Netshoes and ValeCard: the dual security alert Brazil ignored
Netshoes lost 38 million records and ValeCard suffered a ransomware attack with 107 GB exfiltrated. What this means for Brazilian SMEs now.

In less than a month, two well-known names in Brazil's digital ecosystem became synonymous with critical security failure. Netshoes, a leader in sports e-commerce, had 38 million records exposed, CPFs, phone numbers, addresses and complete registration data. ValeCard, a corporate benefits platform used by thousands of companies in the country, was seized by the ransomware group Medusa, which exfiltrated 107 GB of sensitive data and is demanding a US$ 500,000 ransom. These are not isolated accidents. They are symptoms of a data infrastructure that Brazil still treats as an expense, not as a critical asset.
Netshoes, the second leak in eight years
History matters. Netshoes had already been fined by the Public Prosecutor's Office of São Paulo in 2019, after a previous leak exposed data from 2 million customers. At the time, the company paid R$ 500,000 in a settlement and pledged to strengthen internal controls. Six years later, the number of exposed records jumped to 38 million, eighteen times larger.
What makes this case particularly serious is not just the volume. It is the nature of the data: CPF, phone number and home address are the basic triad for social engineering, financial fraud and targeted phishing. With those three pieces of information, a malicious actor can build a convincing enough profile to deceive even alert users. The combination is raw material for SIM swap schemes, opening fraudulent accounts and even more elaborate identity crimes.
The point of failure has not yet been officially disclosed by the company, but patterns in this type of e-commerce incident point to known vectors: misconfigured APIs, compromised credentials in legacy systems and lack of active monitoring for anomalous access to customer databases.
What changes for those who bought from Netshoes
If you have an account on the platform, assume your data was compromised. Change reused passwords, enable two-factor authentication on financial services linked to your CPF and monitor your name with the main credit bureaus. For companies that use Netshoes as a benefits or corporate gifting channel, review data sharing contracts with third parties; joint liability in cases of improper use exists under the LGPD.
ValeCard and the Medusa group, ransomware with double exfiltration
The attack on ValeCard follows a trend that the most sophisticated ransomware groups have consolidated over the last two years, the so called "double extortion". First, data is exfiltrated. Then, systems are encrypted. The victim loses operational access and also faces the threat of data publication if they do not pay.
The group Medusa, active since 2021 with documented victims in more than 20 countries, is known for operating its own portal on the dark web where it publishes countdowns and samples of captured data. In ValeCard's case, the 107 GB exfiltrated likely include beneficiary data, payroll files, corporate card records and client company information. The ransom demanded, US$ 500,000, is relatively contained for the group's standards, which suggests negotiations may still be ongoing.
What Medusa seeks and how it gets in
The most common entry vector for Medusa is exposed RDP (Remote Desktop Protocol) with weak or reused credentials, followed by exploitation of vulnerabilities in outdated corporate VPNs. Once inside the network, the group performs silent lateral movement for days or weeks before triggering encryption, enough time to map and exfiltrate the most valuable assets.
None of these techniques are new. All have documented countermeasures. The problem is that many Brazilian midmarket companies still have not implemented them consistently.
What Brazilian SMEs need to change now
These two incidents have a direct practical lesson for businesses that are not necessarily large corporations:
Immutable backups are not optional. The 3-2-1 strategy (three copies, two different media, one offsite) needs to include at least one immutable copy, that is, a copy that cannot be altered or deleted even by a compromised administrator. Solutions such as Veeam with Object Lock on S3, or Rubrik Security Cloud, provide this at an accessible cost for midmarket companies.
Exfiltration monitoring is different from intrusion monitoring. Many companies invest in firewalls and antivirus, but lack visibility into what leaves the network. DLP (Data Loss Prevention) tools and outbound traffic analysis, such as Darktrace or Microsoft Purview, detect anomalous large-volume data transfers before the ransomware is activated.
Third-party risk is your risk. Both Netshoes and ValeCard are direct vendors for other companies. If you use benefits platforms, corporate e-commerce or any SaaS that stores employee data, you must include those vendors in your third-party risk management (TPRM) program. This means security questionnaires, contractual incident notification clauses and, ideally, periodic audits.
The LGPD has teeth, and they are growing
The ANPD (National Data Protection Authority) opened a public consultation in 2024 to revise its sanctions regulation. The emerging scenario points to progressively larger and faster fines. Companies that have suffered prior incidents and do not demonstrate documented improvement in their security controls face growing regulatory risk, and Netshoes, given its 2019 history, is in a particularly vulnerable position in this regard.
For business leaders in Brazil, the question is no longer "will we be attacked?" The question is, when we are attacked, how much will we lose, and how much can we prove we did everything within our reach?
Those two questions define the difference between a manageable incident and an existential crisis.


