after [[a:960434|16 million COVID-19 patient records, including President Bolsonaro's, leaked via a spreadsheet uploaded to GitHub]] — meaning the health ministry now has two separate exposures of citizen data inside a month, this one far larger at 243M people and sitting undetected for at least six months because a credential was hardcoded into the website's source.
The story also fits a regional pattern the related coverage documents well: an ad agency leaving an open database of 150K+ personal records in 2019, and a hacker breaching Argentina's government IT network to leak citizens' details including Lionel Messi's in late 2021.
First-order effects
- Data of 243M Brazilians was readable for at least six months through a password embedded in the health ministry website's source code, directly following the ministry-linked COVID patient spreadsheet leak — putting Brazil's national health data apparatus under immediate scrutiny as the custodian of two major exposures within days.
Second-order effects
- A ministry already running COVID-19 certificate infrastructure now carries a documented track record of both leaks and, per the later ransomware attack that blocked access to millions of digital vaccination certificates, outages — forcing Brazilian authorities to treat health-data security as a systemic risk rather than an incident-by-incident problem.
Third-order effects
- Across Latin America — Brazil's repeated ministry failures, Argentina's government network breach, and older mass leaks like Taringa's 28M hacked accounts — the pattern points toward hardening of how governments store and gate citizen data, and likely regulatory pressure on public-sector credentials and source-code hygiene.
The trend: Government-held citizen data across Latin America is shifting from scattered, poorly secured databases toward a contested attack surface where a single mismanaged credential or repo can expose populations at national scale.