Back to the archive

The encyclopedia · Marketing & Brand · Operational decision · 2018–2019

Netshoes leaked 2M customers' data, including what they bought — settlement: R$500k

Names, CPFs and shopping histories of 1,999,704 accounts. Brazil's prosecutor made Netshoes phone every customer and pay the extortionist nothing.

Netshoes · 2018-01

What happened

In January 2018, Netshoes — then Latin America's largest online sports retailer — found that data on 1,999,704 customer accounts had leaked. No credit-card numbers or passwords were exposed. What was exposed was, in its way, more personal: names, CPF tax IDs, emails, birth dates and complete purchase histories.

The purchase histories were the sting. Prosecutors noted that order records showed health purchases — blood-pressure monitors and the like — which made them sensitive personal data. Someone held the shopping record of two million people and tried to get paid for it: on 25 January 2018 the MPDFT, the public prosecutor's office for the Federal District, recommended that Netshoes pay the supposed author nothing, 'in real or virtual currency,' and contact every affected customer.

Netshoes complied. From 8 March 2018 it began phoning its way through two million customers, with thirty business days to finish. In February 2019 it settled with the MPDFT: R$500,000 to the diffuse-rights fund, plus commitments to strengthen its data-protection programme, guide consumers and run awareness campaigns on cyber risk.

The fine worked out at roughly R$0.25 per account. In July 2024, Netshoes reported another cyber incident in which customer data may have leaked. The first breach had cost less than a marketing campaign; the second suggested the lesson had been priced the same way.

Why it happened

  • The list was the business: an e-commerce CRM of 2M accounts, valuable precisely because it held purchase history — the same feature that made the leak a privacy harm, not just an IT incident.
  • Purchase records exposed health data — blood-pressure monitors and the like — which prosecutors treated as sensitive personal data years before Brazil's LGPD gave such data a statutory name.
  • The extortion attempt turned a breach into a decision: pay the attacker quietly or disclose loudly. The prosecutor's recommendation — pay nothing, call everyone — made the choice public.
  • The settlement priced the harm at R$500k for 2M accounts — about R$0.25 a customer — which taught the market that Brazilian data law, pre-LGPD, was cheaper to break than to obey.
What it costR$500k settlement; 2M customers phoned one by onecostly

The lesson

A customer list is not an asset you own but a liability you hold. The purchase history made it worse — health products are sensitive data, and the list knew things customers had not told anyone.

Aftermath

The case ran before Brazil's general data-protection law (LGPD) took effect, and prosecutors built it on consumer and diffuse-rights law instead. It became a reference case in Brazilian data-protection teaching — the breach where the shopping history, not the passwords, was the harm.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →