Brazil
Health & Wellness / SaaS
Data Leaked
HerbaSis Database Allegedly Leaked, Exposing Brazilian Customers' Medical Conditions and National ID Numbers
An actor posting as DarkMafiaX has published what they describe as the database of HerbaSis, a Brazilian business management platform used by independent nutrition consultants to track customers, orders, appointments, and wellness assessments. The schema pairs conventional customer fields with CPF national identity numbers, dates of birth, full home addresses, weight and height measurements, and a dedicated illness field. Sample records contain that field populated in plain text with conditions including diabetes, hypertension, heart disease, depression, and arthritis, attached to named individuals. The platform serves consultants of a global nutrition brand but is a separate third-party product. The claim is unverified.
▣Post details
Brazil!Allegedly included
- Declared medical conditions
- Weight & height
- CPF national ID numbers
- Full names
- Dates of birth
- Gender
- Home addresses & postcodes
- Multiple phone numbers
- Email addresses
- Occupation
- Working hours & contact windows
- Referral relationships
- Consultant notes
- Account password field
◱Screenshot
⚠Potential impact
Health data is treated as a protected category under Brazil's data protection law for good reason: it cannot be withdrawn once published and carries consequences for insurance, employment, and family life. Here the conditions are recorded explicitly rather than inferred, and bound to a named person with a CPF, a birth date, and a home address, which is a complete Brazilian identity package alongside a medical profile. The customers were sharing these details to receive nutrition advice, not anticipating publication. Two further fields deepen the exposure: weight and height, and working hours with preferred contact windows, which together indicate when an individual is reachable and where.
iStatus
UnverifiedThe post publishes a full schema and populated sample but states no record count, so the scale cannot be assessed. The schema includes a password column whose storage format is not determinable from the sample. Dark Web Informer is not reproducing the contact routes. The breached party is the third-party platform, not the nutrition brand whose consultants use it. The account is recent with moderate standing. The claim is unverified and HerbaSis has not publicly addressed it.
DARK WEB INFORMER - THREAT INTELLIGENCE