What changed
2026-08-07 00:23 UTC → 2026-08-08 11:34 UTC ·
added
removed
Brazil tightens Pix rules and oversight rules, adds crypto retention rule
In After a June 2026 a breach of the Maranhão civil‑police database exposed cadastral data for 828 Pix keys – names, CPF numbers, bank identifiers and key creation dates – but no passwords or balances. The details, Brazil’s Central Bank of Brazil warned that the information could be used for phishing and directed users to a police‑run verification channel. Following the leak, the regulator issued a 400‑item cybersecurity questionnaire to banks and fintechs and began drafting a framework that could limit transaction amounts, operating hours, or new‑key registration for institutions that fall short of standards. The proposal is linked to a constitutional amendment (PEC 65/2023) that would embed Pix in the Constitution and to new Basel‑aligned capital rules drafted stricter standards for crypto‑asset service instant‑payment providers. On 9 In July the Bank it announced tighter rules, including caps on transfers from unregistered devices (R$ 200 per transaction, R$ 1,000 per day) and progressive sanctions – night‑time limits, reduced daily limits, removal of a tiered sanction regime that can suspend the Pix button, or permanent exclusion function for non‑compliant firms. A July 12 statement highlighted that institutions could lose the Pix function Implementation began in their apps if they fail to meet the new cyber‑security requirements. Two‑stage rule changes were set for August and September 2026. From 10 August, 2026: banks must supply detailed traceability data for each instant Pix transfer must be supplied, and a new monitoring tool will flag flags “orange accounts” used in scams. From linked to fraud. On 1 September, September the Special Refund Mechanism (MED) will allow refund contests was expanded, allowing contestations up to 80 days (up from 30) and will be revised days. A further regulation takes effect on 1 January 2027, requiring virtual‑asset service providers to aid victims in recovering scam‑related losses. These measures aim retain cryptocurrency transfers exceeding US$10,000 for up to boost transparency, speed investigations and strengthen cooperation among banks, credit unions 24 hours for additional risk analysis, targeting stablecoins used to move fraud proceeds. The regulator also faces an internal staffing challenge dubbed “PixExit,” as senior technical personnel depart for other public agencies, prompting discussions of a shared, federated fraud‑data platform to preserve continuity of security and innovation across the payment firms against criminal use of Brazil’s primary instant‑payment system. ecosystem.