Skip to content

Insight

Five security realities reshaping how companies operate in Brazil

When Brazil appears in international headlines, it is homicide statistics, travel warnings, and crime rankings. What rarely makes the headlines is what actually determines whether a security protocol is calibrated to real threats or outdated stereotypes.

Organized Crime & Risk Trends2026-01-195 minBy Alfredo Nardi
All insights →

Brazil's security landscape is shifting faster than most risk assessments can keep up. These are five realities that decision-makers need to understand right now.

Organized crime is already in your supply chain

Most due diligence processes weren't designed to catch what happened in August 2025. Operation Hidden Carbon (Operação Carbono Oculto) revealed that Brazil's largest criminal organization, the PCC (Primeiro Comando da Capital), had infiltrated Faria Lima, São Paulo's Wall Street, controlling over 40 investment funds with more than BRL 30 billion in assets (approximately USD 5.6 billion). They weren't just running drug operations; they were operating over 1,000 gas stations, logistics networks, and port terminals across São Paulo state alone.

The Brazilian Public Security Forum estimates that organized crime diverted BRL 146 billion annually from legitimate supply chains in just four product categories: fuel, gold, beverages, and tobacco. In a survey conducted after the operation, 96% of compliance professionals identified organized crime as a growing threat to their organizations, yet only 57% said their companies had adequate controls to detect it.

What this means for you: traditional vendor vetting, which checks registration documents, financial statements, and references, isn't enough anymore. Criminal organizations are using sophisticated corporate structures that look legitimate on paper. If you are operating in Brazil's fuel, logistics, fintech, or real estate sectors, your diligence needs to include beneficial ownership verification, cross-referencing with law enforcement databases, and ongoing monitoring, not just one-time checks at onboarding.

A falling national average hides a geographic paradox

The national average tells you almost nothing about where your people actually work. Brazil's 2024 national homicide rate dropped to 17.1 per 100,000 inhabitants, the lowest in over a decade and a 6.2% decrease from 2023. International risk assessments often cite this as evidence that Brazil is 'getting safer.' But that average masks extreme regional variation that makes generic security protocols dangerously inadequate.

The reality by location: São Paulo state sits at 5.7 per 100,000 (safer than many U.S. cities). Rio de Janeiro state is at 17.1 per 100,000, exactly the national average. Pernambuco is at 35.1 per 100,000, more than double the national rate. Ceará is at 34.9 per 100,000, up 9.4% from the previous year. Feira de Santana, Bahia, sits at 55.63 per 100,000, Brazil's most violent city in 2024.

The U.S. State Department's OSAC classifies Rio de Janeiro, São Paulo, Recife, and Porto Alegre as CRITICAL threat for crime, but São Paulo's actual homicide rate is three times lower than Recife's.

What this means for you: your security protocols should vary dramatically by location. An executive traveling to São Paulo's financial district doesn't face the same risk profile as one visiting operations in Recife or Fortaleza. Route planning, transportation security, and accommodation selection need hyperlocal intelligence, not national-level statistics.

The cyber threat traveling executives aren't prepared for

Brazil just became the world's fastest-growing target for cyberattacks, and executives are the primary vector. In December 2025, Brazil recorded an average of 3,520 cyberattacks per organization per week, a 38% increase compared to the previous year and the highest growth rate globally. That is one attack every 17 minutes for every organization operating in Brazil, and it's accelerating: 2026 is projected to be Brazil's 'most critical year' for cyberattacks according to leading threat intelligence firms.

The threats targeting executives have evolved beyond phishing emails. AI-generated deepfakes are now being used to impersonate CEOs and CFOs in video calls authorizing fraudulent wire transfers. About 80% of phishing emails are now AI-generated, making them virtually indistinguishable from legitimate communications. Brazil recorded 4,500 financial scam attempts per hour in 2024, one scam every 16 seconds, resulting in over BRL 10 billion in losses, a 17% increase from 2023. Identity breaches jumped from 42% to 69% of organizations in just one year (2025–2026), with Brazil leading the world in identity-related security incidents. Ransomware attacks hit 945 publicly disclosed incidents in December 2025 alone, a 60% increase from December 2024.

What this means for you: physical security for traveling executives is no longer enough. Your team needs protocols for using VPNs on hotel WiFi, multi-factor authentication on all devices, avoiding public charging stations, verifying verbal authorization codes for financial requests (even if the 'CEO' is on video), and understanding that Brazil's instant payment system (PIX) is a major fraud vector.

Why the U.S. State Department just added a kidnapping indicator

Express kidnapping hasn't disappeared. It's just not making international headlines anymore. On May 30, 2025, the U.S. State Department updated Brazil's Level 2 travel advisory to include an explicit kidnapping indicator for the first time in years. This wasn't a bureaucratic formality. It was a response to sustained risk that many corporate security assessments had downplayed.

Brazil records 4,390 kidnapping cases annually, the highest in Latin America and the Caribbean. But the majority aren't the cinematic 'held for ransom' scenarios many corporate security assessments imagine. Express kidnappings, where victims are forced to withdraw cash from ATMs or authorize bank transfers before being released within hours, remain common in Rio and São Paulo, particularly targeting business travelers using ride-hailing apps. The U.S. Embassy also warns of 'virtual kidnappings' (fake ransom demands made via phone without actual abduction) and dating-app scams where tourists and business travelers are drugged and robbed.

What makes executives vulnerable: predictable routines. Criminals monitor patterns: same hotel, same restaurant, same route to the office, same time. Middle-level executives traveling alone, without visible security, are statistically the most frequent targets because they have access to corporate funds but lack the high-profile protection that draws attention.

What this means for you: route variation, unpredictable timing, avoiding ride-hailing pickups at hotels, using vetted drivers, and never displaying corporate logos or expensive accessories in public. Your security protocols need to assume surveillance, not respond to incidents.

What 1.96 million fraud cases reveal about Brazil's crime evolution

Street crime is falling. Digital crime is exploding. And your security strategy probably still reflects 2015. Here's the paradox: while robberies in Brazil dropped from 1.5 million to 870,320 cases between 2018 and 2023, fraud reports quadrupled, from 426,799 to 1,965,353 in the same period. Brazilian criminals aren't going away. They're pivoting from physical violence to digital exploitation, where the risk is lower and the payoff is higher.

The most common tactic: criminals posing as bank employees via WhatsApp or phone, convincing victims to 'secure' their accounts by transferring funds or providing access codes. A new banking Trojan called Eternidade Stealer has been observed spreading through WhatsApp, harvesting financial data and contact lists to fuel rapid lateral spread.

At the same time, Brazil's PCC has gone global. In 2025, Portuguese authorities confirmed the PCC was attempting to purchase football clubs in Portugal's second division as part of a money-laundering infrastructure. INTERPOL arrested a top PCC leader in Portugal in November 2025, highlighting the organization's evolution from a prison gang to a transnational criminal powerhouse with operations in Europe, Africa, and Latin America.

What this means for you: if your corporate security strategy still focuses mainly on physical threats like armored cars, gated compounds, and bodyguards, you're fighting yesterday's war. Today's threats are sitting in your employees' WhatsApp messages, impersonating your CFO on a Zoom call, or buried three levels deep in the corporate structure of a logistics partner you vetted three years ago. Security in Brazil now requires equal investment in cybersecurity, digital identity verification, and continuous vendor monitoring as it does in physical protection.

The bottom line

Brazil's security landscape in 2026 isn't defined by a single statistic or travel advisory level. It's defined by sophisticated organized crime infiltrating formal economies, extreme geographic variation in physical risk, accelerating cyber threats targeting predictable routines, persistent kidnapping tactics, and a fundamental shift from street crime to digital exploitation.

The companies that operate successfully in Brazil don't rely on outdated stereotypes or national-level statistics. They use hyperlocal intelligence, dynamic threat assessment, and integrated physical-digital security protocols calibrated to how threats actually manifest on the ground.

Sources: U.S. Department of State OSAC, Chambers Global Practice Guides, Check Point Research, Brazilian Public Security Forum, Statista, Americas Society/Council of the Americas, RSA Identity Security Report 2026.

Operational Review

Planning an assignment in Brazil?

This insight reflects field perspective, not a scoped recommendation. Blue Lion Ops reviews itinerary, exposure, and support needs directly before proposing scope.

BriefingWhatsApp