Brazil's national health surveillance system, SISVISA, left a massive database containing over 102,000 files and 79 gigabytes of sensitive citizen data accessible online without any password protection. The exposed database contained tax identification numbers and identity documents belonging to Brazilian citizens who interacted with the country's health surveillance infrastructure.
The SISVISA system serves as a critical component of Brazil's public health monitoring framework, tracking disease surveillance and health-related incidents across the country. The platform processes personal information from citizens as part of routine health monitoring activities, making the security of its data storage systems particularly sensitive.
The misconfiguration allowed anyone with internet access to view and download the entire dataset without authentication. The 79GB repository included 102,215 individual files containing personally identifiable information that could be used for identity theft or fraud. Security researchers discovered the exposure, though the duration of the exposure period and whether malicious actors accessed the data remains unclear.
The incident affects an unknown number of Brazilian citizens whose personal information was processed through the SISVISA system. Tax identification numbers combined with identity documents provide sufficient information for criminals to commit financial fraud, open fraudulent accounts, or engage in identity theft. The exposure also raises concerns about compliance with data protection regulations and the adequacy of security practices in government health systems.
Organizations operating similar health surveillance or government database systems should immediately conduct security audits of their data storage configurations. All databases containing sensitive personal information must be protected with strong authentication mechanisms, encryption, and access controls. System administrators should verify that cloud storage buckets and database instances are not publicly accessible, implement monitoring for unauthorized access attempts, and establish incident response procedures for potential data exposures. Citizens affected by this breach should monitor their financial accounts for suspicious activity and consider placing fraud alerts with credit bureaus.
Source: https://hackread.com/brazil-health-surveillance-database-exposed-records/


