INSS confirms that beneficiary information was exposed in a leak
The National Institute of Social Security (INSS) confirmed this Thursday (21) that data from INSS policyholders was leaked following a security breach in the institute's digital system.
According to the INSS, the incident was identified almost a month ago, on April 22nd, by Dataprev, a state-owned technology company that manages data on millions of people, including retirees and pensioners.
According to technicians, data from around 2 million policyholders from the INSS was leaked. INSS.
Now on g1
The leak was reported by the newspaper "Folha de São Paulo" and confirmed by TV Globo.
In a note, the INSS said that the necessary measures were taken and reported that the majority of the data that was exposed were from deceased citizens.
"According to preliminary information, of the total number of CPFs accessed, 97% were from deceased citizens. individuals who do not have a death record - less than 3% of registered cases. The data is still being consolidated by Dataprev", stated, in a note, the INSS.
Security failure
The institute stated that, despite the data leak, a series of documents and steps are required for approval, for example, the granting of a payroll loan.
The death pension requires a death certificate, among other documents and procedures, added the INSS.
CPMI on illegal discounting of benefits wants to hear from ten former presidents of the INSS
Reproduction/TV Globo
"The granting of any benefit has a series of security locks. The INSS has reinforced its internal controls in order to offer greater security in the analysis of its benefits", says the note.
In 2024, the INSS also confirmed that another vulnerability in the system left confidential information of people with pensions and social and assistance benefits exposed.
Source: G1