Netshoes, ValeCard, and the real cost of ignoring security across the chain
38 million records exposed at Netshoes and the Medusa ransomware attack on ValeCard reveal systemic risk for SMEs connected to large platforms.

In less than 30 days, two major security incidents shook Brazil's corporate ecosystem: Netshoes had 38 million user records exposed, CPF numbers, phone numbers, and full addresses, in its second significant leak in eight years, and ValeCard, a corporate benefits manager, was hit by the ransomware group Medusa, which locked critical systems and exfiltrated 107 GB of internal data. For those who think these cases only affect the companies named in the headlines, it is time to revisit that logic.
What happened, no euphemisms
Netshoes, recurrence is not coincidence
The first Netshoes leak happened in 2018, when customer data was exposed and the company reached a settlement with the Public Prosecutor's Office. Now, in 2025, the volume is even larger: 38 million records, with data that allow full identification of natural persons. CPF combined with phone number and address is the basic input for social engineering scams, SIM swap fraud, and fraudulent credit applications.
Netshoes, now part of Grupo Magazine Luiza, has not publicly disclosed the attack vector so far. But the pattern, large volumes of structured data, silent exfiltration, absence of encryption on the most sensitive fields, points to failures in access controls for legacy databases, a classic problem in companies that grew by acquisition and never unified their security architecture.
ValeCard and the Medusa group, an attack backed by RaaS
Medusa is not a homebrew collective. It is an organized group operating under the Ransomware-as-a-Service (RaaS) model, with affiliates recruited on closed forums and its own negotiation infrastructure, including a dark web leak site where it publishes samples of stolen data as proof of compromise.
In ValeCard's case, the 107 GB exfiltrated include, according to preliminary analyses, corporate contract data, employee information, and benefits records. ValeCard processes meal voucher, food voucher, and mobility transactions for thousands of client companies across Brazil. That means the scope of impact does not stop at ValeCard's headquarters, it expands to every company that uses the platform as a service provider.
Why this matters for SMEs
There is a common misperception in the market: SMEs believe they are not targets because "they have nothing of value." The reality is that they are not targeted directly, they are compromised by ricochet.
When a company uses Netshoes as a sales channel or integrates ValeCard for benefits management, its data, and the data of its employees and customers, transit through those environments. A failure at the weakest link of the chain exposes the entire network.
What changes in practice for those with large partners
1. Security contract clauses are not bureaucracy. Any contract with vendors that process personal data needs security SLAs, an obligation to notify incidents within 72 hours (LGPD requirement, article 48), and the right to audit. If your contract with your e-commerce platform or benefits manager lacks these, renegotiate now.
2. Mapping third-party data is part of your DPIA. The Data Protection Impact Assessment does not end at your company gate. Every piece of data you share with third parties must be mapped, with the required level of protection documented. If ValeCard did not encrypt data at rest, you needed to know that before the incident.
3. Dark web monitoring is not paranoia. Services like Have I Been Pwned, SpyCloud, and enterprise solutions like Recorded Future and Flare allow monitoring whether your company credentials or data appear in leaks. The cost of a basic corporate license is a fraction of the cost of an incident notification to the ANPD.
What the LGPD requires, and what companies still do not do
The General Data Protection Law (Law 13.709/2018) is clear, the controller is responsible for damages caused by its processors. If ValeCard is a processor of an SME's data, and an incident occurs, the SME as controller can also be held liable before its data subjects.
The ANPD is still building its enforcement history, but the international precedent, especially under the European GDPR, shows that ignoring partner security has been costly for companies of all sizes. British Airways paid £20 million in fines for a third-party failure in 2020. Brazil is on a similar path.
What to do now, short list, high priority
- Audit your critical vendors that process employee or customer data. Request evidence of annual penetration tests and certifications such as ISO 27001 or SOC 2.
- Review access privileges to systems integrated via API with e-commerce and benefits partners. Least privilege is not optional.
- Implement MFA on all administrative access, especially on B2B integrations. Medusa frequently enters via compromised valid credentials.
- Test your incident response plan before you need it. A four-hour tabletop exercise with a ransomware scenario can save weeks of chaos.
The Netshoes and ValeCard incidents are not stories about careless large companies. They are stories about how digital security works as a network, and how each weak link contaminates the others. For Brazilian SMEs, the lesson is not to watch from afar. It is to understand that the next chapter may include your name.


