Global Scam IntelligenceDaily updates on global scam news and tactics
← Back to home
PhishingPublished: September 27, 2026Brazil

Scams Using Personal Data on the Rise: Impersonating Banks, Stores and Brands

According to Brazilian research, 32% of internet users have experienced fraud attempts using personal data, with 20% becoming actual victims. Criminals now use real personal information to build credible false narratives, impersonating banks, delivery services, and lawyers to steal money. AI-generated deepfakes have added another layer to these scams.

How Scams Work: A More Sophisticated Evolution

Traditional fraud messages were often full of errors and easy to identify. Today, criminals impersonate legitimate company communications and use real personal information about victims to make their false narratives credible and convincing.

According to a Brazilian study on Privacy and Personal Data Protection by Cetic.br, approximately 45 million Brazilians aged 16 or older—32% of internet users—report experiencing fraud attempts using personal data. Of these, 20% became actual victims. Messaging apps were the primary channel, cited in 84% of fraud attempts.

The growth of online shopping has increased exposure to fraud. According to Serasa Experian, 82% of Brazilians make at least one online purchase per month.

Common Scam Patterns

Fake Bank Manager Scam

Criminals call victims already knowing their name, tax ID number (CPF), bank branch, and recent purchases. They claim fraudulent transactions occurred and request a transfer to a "secure account" or installation of a remote access app.

Fake Lawyer Scam

Criminals use real court information available in public tribunal databases to demand fees, honoraria, or release taxes for lawsuits.

Fake Delivery Service Scam

After online purchases, victims receive messages claiming incorrect delivery addresses or small fees needed to complete delivery.

Leaked Data as Fraud Fuel

According to cybersecurity expert Carlos Cabral of Tempest Security Intelligence, "leaked personal data has become a raw material for social engineering. When criminals know true information about a victim, they build a much more plausible story and reduce suspicion on first contact."

Phishing Scams: Entry Points from Search Results

Traditional Phishing

Messages impersonating brands offer flash sales, coupons, or report false order problems to trick users into clicking malicious links that steal passwords and credit card data.

SEO Poisoning

Criminals use search engine optimization techniques to place fake websites high in search results. Searching for a store's name may lead to fraudulent sites instead.

Quishing (QR Code Phishing)

Fake QR codes lead to fraudulent websites or redirect payments without users seeing the destination before scanning. Always verify the recipient's name and amount directly on your banking app before confirming a transfer.

AI Amplifies Fraud Reach

Artificial intelligence has introduced another layer to fraud. Deepfakes—images and voices created by AI—allow criminals to swap the faces of executives, influencers, or celebrities in videos promoting false promotions, giveaways, and investment opportunities.

The technique also appears in "family scams," where criminals use photos stolen from social media to request urgent money transfers via WhatsApp. Video and audio should be treated as indicators, not proof of identity. If someone known requests money for an urgent situation, interrupt the conversation and confirm through a channel that existed before this contact.

Payment Fraud: Even at Legitimate Stores

Fraud can occur at the moment of payment or after purchase:

  • Altered invoices: Barcode numbers are changed to redirect payments
  • Pix simulation scams: Criminals claim they accidentally sent money and request a new transfer to another account
  • Fake giveaways: Forms request personal data and small fees to claim prizes
  • Fake auctions and liquidations: Electronics and vehicles sold well below market price with prepayment required
  • Fake investment opportunities: Promise guaranteed returns using real institution names

Account Takeovers: Weak Passwords

Criminal also seize accounts through WhatsApp hijacking, fraudulent mobile number porting, and password reuse. This allows criminals to use existing cards or saved data.

Prevention Strategies

The Golden Rule

Cabral recommends a practical rule that prevents most scams: "Never complete a transaction through the same channel that initiated contact. If a message arrived via WhatsApp, exit and open the official app. If you received a call, look up the phone number directly on the website or card."

Additional Precautions

  • Google searches are not guaranteed security. Scroll through results to official organic results, check the domain character by character, and bookmark frequently used stores
  • Before confirming a Pix transfer, always verify the recipient's name and amount directly on your banking app
  • Create a security word with family members to verify identities
  • Use different passwords for each service
  • Enable two-factor authentication, preferably via authenticator apps
  • Never install remote access apps requested by callers or messages

Where to Report

If you experience fraud or receive suspicious contact, report it to local police, consumer protection agencies, or your bank immediately.

Source: CartaCapital

Share