< Back to all clusters
[BUSINESS] · Brazil · 9 sources

Brazil central bank tightens Pix rules and caps transfers on unregistered devices

The Central Bank of Brazil is enforcing stricter security standards for the Pix instant‑payment system. Starting May 2026, banks and fintechs that fail to meet new cyber‑security requirements may have the Pix function removed from their apps, face reduced operating hours or even lose their licence to operate the service.

In parallel, a rule that has been in force since November 2024 limits Pix transfers made from devices not registered with the bank to R$ 200 per transaction and R$ 1,000 per day, a measure intended to curb fraud with stolen accounts.

The regulator is also studying additional restrictions, such as limits on transaction values and hours, and the possible suspension of access for institutions with repeated security breaches. The push follows a series of high‑profile cyber‑attacks that have caused over R$ 1.5 billion in losses, including an incident at C&M Software that diverted about R$ 800 million. "Cyber‑security has become a strategic issue for the National Financial System," said Rodrigo Teixeira, director of Administration at the Central Bank, while supervising director Ailton Aquino warned that cyber risks remain a top concern.