
A major cybersecurity breach has exposed sensitive personal information from Brazil’s CIEE One platform, a widely used service that connects companies with trainees and apprentices. The breach, discovered by U.S.-based cybersecurity firm Resecurity, revealed that confidential data was compromised and later offered for sale by an underground data broker known as “888.”
The incident, traced to a misconfigured Google Cloud Storage bucket, compromised a broad array of personally identifiable information (PII), including identity documents, contact details, medical reports, and scanned personal files. The breach affected a platform operated by Centro de Integração Empresa-Escola (CIEE), a key player in Brazil’s workforce development ecosystem that serves major corporations in sectors such as banking, telecommunications, energy, and technology.
According to Resecurity’s HUNTER team, which identified the breach, the exposed cloud storage was left vulnerable due to inadequate configuration and lack of basic cybersecurity protections. The company notified both CIEE and the Computer Emergency Response Team in Brazil (CERT.br), but noted that exposed cloud buckets remain a common weak point for data theft across industries.
The data broker behind the sale, operating under the alias “888,” is a well-known figure in cybercriminal marketplaces. Active since at least 2024, he is associated with a string of high-profile breaches involving companies like Microsoft and BMW’s Hong Kong division. Resecurity describes “888” as a financially motivated actor with a reputation for selling verified, high-value datasets to other cybercriminals, often overlapping with networks run by actors such as IntelBroker, recently indicted by the FBI.
The CIEE One platform, designed to personalize recruitment for internships and apprenticeships, attracts large volumes of sensitive data as part of its vetting and onboarding process. That very richness of information makes such platforms attractive targets for cybercriminals, who exploit the stolen data for identity theft and financial fraud.
Cybersecurity experts continue to warn that cloud misconfigurations remain among the top causes of data breaches globally. Recent statistics show that 41% of cloud security incidents stem from poor configuration practices, with publicly accessible storage buckets topping the list of vulnerabilities.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543