Brazil's Central Bank moves to tighten Pix security and consider constitutional protection
The Central Bank of Brazil is evaluating new restrictions on the use of Pix, the country’s instant payment system, for financial institutions that fail to meet cyber‑security standards. Institutions deemed vulnerable could face limits on transaction hours, amounts, or be barred from registering new Pix keys. The proposal follows a series of high‑profile hacking incidents, notably a June 2025 breach that diverted about R$ 813 million, and a total of roughly R$ 1.5 billion in losses since the previous year. The Bank has issued a questionnaire with more than 400 items to assess institutions’ IT controls, use of artificial intelligence, and data‑protection measures, and is preparing a regulatory framework that would allow preventive sanctions.
In parallel, Senator Plínio Valério has urged a vote on constitutional amendment PEC 65/2023, which would embed Pix in the Brazilian Constitution and guarantee its free, non‑outsourcable status. Attorney‑General Jorge Messias reiterated that Pix is a sovereign national asset and will not be negotiated with other countries. The Central Bank has also introduced new rules for crypto‑asset service providers (Resolutions BCB 521, 580 and 561), classifying them as type‑3 financial institutions and imposing Basel‑based capital requirements from 2027, signaling a broader effort to bring digital payments and virtual assets under stricter oversight.