EVERTEC, Inc.
Aug 2025 · Graded Verified · Technology and Software · Government record
Incident summary
EVERTEC, Inc.Aug 2025
breach at Sinqia S.A.
$37.7M
Spent responding & recovering
Direct expense
The money moved through Sinqia's Pix environment on credentials stolen from its own IT vendors, which is what happens once a payment connector treats a supplier's login as its trust boundary. Roughly R$710 million in unauthorized transactions cleared before processing halted, aimed mostly at HSBC, with about half later frozen. Sinqia is the third Brazilian firm wired between banks and the central rail to be looted this way in a year: the soft spot in real-time payments is not the bank but the plumbing that reaches it.
Verified: the linked document states this figure.
SEC 8-K, Item 8.01
Initial attack type compromised credentials confirmed · Impact financial theft or fraud confirmed
Quantified 66 days after disclosure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
About this record
This incident is on the public government record: an SEC 8-K filing or a state-regulator notification, graded Verified. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.