Researcher Jeremiah Fowler found a publicly accessible database that turned out to belong to SISVISA, Brazil’s Health Surveillance Information System, and alerted ExpressVPN, which later shared the findings with Hackread. The exposed instance held exactly 102,215 files, roughly 79 GB of data, tied to a platform regulators use to track health rules, issue licences and manage inspections for hospitals, restaurants and pharmacies. In other words, it wasn’t some forgotten test box in a corner; it was wired into how the state does its job. “Over 102,000 private records belonging to Brazil’s health surveillance system were left online without passwords or basic encryption.
Security researcher Jeremiah Fowler found this publicly accessible database and alerted cybersecurity firm ExpressVPN, which later shared the details with Hackread.com.” reads the report published by Hackread. “According to Fowler, this open database stored exactly 102,215 files (around 79GB). Further probing revealed that these records belong to Brazil’s Health Surveillance Information System (SISVISA). For your information, this is a crucial platform used by Brazilian health authorities to track public health rules, issue business permits, and manage inspections for hospitals, restaurants, and pharmacies.” Once inside, Fowler didn’t need exploits or clever tricks.
Anyone who knew the URL could browse folders called “backups”, “imports”, “documents” and “uploads” with no login at all. Inside there were full names, home addresses, phone numbers, CPF and CNPJ tax IDs, scans of driver’s licences and federal doctor ID cards, photos of faces and fingerprints, inspection reports, complaint records and compressed backup archives. This is the kind of data that doesn’t just identify you; it lets someone convincingly pretend to be you.
With that in hand, attackers can run phishing and impersonation campaigns, open lines of credit, or plug tax IDs into other breached datasets until something cracks. They can also weaponise the files themselves by adding malware to documents and re-uploading them, or by locking the whole thing and asking for ransom. During the investigation, Fowler found that the exposed server could be accessed without login credentials, revealing sensitive personal and government documents, including IDs, tax records, photos, and regulatory files. “Scammers can get quick access to sensitive data like tax numbers or photos of driver’s licenses and trick people or steal funds.
They may also download the files, add viruses to them, and put them back online or even lock the whole system and demand ransom to return access.” continues the report. If you’ve spent years pushing “go digital” inside a public body, this is the flip side. SISVISA replaced slow, paper-based workflows in 2015 and made it much easier to approve applications and track compliance.
That speed gain is real, but paper stored in a filing cabinet doesn’t show up in a Shodan scan or get scraped at scale in a weekend. It’s still not clear whether this instance was run directly by a government team or handed off to a third-party provider. Fowler sent urgent notices to several agencies; public access went away shortly afterwards, but no one ever replied, and there’s no public timeline for how long the data was exposed or who else may have pulled it.
That silence is a finding in sé, and not il migliore. “However, Fowler clarified that it is still unclear if government staff ran this database themselves or hired a third party to do it.” concludes the report. “The researcher sent quick warnings to several government offices after finding the exposed data, and public access was turned off shortly after that. However, no official ever replied to the warnings, so no one knows how long the files were left open or if anyone accessed them already.” From a defender’s point of view, the scenario is depressingly familiar: a critical system, no authentication, no encryption, and no clear owner who feels personally responsible. The twist here is the domain: health surveillance, with fingerprints and medical regulators in the mix, not just another marketing list.
That raises the stakes for fraud and for long-term abuse of identity data. If you suspect you or your organisation might be in that dataset, you can’t retroactively make it private. What you can do is watch financial accounts more closely, treat unexpected calls and emails that reference tax IDs or licences as hostile by default, and turn on multi-factor authentication wherever it’s available.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon