✓ verbatim from the press
About 20,000 Nubank clients received a false message on Friday (12) informing them about the bank's extrajudicial liquidation. Nubank explained on Saturday (13) that a developer accidentally triggered a communication flow used to notify about financial institution liquidations — and since no real bank was linked to the system, the company's own name appeared as automatic filling. ✓
Press quotes (2)
"O Nubank detalhou neste sábado (13) por meio de nota, que a mensagem falsa disparada a clientes do banco ontem aconteceu após um desenvolvedor ter acionado, por engano, um comando com preenchimento padrão."
"O Nubank disse em nota neste sábado (13) que um desenvolvedor acionou por engano esse sistema e, como não havia um banco real vinculado ao fluxo de comunicação, o nome do Nubank apareceu como preenchimento padrão."
The incident primarily affected clients in the Ultraviolet category, the premium service of the fintech worth $58.5 billion in market value. Messages were sent through app, SMS and email before an employee noticed the error and stopped the sending to the entire premium client base. ✓
Press quotes (1)
"As falsas notificações foram enviadas pelo aplicativo, SMS e email para parte dos clientes Ultravioleta, categoria premium da instituição financeira"
According to cybersecurity experts consulted by Valor Econômico, critical messages in digital financial institutions normally go through internal platforms that include approval flow verification, control of test environments disconnected from production and communication template validation. ✓
Press quotes (1)
"Em instituições financeiras digitais, mensagens para clientes normalmente passam por plataformas internas de comunicação, automação, CRM, push notification ou e-mail marketing integradas a bases oficiais. Um erro nesse tipo de ambiente pode ocorrer por falha humana, uso indevido de template, automação mal configurada, ambiente de teste conectado indevidamente à produção ou falha no fluxo de aprovação antes do disparo."
Journalist Luis Nassif raised an alternative interpretation in articles in Jornal do Brasil and Jornal GGN, attributing the incident to 'internal boycott' motivated by a 'disastrous personnel policy' and citing a recent exodus of key executives, including CTO Vitor Olivier and security professionals like Renan Capaverde and Justin Gehtland. ✓
Press quotes (2)
"O que ocorreu com o Nubank – com o aplicativo enviando uma mensagem comunicando aos clientes o fechamento do banco – não foi trabalho de hackers. Foi boicote interno, devido a uma política de pessoal desastrosa."
"O que ocorreu com o Nubank – com o aplicativo enviando uma mensagem comunicando aos clientes o fechamento do banco – não foi trabalho de hackers. Foi boicote interno, devido a uma política de pessoal desastrosa."
Nubank attributes the error to a developer who accidentally triggered a liquidation communication system
About 20,000 clients received the false message on Friday (12)
Covered by only some sources, or where the accounts diverge.
Covered by only some sources (2)
Folha reports possible artificial intelligence involvement in automatic filling of Nubank name
Luis Nassif attributes the incident to internal boycott motivated by toxic organizational climate
Conflicting versions (1)
Nature of the incident - technical error versus internal boycott
-
What type of code review allowed a pull request to activate a liquidation protocol?
Why it's still unknown: Nubank did not detail the code approval process that should have prevented accidental activation of the liquidation communication system.
-
How many employees have access to the emergency communication system for liquidations?
Why it's still unknown: It was not disclosed how many people in the company have permission to access or modify liquidation communication protocols.
-
What was the specific financial market impact during the period between the false alert and the denial?
Why it's still unknown: While Folha reported stock and BDR oscillations, there is no precise data on withdrawal volume, CDB spreads or detailed timeline of indicator recovery.