CSIDB logo
Incident

Prefeitura de Silveiras

Incident posture

Attack window
Feb 2025
Location
Brazil
Status
Ongoing
CIA posture
Available to members
Updated
2026-09-02 17:15

Linked entities

Victim
Prefeitura de Silveiras
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Undetermined
Disclosed
Mar 2025
Resolved
Pending

Summary

In February, a hacker attack targeted the municipality of Silveiras, resulting in the diversion of R$472,900.36 from municipal accounts linked to the Caixa Econômica Federal. The municipal administration reported the incident to the Civil Police and Federal Police, which opened investigations to identify the perpetrators and recover the stolen funds. The mayor also traveled to Brasília to formally request the return of the diverted amounts from the bank. Caixa Econômica Federal confirmed it is assisting the municipality and stated that the contested transactions would be analyzed individually.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In February 2025, the municipal administration of Silveiras, a city in the state of São Paulo, suffered a cyberattack that resulted in the unauthorized diversion of funds from public accounts held at Caixa Econômica Federal. According to a statement released by the Prefeitura de Silveiras, the attack compromised accounts linked to the municipality and led to the loss of R$ 472.900,36. The disclosure was made public on Thursday, March 13, when the municipal government issued a formal note addressing the incident. The administration characterized the event as a hacker attack, indicating that external actors had gained unauthorized access to the city's banking resources and transferred the funds without the knowledge or consent of local authorities. The disclosure came more than a month after the original attack, suggesting that the municipality took time to assess the situation, engage with banking officials, and coordinate with law enforcement before making the event public.

The impact of the incident centered on the financial losses sustained by the municipality, with nearly half a million reais removed from public accounts intended to serve the local population of Silveiras. The diverted funds represented a significant blow to the municipal budget, though the Prefeitura did not specify which public services or projects were directly affected by the loss. The accounts that were compromised were tied to Caixa Econômica Federal, the public bank where the city maintains its official banking relationships. The attack exploited access to these accounts to execute the unauthorized transfers, and the municipality moved quickly to engage the bank's internal investigation channels to attempt recovery of the stolen amounts. The financial institution confirmed that it was assisting the Prefeitura and opened its own inquiry into the circumstances surrounding the unauthorized transactions, working in parallel with the police investigations.

In response to the attack, the Prefeitura de Silveiras took multiple coordinated actions aimed at identifying the perpetrators, recovering the diverted funds, and strengthening accountability. The municipal administration filed reports with both the Polícia Civil and the Polícia Federal, the two main law enforcement bodies in Brazil responsible for investigating cybercrime. These agencies began parallel investigations to trace the attack to its source and identify the individuals or groups responsible. The prefeito, Edson Mota, traveled to Brasília and visited the headquarters of Caixa Econômica Federal to formally request the return of the stolen funds and to reinforce the municipality's claim on the diverted money. Caixa, in turn, provided guidance that the Prefeitura could file a formal contestation regarding the unacknowledged transactions at any of its branches, with each case to be analyzed individually. The bank also issued a public advisory warning clients to remain vigilant against suspicious activities, advising against clicking on links received via SMS, WhatsApp, or social media, and cautioning that anyone identifying themselves as a Caixa employee by phone should be treated with suspicion, with clients urged to verify such contacts through official channels.

Following the public disclosure, the Prefeitura emphasized that it was closely monitoring all procedural steps related to the case to ensure the recovery of the diverted funds and their return to the public coffers. The administration expressed its commitment to pursuing all available legal and administrative remedies, cooperating fully with the police investigations and the bank's internal review. The Caixa's official statement, issued in response to the incident, reiterated the bank's continuous monitoring of its products, services, and transactions to detect and investigate suspicious activity. The bank also highlighted that it constantly refines its security criteria for application access and financial transactions, following market best practices and adapting to the evolving methods used by fraudsters and scammers. As part of its preventive efforts, the bank stated that it regularly conducts awareness and guidance actions for clients through its service channels, website, and social media platforms. By the time the incident was reported, the outcome of the contestations filed by the Prefeitura and the progress of the police investigations had not been publicly disclosed, leaving the recovery of the funds and the identification of the attackers as ongoing processes subject to further developments.

Sources

Sources available to members: 1 source.

CSIDB