Elections increasingly attract cyber operations that target politicians, businesses and the public. These activities range from espionage campaigns against political parties targeting operations seeking to shape opinions, sow discontent or undermine democratic processes.

This newsletter, published twice a month, provides an overview of key cyber incidents and emerging threats related to the upcoming October 2026 general elections in Brazil. It offers recommendations on how organizations and individuals can mitigate and protect against these threats.

Key incidents

In this issue we focus on the following:

Experiment exposes failure to prevent Brazilian election-related disinformation ads on Facebook

According to a press release on August 25, Amnesty International submitted 15 election-related advertisements containing disinformation to test Meta’s content moderation, with eight of them accepted and the other seven flagged but not rejected.

AI-enabled breach of Brazil’s Social Security system

According to a Cyber News article on September 9, hackers using an AI agent called “Manus AI’ breached systems associated with the Instituto Nacional do Seguro Social (INSS), which administers Brazil’s social security system as well as those for other benefits. 

USD 7.13m is the projected value of the Brazilian smart surveillance market by 2032, rising from approximately USD 2.994m in 2025. Video surveillance and analysis remain the core solution, but AI-enabled video, access control, remote monitoring and cloud services are growing rapidly in the country’s security market.

Source: “Brazil Electronic Security & Smart Surveillance Market Moves from Cameras to Recurring Intelligence”, Ken Research, September 21, 2026

Mitigation advice

  • Review existing security controls to strengthen defenses against AI-enabled threat activity, ensure they adequately address threats like automated phishing campaigns, credential theft, malicious code generation, and large-scale reconnaissance activities. Security monitoring procedures should be regularly updated to reflect evolving adversary capabilities.
  • Given the increasing use of AI to accelerate intrusion activity, companies should strengthen identity security through multi-factor authentication, privileged access management, and continuous monitoring of identity activities (human and non-human identities). Access rights should be reviewed frequently to ensure alignment with business requirements and least privilege principle.
  • Enhance awareness training to help employees identify AI-generated content, impersonation attempts, deepfakes, and manipulated information. Special attention should be given to personnel with access to sensitive information, financial systems, or executive communications.
  • Employees should be encouraged to validate politically sensitive, security-related, or potentially disruptive information through trusted and authoritative sources before acting upon or sharing it. Verification procedures help to reduce the impact of false narratives or influence operations.
  • Proactively monitor for fraudulent use of executive identities, corporate brands, and digital assets across online platforms.

Amnesty International election-related disinformation ads reveal content moderation issues 

According to the Amnesty International article, the ads were submitted to Meta’s Facebook Advertisement platform as a means of testing moderation capabilities before the upcoming October 4 Brazilian election. The “mock” ads included content falsely alleging election fraud and advocating for a military takeover. The Brazilian-Portuguese ads were developed based on social media chatter and online conversations observed by Amnesty, and were submitted (from a London location) to target Brazil’s voting age population. Eight of the ads were immediately approved by Facebook, with four of these focused on “electoral delegitimization,” and the other four straddling categories – to include urging non-participation and providing false information about when and how to vote. The seven ads that were not approved were not rejected outright, but rather were flagged for additional identity verification measures.

Potential impact: Although Amnesty International scheduled the ads to run in the future, and was thus able to ensure they never went live despite being approved, the incident nevertheless points to a potentially troubling trend in efforts to limit Brazil-election related disinformation. Moreover, the fact that the mock ads were submitted without hindrance from outside Brazil again raises the potential spectre of foreign interference in the upcoming October election, and calls into serious question the effectiveness of Meta’s content moderation efforts more broadly.

Apparent AI-enabled breach of Brazil’s social security system detected

According to the Cyber News article, their researchers first discovered the attack in July, and confirmed that hackers had successfully compromised 375 login credentials from 40 Brazilian government employees at INSS, Dataprev, and Previdencia. The threat actors also allegedly stole an unspecified number of digital certificates during the attack, which could potentially allow them to intercept or alter government web traffic. Researchers were still not clear as to how deeply into INSS-related systems the attack had penetrated, but noted that the personal data of some 214 million Brazilians could have been threatened.

Potential impact: Cyber-criminals often seek to harvest the credentials and personal data of citizens to enable their fraud-focused activities at a later date, and this was likely the motivation behind this apparent incident as well. Given that the initial targets of this particular attack were government systems and employees, however – and that INSS systems hold the personal data of some 214 million Brazilians – the stakes appear significantly higher. As noted in the article, INSS is responsible for a range of benefits and payments beyond social security, to include sickness, disability, maternity, and death. The AI-enabled nature of the attack is also noteworthy, and the overall security of Brazilian government systems in the run-up to the October election appears to remain something of a question mark.

Focus on: The evolution of Brazilian voting machines

Electronic voting machines have been used in Brazilian elections since 1996. The Superior Electoral Court project to devise the machines was driven by longstanding paper ballot fraud, as well as partially annulled elections in Rio de Janeiro in 1994, according to a September 22 article in the Latin American Post. The machines had certain initial requirements, to include no connection to the internet or any other network, portability, durability, and that they could be used and understood even by those who had never before used a computer.

Approximately 32% of voters used electronic voting during the elections in 1996, almost 58% in 1998, and virtually the entire electorate in 2000 -- and 2002 saw the first presidential elections in Brazil conducted entirely electronically. Early doubts about the voting machines seemed to focus on technological questions and a lack of computer literacy, according to the article, with distrust in recent years seemingly more politically and ideologically motivated.

Since 2009, researchers have attempted to expose weaknesses and vulnerabilities in the equipment and software, and to find and correct such issues. Human beings still play an important role in monitoring, custody, and auditing.