Sinqia (Evertec) hack — August 2025
Incident facts
| Date of incident | |
|---|---|
| Publicly disclosed | September 2, 2025 |
| Target type | Infrastructure provider |
| Loss | $130,000,000Price at time of incident |
| Recovered | $108,000,000 |
| Method | Supply chain or frontend compromiseAttackers used the credentials of legitimate Sinqia IT vendors to inject unauthorised business-to-business Pix transactions into the Pix environment Sinqia operates, moving money out of interbank settlement accounts that two of its financial-institution customers hold directly at the Banco Central do Brasil. Sinqia halted transaction processing and terminated access for the credentials involved. |
| Chains | Off-chain systems |
| Outcome | Arrests or charges |
What happened
On 29 August 2025 Sinqia S.A., the Brazilian subsidiary of the Puerto Rico-based payments company Evertec, detected unauthorised activity in the environment it operates for Pix, the Brazilian central bank's instant payment system. In an 8-K filed with the U.S. Securities and Exchange Commission, Evertec said approximately R$710 million in unauthorised transactions affecting two of Sinqia's financial-institution customers were processed through that environment on the day, and that preliminary forensics indicated the transactions were introduced by exploiting the credentials of legitimate Sinqia IT vendors. Sinqia halted processing and cut off those credentials. The central bank then barred it from resuming in the national payments system until it reviewed the remediation, forcing Sinqia's clients onto other providers.
Evertec did not break the figure down or state how much was lost, saying only that a portion had been recovered and that recovery efforts continued. G1, citing sources at the affected institutions, reported that HSBC accounted for about R$670 million and the fintech Artta about R$41 million, and that the Banco Central do Brasil blocked roughly R$589 million, about 83 per cent of the diverted total. At the late-August 2025 exchange rate, R$710 million was about $130 million and R$589 million about $108 million.
HSBC said no customer accounts or funds were affected because the transactions occurred only in the provider's system, and Artta said the accounts involved are held at the central bank purely for interbank settlement.
In March 2026 the Federal Police and São Paulo prosecutors ran 'Operação Cofre Digital', making arrests and freezing assets. Investigators said suspects used shell companies to convert the diverted money into cryptocurrency. No one has been convicted.
Law enforcement
Brazilian federal and São Paulo state authorities notified on the day. In March 2026 the Federal Police and the São Paulo public prosecutor's cyber unit ran 'Operação Cofre Digital', executing three temporary arrest warrants and five search-and-seizure warrants, and imposed asset blocks on four individuals and 28 companies.
Sources
- Evertec, Inc. Form 8-K filed with the U.S. Securities and Exchange CommissionPrimary · retrieved 2026-08-01
- G1 (Grupo Globo)Secondary · retrieved 2026-08-01
- Infosecurity MagazineSecondary · retrieved 2026-08-01
- Finsiders BrasilSecondary · retrieved 2026-08-01
Official post-mortem: https://www.sec.gov/Archives/edgar/data/1559865/000155986525000043/evtc-20250829.htm
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Sinqia (Evertec) hack — August 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/sinqia-evertechttps://itokenly.com/hacks/sinqia-evertecPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.