Brazil Central Bank to Tighten Pix Rules Amid Security Breaches
The Central Bank of Brazil is evaluating a set of new restrictions for banks and fintechs that do not meet minimum cybersecurity standards in the instant‑payment system Pix. Proposals include limiting transaction amounts and operating hours for vulnerable institutions, blocking the registration of new Pix keys, and in severe cases suspending or permanently excluding non‑compliant firms from the network.
The measures respond to a wave of cyber‑attacks that have caused more than R$ 1.5 billion in losses over the past year, including a high‑profile breach of C&M Software that diverted around R$ 800 million and attempted intrusions on entities such as MagaluPay. The Central Bank aims to strengthen digital safeguards, improve data accuracy, and intensify monitoring of anti‑money‑laundering and fraud‑prevention controls. While the rules target financial institutions, ordinary users should not notice changes in how Pix operates, though they may need to switch providers if their current institution is barred from the system.