5 Cyber Threats to Watch as Brazil Heads to the Polls
Tabla de contenido
- 1. AI-powered deepfakes that are increasingly hard to distinguish from real images
- 2. Fake websites and phishing
- 3. Defacement campaigns targeting governmental entities
- 4. Ransomware, data leaks, and the private sector
- 5. Infostealers and what compromised machines reveal
- Brazil's voting machines dare you to hack them
- What organizations should do now
- When and how are the elections running?
- Monitor your Brazilian exposure now
Brazil voted on October 4 and will vote again on October 25. These are five cybersecurity threats companies with operations, partners, or suppliers in the country should be monitoring between now and the second round, and well beyond.
Our data shows a 135% increase in the volume of claimed attacks targeting Brazilian entities between January and October 2026, compared to the same period in 2025. The much-anticipated presidential election, along with the lower skill barrier for entering the cybercriminal industry, has played a significant role in making Brazil one of the most-targeted regions. In February, Brazil became one of the ten most-targeted countries for ransomware in Latin America.
What the election adds is less a new threat than a spotlight, and a narrower window for anyone hoping to exploit the moment: a confused voter, a rushed finance employee, a journalist chasing a viral claim that voting machines were hacked when they were not. That is the risk worth watching between now and October 25, and well after it.
Here is what companies with any exposure to the country need to watch.
1. AI-powered deepfakes that are increasingly hard to distinguish from real images
Deepfakes have been commonly seen in Brazilian electoral politics, including major politicians creating AI clones of themselves and others as part of their campaign advertisements. This has led Brazilian authorities to implement one of the strictest AI election frameworks we have seen yet: deepfakes are banned outright in all campaign content, and any AI-manipulated media is required to carry a clear label.
Law does not guarantee enforcement. Deepfakes continue to appear across social media, where 54% of Brazilians get their news. The TSE has gone further still, imposing a 72-hour synthetic-content blackout immediately before and after each round of voting, backed by platform liability and fines.
The decreasing cost of creating deepfakes and the increasing sophistication of the output makes them an attractive attack vector for financially motivated actors as well. Unico, a Brazilian digital identity firm, reported a 400% jump in “homemade” deepfake fraud attempts in the first half of 2026 alone.
Brazil now accounts for an estimated 39% of all deepfake fraud cases identified across Latin America, and 80% of Brazilians say they have encountered a deepfake. Only 29% say they can reliably tell a fake video from a real one.
2. Fake websites and phishing
Elections are a hotspot for phishing scams, especially in countries like Brazil where electoral participation is mandatory.
Because voting is a legal obligation, the period leading up to an election is a high-activity window for individuals ensuring their documentation and administrative processes are in order. That is the perfect condition for a phishing campaign exploiting inertia and bureaucracy.
In September, the Electoral Courts of Brazil issued warnings to citizens about ongoing phishing campaigns. The main lures claim that access to voting or government services has been suspended, falsely announce newly introduced voter registration fees, or issue fake summonses to serve as a poll worker. Delivered through WhatsApp messages or emails, the scams often include the recipient’s full name and tax identification number, which lends an air of legitimacy. The pattern is not new: Google and Mandiant have documented long-running campaigns by groups such as PINEAPPLE that impersonate Receita Federal and the Ministry of Finance to deliver banking trojans and infostealers.

Observed cases include a WhatsApp message that leads to a malicious website impersonating the Tribunal Superior Eleitoral (Superior Electoral Court). The site asks the victim to input their taxpayer ID to verify a “pending debt.” A second page then claims the victim owes the government anywhere from 60 Brazilian reais in fines for electoral absence, up to larger amounts in legal, administrative, and registration regularization charges. Payment is routed through the PIX platform to complete the scam.
3. Defacement campaigns targeting governmental entities
Defacement is one of the most prominent politically charged cyberattacks we observe during election seasons. The low cost and high visibility of the attack make it ideal for politically motivated groups.
Our data shows a sharp difference between the volume of defacement attacks against Brazilian targets in July, August, and September of 2025 versus the same quarter in 2026.

In July 2025, the websites of the municipalities Goiatuba and Morrinhos suffered defacement attacks by a group identified as BL33DR00T. The politically motivated group, known for targeting government entities across South America, replaced institutional pages on these websites with messages critical of President Luiz Inácio Lula da Silva, along with other politically prominent individuals and public bodies.
On August 6, more than 20 municipal sites were defaced by the actor BLCKORDER. These included Vitoria City Council, and the city halls of Joao Neiva and Ibatiba, among others. The group appears to have exploited a vulnerability in Agape Consultoria, a Brazil-based business that hosted a total of 49 council websites and 32 city-hall websites.
The defacements replaced the actual content with images containing offensive phrases about politicians at local and federal levels.
As political tensions rise, more politically motivated attacks are expected, potentially targeting individuals or organizations that openly support a candidate.
4. Ransomware, data leaks, and the private sector
In the Brazilian cyber landscape, the government is not the only target, and outside the noisy defacements, the private sector is absorbing a very different kind of risk. Nearly half of everything CybelAngel is tracking this year targets private companies in Brazil rather than government bodies.
The split in attack vectors is revealing.
Around 57% of incidents against government and education bodies were defacements: noisy but largely cosmetic. Private-sector incidents skewed almost the opposite way, led by data breaches (28%), initial access sales (22%), and ransomware (20%). This is the kind of activity that rarely makes a headline until the ransom note lands.
IT services, financial services, and healthcare were the most represented private industries, and the ransomware brands behind these cases are the same ones active globally: LockBit (now on version 5.0), The Gentlemen, SECTION9, y INC RANSOM.
Historical targeting of Brazilian government organizations also carries private-sector consequences. Receita Federal, the tax authority, has suffered at least four data breach incidents since 2023, most recently when the Emperador ransomware group claimed responsibility for a September 23, 2026 attack. The sensitive and confidential data exposed in those breaches includes corporate registration data, tax classification codes, and other information belonging to private companies.
If your company has a CNPJ, your exposure is not limited to your Brazilian employees’ personal data. It can include the company itself.

5. Infostealers and what compromised machines reveal
Not every risk comes from a targeted attack. Some of it comes from ordinary malware sitting on ordinary employees’ personal computers, capable of causing tangible damage in the hands of the right (or wrong) threat actor.
At one of the country’s largest e-commerce retailers, infostealers have swept up more than 360,000 compromised machines since 2022, including dozens of employee accounts with VPN and B2B portal access.
At a major investment bank, infected employee machines carried credentials for a remarkably sensitive spread of internal systems: VPN, SSO, SAP, Salesforce, GitHub, and Citrix among them. That is the kind of access list that lets an attacker move well beyond a single stolen password.
Infostealers are typically installed through links sent to victims via phishing emails or WhatsApp messages, or through innocuous-looking social media posts. With the rise in activity during an election season, an increase in infostealer attacks is to be expected.
Brazil’s voting machines dare you to hack them
Historically, disinformation has played a prominent role in instability and conflict during election periods. In 2023, riots and protests broke out after the conclusion of the 2022 Brazilian presidential election, driven by a false rumor that the voting machines had been rigged.
Three years later, with another tight race underway, election authorities have worked hard to separate rumor from reality.
Brazil has used electronic voting since 1996, with no confirmed case of fraud altering an election result in that time. The machines are never connected to the internet, their software is digitally signed before election day, and any tampering is designed to be detected automatically, causing the machine to simply refuse to run.
The more interesting part: Brazil does not just claim the system is secure, it tests that claim publicly, every election cycle, and has done so since 2009. The Public Security Test invites vetted security researchers, “hackers do bem” (ethical hackers), to actively try to break the voting system under controlled conditions months ahead of the vote. The most recent round ran from December 1 to 5, 2025, with 35 separate test plans. Any confirmed findings get patched before results are certified. Brazil was the first country in the world to run this kind of public test on its voting infrastructure, and remains one of the very few that still does.
What organizations should do now
Line up the five threats above and a pattern emerges. The loudest ones (deepfakes, phishing, defacements) are built to exploit attention and urgency, which an election period manufactures in abundance. The quieter ones (ransomware, data breaches, infostealer-driven credential theft) do not need an election at all. They are just easier to pull off while everyone is looking somewhere else.
A few things worth doing now:
- Tighten phishing awareness and MFA enforcement for Brazil-based staff and executives, particularly around the PIX-themed and electoral-obligation lures described above.
- Monitor for lookalike domains impersonating your company and for brands falsely associated with electoral bodies, political parties, and financial institutions.
- Extend credential and infostealer monitoring to Brazilian subsidiaries, given how exposed the surrounding ecosystem already is, government and private sector alike.
- Build a short crisis-communications plan for AI-generated or deepfake content involving your brand or executives. The enforcement gaps described in Brazil’s own framework will not be unique to the TSE.
When and how are the elections running?
Brazil voted on October 4 and will vote again on October 25.
Whoever wins, the cyber pressure the country is under right now will not ease off the day the results are certified. The Brazilian government incident-response center, CTIR.Gov, counted 6,774 cyberattacks on federal networks in just the first five months of 2026, roughly 45 a day. More broadly, around 26% of all cyberattacks tracked in Brazil target government institutions, a share that remains among the highest in Latin America.
Receita Federal will likely still be a target. Small municipalities will likely still get defaced by whichever opportunistic group finds the next shared vulnerability. The banking trojans built and refined against Brazilian users will keep getting exported elsewhere, as Spanish and Portuguese banks have already discovered. The same commodity infostealers quietly compromising both government institutions and the country’s largest companies will keep doing so, with or without an election to amplify the noise around them.
None of the above is conditional on who wins.
Monitor your Brazilian exposure now
If your organization has operations, suppliers, or partners in Brazil, the window to tighten your posture is this week, not after October 25. CybelAngel maps your external attack surface across Brazilian subsidiaries and supply chains, surfaces leaked credentials from infostealer-compromised machines, and identifies the lookalike domains and brand abuse that election-season phishing campaigns rely on.