Skip to content

HerbaSis Database Allegedly Leaked, Exposing Brazilian Customers' Medical Conditions and National ID Numbers

Breach Report Brazil flagBrazil Health & Wellness / SaaS Data Leaked

HerbaSis Database Allegedly Leaked, Exposing Brazilian Customers' Medical Conditions and National ID Numbers

An actor posting as DarkMafiaX has published what they describe as the database of HerbaSis, a Brazilian business management platform used by independent nutrition consultants to track customers, orders, appointments, and wellness assessments. The schema pairs conventional customer fields with CPF national identity numbers, dates of birth, full home addresses, weight and height measurements, and a dedicated illness field. Sample records contain that field populated in plain text with conditions including diabetes, hypertension, heart disease, depression, and arthritis, attached to named individuals. The platform serves consultants of a global nutrition brand but is a separate third-party product. The claim is unverified.

Health dataPlaintext
National IDsCPF
FormatSQL & CSV
ActorDarkMafiaX

Post details

TargetHerbaSis
CountryBrazil flagBrazil
SectorWellness / Business software
ListingLeaked, contact via messenger
RecordsNot stated
DataCustomer, health, contact
Observed
ActorDarkMafiaX

!Allegedly included

  • Declared medical conditions
  • Weight & height
  • CPF national ID numbers
  • Full names
  • Dates of birth
  • Gender
  • Home addresses & postcodes
  • Multiple phone numbers
  • Email addresses
  • Occupation
  • Working hours & contact windows
  • Referral relationships
  • Consultant notes
  • Account password field

Screenshot

Potential impact

Health data is treated as a protected category under Brazil's data protection law for good reason: it cannot be withdrawn once published and carries consequences for insurance, employment, and family life. Here the conditions are recorded explicitly rather than inferred, and bound to a named person with a CPF, a birth date, and a home address, which is a complete Brazilian identity package alongside a medical profile. The customers were sharing these details to receive nutrition advice, not anticipating publication. Two further fields deepen the exposure: weight and height, and working hours with preferred contact windows, which together indicate when an individual is reachable and where.

iStatus

Unverified

The post publishes a full schema and populated sample but states no record count, so the scale cannot be assessed. The schema includes a password column whose storage format is not determinable from the sample. Dark Web Informer is not reproducing the contact routes. The breached party is the third-party platform, not the nutrition brand whose consultants use it. The account is recent with moderate standing. The claim is unverified and HerbaSis has not publicly addressed it.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest