AI-driven hack snags 375 Brazil government employee logins
214 million Brazilians may be at risk.

Illustration by Cybernews
- An AI agent called Manus AI helped hackers try to break into Brazil's Social Security system, run by INSS.
- The attack stole 375 login credentials from 40 government employees at INSS, Dataprev, and Previdência.
- Hackers also stole digital certificates, which could let them intercept and alter government web traffic.
- If fully successful, the breach could have exposed Social Security data belonging to 214 million Brazilians.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
An AI agent has helped hackers target Brazil’s Social Security system. The attack, if successful, could put 214 million Brazilians at risk.
A threat actor set up an AI agent to steal digital certificates and harvest hundreds of Brazilian government employee credentials. The aim was to establish a potential man-in-the-middle foothold inside systems connected to Instituto Nacional do Seguro Social (INSS).
INSS administers Brazil's General Social Security System and is responsible for benefits including retirement, sickness, maternity, accident, death, and other social security payments.
The attack was still underway when our research team discovered the operation on July 6th. Our researchers could not determine exactly how deeply the attacker had penetrated government systems.
But the stolen credentials and certificates could have given the threat actor access to systems containing the Social Security information of more than 214 million Brazilians.
“If this attack were fully successful, the attacker could have exfiltrated a massive dataset of highly sensitive information that could be abused to commit Social Security fraud, credit fraud, and identity theft,” the researchers said.
Our team has alerted Brazil’s CERT and reached out to INSS for comment.
Anatomy of an attack
The attackers used Manus AI, an autonomous AI agent developed by the Chinese company Butterfly Effect. Meta planned to acquire Manus for approximately $2 billion, but Chinese regulators subsequently investigated the deal and blocked it.
The AI agent was running on a Google Cloud Platform command-and-control server (C2). A second C2 server was subsequently established on Microsoft Azure and used as a backup after the original infrastructure was taken down.
From there, the attacker used known weak credentials to access a Windows virtual machine belonging to INSS through Windows Remote Management.
Brazil’s digital identity certificates exfiltrated
Threat actors used the Manus AI agent to inspect the compromised machine and identify installed digital certificates. They exfiltrated the certificates, including ICP-Brazil A3 certificates, used within Brazil's digital identity infrastructure.
The stolen ICP-Brazil A3 certificates could potentially be used for authentication and digital signatures.
“At least in theory, government employee digital signatures could have also been compromised,” our researchers explained.
Employee access hijacked
According to the research team, the attacker injected a rogue Certificate Authority (CA) certificate into the compromised environment. CA is a trusted organization that verifies identities and issues digital certificates to secure websites.
This enabled the threat actor to establish man-in-the-middle access to certain government web traffic. The attacker could position themselves between an employee and an online service, intercepting and modifying the traffic.
Researchers confirmed that this capability was deployed against the VPN login panel used by Dataprev, the Brazilian public technology company responsible for processing Social Security data.
When employees attempted to access the VPN, their credentials could be captured by an attacker-controlled HTTPS proxy.
The operation yielded 375 credential pairs belonging to 40 Brazilian government employees across INSS, Dataprev, and Previdência active directory domains.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
AI agents are increasingly used in cyberattacks
This is not the first time the Cybernews research team has found AI being used as part of an active cybercrime campaign.
This June, our team uncovered a Russian hacker using HexStrike AI, combined with Anthropic's Claude, to steal data from numerous companies in the accommodation sector.
Another research project found that attackers used Claude in an attack against live BuddyBoss servers. BuddyBoss is a premium WordPress platform for e-learning and online communities.
Hundreds of websites were compromised, and thousands remain in danger.
Also, it is not the first time Brazil has been affected by a massive cyber incident. Cybernews in-house research previously uncovered a Brazilian CPF data leak that exposed the personal identification numbers of the entire population.
Disclosure timeline
Leak detected: July 6th, 2026
Initial disclosure: July 6th, 2026