The encyclopedia · Marketing & Brand · Operational decision · 2018–2019
Netshoes leaked 2M customers' data, including what they bought — settlement: R$500k
Names, CPFs and shopping histories of 1,999,704 accounts. Brazil's prosecutor made Netshoes phone every customer and pay the extortionist nothing.
Netshoes · 2018-01
What happened
In January 2018, Netshoes — then Latin America's largest online sports retailer — found that data on 1,999,704 customer accounts had leaked. No credit-card numbers or passwords were exposed. What was exposed was, in its way, more personal: names, CPF tax IDs, emails, birth dates and complete purchase histories.
The purchase histories were the sting. Prosecutors noted that order records showed health purchases — blood-pressure monitors and the like — which made them sensitive personal data. Someone held the shopping record of two million people and tried to get paid for it: on 25 January 2018 the MPDFT, the public prosecutor's office for the Federal District, recommended that Netshoes pay the supposed author nothing, 'in real or virtual currency,' and contact every affected customer.
Netshoes complied. From 8 March 2018 it began phoning its way through two million customers, with thirty business days to finish. In February 2019 it settled with the MPDFT: R$500,000 to the diffuse-rights fund, plus commitments to strengthen its data-protection programme, guide consumers and run awareness campaigns on cyber risk.
The fine worked out at roughly R$0.25 per account. In July 2024, Netshoes reported another cyber incident in which customer data may have leaked. The first breach had cost less than a marketing campaign; the second suggested the lesson had been priced the same way.
Why it happened
- The list was the business: an e-commerce CRM of 2M accounts, valuable precisely because it held purchase history — the same feature that made the leak a privacy harm, not just an IT incident.
- Purchase records exposed health data — blood-pressure monitors and the like — which prosecutors treated as sensitive personal data years before Brazil's LGPD gave such data a statutory name.
- The extortion attempt turned a breach into a decision: pay the attacker quietly or disclose loudly. The prosecutor's recommendation — pay nothing, call everyone — made the choice public.
- The settlement priced the harm at R$500k for 2M accounts — about R$0.25 a customer — which taught the market that Brazilian data law, pre-LGPD, was cheaper to break than to obey.
The lesson
A customer list is not an asset you own but a liability you hold. The purchase history made it worse — health products are sensitive data, and the list knew things customers had not told anyone.
Aftermath
The case ran before Brazil's general data-protection law (LGPD) took effect, and prosecutors built it on consumer and diffuse-rights law instead. It became a reference case in Brazilian data-protection teaching — the breach where the shopping history, not the passwords, was the harm.
Sources
- MPDFT — MPDFT recomenda providências à Netshoes após vazamento de quase 2 milhões de dados de clientes
- MPDFT — MPDFT e Netshoes firmam acordo para pagamento de danos morais após vazamento de dados
- G1 — Netshoes diz que dados de clientes podem ter sido vazados após incidente cibernético
spotted an error? The club wants to know.
More like this
A livestreamer's pad brand hit ¥75M/month — then buyers found black debris sealed inside
Pontofrio dropped half its name in 2021. Three years and a refit later, it took it back.
Casper spent $423M on marketing to sell a product people buy twice a lifetime
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.