IBOV 188,019.40 ▲ 1.52% IPSA 11,315.26 ▼ 1.14% IPC MEX 64,884.28 ▲ 0.57% MERVAL 3,106,216 — 0.00% COLCAP 2,489.31 ▲ 0.77% BVL PERÚ 59,515.48 ▲ 0.34% USD/BRL5.10▲ 0.08% USD/MXN16.97— 0.00% USD/CLP931.42▼ 0.66% USD/COP3,144▼ 0.81% USD/PEN3.36▼ 0.24% USD/ARS1,509▼ 0.12% USD/UYU40.24▲ 1.14% USD/PYG5,885▲ 1.63% USD/BOB12.30▲ 4.75% USD/DOP58.65▲ 0.17% USD/CRC447.49▲ 1.34% USD/GTQ7.63▲ 2.30% USD/HNL26.83▲ 1.65% USD/NIO36.62▲ 0.71% USD/VES802.80▼ 0.13% USD/PAB1.00— 0.00% USD/BZD2.00— 0.00% USD/JMD 157.28 — 0.00% USD/TTD6.68▲ 0.40% EUR/BRL5.93▼ 0.67% BRENT 88.88 ▼ 0.03% WTI 83.11 ▼ 0.11% IRON ORE 161.91 — — COPPER 6.61 ▲ 0.03% GOLD 4,461 ▲ 1.78% SILVER 65.59 ▲ 1.26% SOY 1,184 ▲ 3.20% CORN 480.50 ▲ 10.02% WHEAT 655.00 ▲ 3.93% COFFEE 317.25 ▼ 5.51% SUGAR 16.43 ▼ 1.79% ORANGE JUICE 138.55 ▼ 0.47% COTTON 85.03 ▲ 2.33% COCOA 5,719 ▲ 3.18% BEEF 223.60 ▼ 3.93% CATTLE 339.10 ▼ 3.16% LITHIUM 75.20 ▲ 1.47% PETR4 41.64 ▼ 0.05% VALE3 72.97 ▲ 0.83% ITUB4 38.60 ▼ 1.03% BBDC4 16.85 ▲ 0.36% ABEV3 14.89 ▼ 0.80% BBAS3 19.37 ▲ 0.47% B3SA3 14.26 ▼ 0.21% WEGE3 47.59 ▲ 0.49% PRIO3 59.14 ▼ 0.19% SUZB3 41.33 ▲ 2.35% RENT3 34.68 ▼ 0.09% AZZA3 15.89 ▼ 2.63% CSAN3 3.22 ▼ 1.83% RAIZ4 0.25 — 0.00% PCAR3 2.75 ▼ 0.36% GMAT3 3.65 ▼ 1.08% PSSA3 48.13 ▼ 0.54% CVCB3 1.33 ▼ 2.92% POSI3 3.36 ▲ 2.44% SLCE3 13.34 ▲ 0.30% NATU3 8.14 ▼ 0.73% IBOV 188,019.40 ▲ 1.52% IPSA 11,315.26 ▼ 1.14% IPC MEX 64,884.28 ▲ 0.57% MERVAL 3,106,216 — 0.00% COLCAP 2,489.31 ▲ 0.77% BVL PERÚ 59,515.48 ▲ 0.34% USD/BRL 5.16 ▲ 0.01% USD/MXN 17.06 ▼ 0.24% USD/CLP 913.98 ▲ 0.04% USD/COP 3,140 ▲ 0.03% USD/PEN 3.36 ▼ 0.66% USD/ARS 1,493 ▲ 0.10% USD/UYU 40.27 ▲ 1.24% USD/PYG 5,939 ▲ 1.68% USD/BOB 11.64 ▼ 0.76% USD/DOP 58.34 ▲ 1.25% USD/CRC 445.92 ▲ 0.89% USD/GTQ 7.62 ▲ 2.21% USD/HNL 26.79 ▲ 1.57% USD/NIO 36.62 ▲ 0.69% USD/VES 762.44 ▼ 0.13% USD/PAB 1.00 — 0.00% USD/BZD 2.00 — 0.00% USD/JMD 157.28 — 0.00% USD/TTD 6.70 ▲ 0.61% EUR/BRL 5.95 ▲ 1.01% BRENT 88.88 ▼ 0.03% WTI 83.11 ▼ 0.11% IRON ORE 161.91 — — COPPER 6.61 ▲ 0.03% GOLD 4,461 ▲ 1.78% SILVER 65.59 ▲ 1.26% SOY 1,184 ▲ 3.20% CORN 480.50 ▲ 10.02% WHEAT 655.00 ▲ 3.93% COFFEE 317.25 ▼ 5.51% SUGAR 16.43 ▼ 1.79% ORANGE JUICE 138.55 ▼ 0.47% COTTON 85.03 ▲ 2.33% COCOA 5,719 ▲ 3.18% BEEF 223.60 ▼ 3.93% CATTLE 339.10 ▼ 3.16% LITHIUM 75.20 ▲ 1.47% PETR4 41.64 ▼ 0.05% VALE3 72.97 ▲ 0.83% ITUB4 38.60 ▼ 1.03% BBDC4 16.85 ▲ 0.36% ABEV3 14.89 ▼ 0.80% BBAS3 19.37 ▲ 0.47% B3SA3 14.26 ▼ 0.21% WEGE3 47.59 ▲ 0.49% PRIO3 59.14 ▼ 0.19% SUZB3 41.33 ▲ 2.35% RENT3 34.68 ▼ 0.09% AZZA3 15.89 ▼ 2.63% CSAN3 3.22 ▼ 1.83% RAIZ4 0.25 — 0.00% PCAR3 2.75 ▼ 0.36% GMAT3 3.65 ▼ 1.08% PSSA3 48.13 ▼ 0.54% CVCB3 1.33 ▼ 2.92% POSI3 3.36 ▲ 2.44% SLCE3 13.34 ▲ 0.30% NATU3 8.14 ▼ 0.73%
since 2009
Thursday, September 3, 2026

Brazil Business

iFood Says Hacker Exposed 1.2 Million Brazilians Names and Tax IDs

By · June 5, 2026 · 5 min read

Daily Brief

The morning intel from across Latin America. Free.

By subscribing you agree to our privacy policy. We never share your email.

Brazil · Technology

Key Facts

The breach. iFood, Brazil’s dominant food-delivery platform, confirmed on June 3 that a hacker exposed the names and tax-ID numbers of about 1.2 million users, roughly 2% of its customer base.

What leaked. The company says only registration data — full name and the CPF taxpayer number — was affected, with no passwords, payment methods or financial records compromised.

The timing. iFood says the incident occurred in December 2025 and was contained then; it disclosed publicly only six months later, citing a Brazilian data-law exemption for breaches it judged low-risk.

The dispute. A dark-web actor claims a far larger trove of 43.8 million records including emails, phones and card data. iFood says it found no evidence supporting that figure.

The regulator. Brazil’s National Data Protection Authority (ANPD) has asked iFood for explanations and is weighing the incident’s severity.

iFood Says Hacker Exposed 1.2 Million Brazilians Names and Tax IDs. (Photo Internet reproduction)
One-stop reference
Company Intelligence
Every listed company in Latin America — financials, ownership and structure for 1,450+ companies across 26 exchanges, in one place.
Browse the directory →
RT
Ask Rio Times
Latin American markets, currencies and companies.
Open the full Ask Rio Times →

Latin America’s largest food-delivery company has confirmed a data breach affecting more than a million customers — and is now disputing a hacker’s claim that the true scale is dozens of times larger.

What the iFood data breach exposed

iFood, the food-delivery app that handles roughly 120 million orders a month for some 60 million customers across more than 1,500 Brazilian cities, said in a statement on Wednesday that personal data belonging to about 1.2 million users had been exposed. That figure represents close to 2% of its customer base. According to the company, the leaked information was limited to registration details — users’ full names and their CPF, the individual taxpayer identification number that functions as Brazil’s primary personal identifier. iFood said no passwords, payment methods, financial records or transaction histories were affected, and that it found no evidence of access to banking data.

The company characterised the episode as an isolated incident that took place in December 2025 and was quickly neutralised by its security protocols at the time. It said it operates in compliance with Brazil’s General Data Protection Law, known by its Portuguese acronym LGPD, and reminded customers to treat only the platform’s official channels as legitimate sources of communication about the matter.

A six-month delay and a regulator’s questions

One of the most contested aspects of the disclosure is its timing. The breach dates to December 2025, but iFood made it public only this week — roughly six months later. The company argued that Brazilian law waives the requirement to notify affected individuals when an incident does not create a relevant risk or harm, under the criteria set by the data-protection regulator. That justification is now itself under scrutiny.

The National Data Protection Authority, the ANPD, has requested explanations from iFood and signalled it will assess the incident’s severity, weighing factors such as the type of data exposed, the number of people affected and the potential consequences. The authority noted that even where the extent of harm is uncertain, the data controller — in this case iFood — is obliged to adopt adequate preventive measures. For a company that holds the tax IDs and contact details of tens of millions of Brazilians, the regulatory question is whether the low-risk classification that justified the delayed disclosure will hold.

The disputed 43.8 million-record claim

iFood’s confirmation followed reporting by Brazilian technology outlets and a claim circulating on a dark-web hacking forum. A user of BreachForums, a marketplace where stolen material is bought and sold, asserted last week to hold data on more than 43.8 million Brazilian iFood customers — a set said to include not only names and tax IDs but also emails, phone numbers and credit-card information. A separate cybersecurity monitor warned that, if accurate, such a trove could enable large-scale identity and financial fraud, including mass phishing campaigns using verified contact details. The actor reportedly demanded that iFood make contact by June 10 and pay an unspecified sum.

iFood pushed back firmly on the larger figure. The company said that after repeated analyses it found no evidence that 43 million user records had been leaked, and that the material posted online corresponds to the same isolated December 2025 incident it had already identified and contained. The gap between the company’s account and the criminal’s claim — and whether they describe one breach or two — remains unresolved, and is part of what the regulator will examine.

Why it matters beyond Brazil

iFood is one of Latin America’s most prominent technology champions, a Brazilian platform that has fended off well-funded challengers including a relaunch of China’s Didi-owned 99Food and the regional arrival of Meituan’s Keeta. A breach touching the personal identifiers of more than a million users — and a louder, unverified claim of a far bigger one — lands at a moment when the region’s data-protection regimes are still maturing and enforcement records are thin. For foreign investors watching Brazil’s digital economy, the episode is a test of how aggressively the ANPD will police disclosure obligations, and of how much reputational and regulatory risk sits inside the consumer-data holdings of the platforms that now mediate everyday life across the country.

Frequently Asked Questions

How many iFood users were affected?

iFood confirmed about 1.2 million users, roughly 2% of its base. A dark-web actor claims a much larger 43.8 million records, which iFood says it found no evidence to support.

What data was leaked?

According to iFood, only names and CPF taxpayer numbers. The company says no passwords, payment methods, financial records or banking data were compromised.

When did the breach happen?

iFood says the incident occurred in December 2025 and was contained then. It disclosed the breach publicly only in June 2026, citing a data-law exemption for low-risk incidents.

Is iFood facing regulatory action?

Brazil’s data-protection authority, the ANPD, has asked iFood for explanations and is assessing the incident’s severity, including the delayed disclosure.

Connected Coverage

The breach lands in a fiercely contested market we have tracked as iFood and Uber turn Brazil into a test case for super-app power, with Chinese challengers circling, detailed in Didi’s R$1bn ($190m) bet on Brazilian food delivery.

This article was produced by The Rio Times’ automated newsroom system. How we use AI · Report an error

Read More from The Rio Times

The Rio Times · Power Map
See who really holds power in Latin America
Click to open the Power Map

Rotate for Best Experience

This report is optimized for landscape viewing. Rotate your phone for the full experience.