cyberx_█
← back to indexCompliance & Regulation12 min read

The column that should tell you whether you've been flagged — and what it says instead

The Banco Central promised that 2026 would bring a lookup showing whether your Pix key had been flagged for fraud — and warned, at the same press conference, that it would not include the reason. As of September 2026, neither exists. The report that does exist has a field called "Situação" (Status), and it answers a different question.

Robert F.
The column that should tell you whether you've been flagged — and what it says instead
▸In this article

Update, September 18, 2026. Resolution BCB No. 587, released on this date, created what this piece describes as missing: a duty for the institution to notify the person it flagged, and a review path with an answer due within seven days. The review is already in force; the notice only from February 1, 2027, and with no obligation to state the reason. The user's own access to the flag, which is the core of this analysis, is not part of the resolution and still does not exist. The section on needing to know there is something to contest describes the rules as they stood until September 17, 2026. What changed, and what was left out.

Anyone who suspects they have been flagged in the Pix system has an obvious place to look. Registrato, inside the Banco Central's logged-in area, is where citizens can see what the financial system has recorded about them: loans, accounts and relationships, bounced checks, foreign exchange. And Pix keys.

The Current Pix Keys Report returns a seven-column table: key, institution, account type, branch, account, created on, and status.

It's the last one that stops you. "Situação" — status — is exactly the name you would give to the field that answers the question.

The report itself documents, in its footnotes, what that column can say. There are three possibilities besides "active": the key may be under an ownership claim, under portability, or blocked by court order.

None of them is a fraud flag.

This is not a report missing from the menu. The absence sits inside the very field that makes the promise: there is a column called "Situação," it can be consulted, and the situation that matters most to the person consulting it is not one of the ones it can hold.

The footnote closes off the exit

Just below the table, the same report explains what to do in case of disagreement:

"To correct any information, or if you disagree with the status of any key, contact the institution shown in the report."

The instruction is reasonable, and it works for the three scenarios the report contemplates. Someone with a key under portability knows which institution to approach, because it's right there on the same line.

For a fraud flag, the instruction spins in place. The flag does not appear in the report, and therefore no institution appears in the report to approach. The path to contest it offered by the document presupposes information the document does not carry.

On the other side of the counter, it circulates freely

The record exists. The Banco Central itself describes it, in the Relatório de Gestão do Pix 2023-2025, when explaining what the Diretório de Identificadores de Contas Transacionais holds:

"the DICT stores security information, such as fraud flags on users and on Pix keys, which are shared with all participating institutions to be used in their fraud risk management mechanisms."

All participating institutions. This is the asymmetry this series has already covered in another piece, now stated in the regulator's own document: data about a person circulates among hundreds of institutions, feeds risk decisions at each one of them, and the person it refers to cannot reach it.

This is no marginal phenomenon. In 2024 alone there were 1.223 million flags, according to data obtained by Broadcast, of Grupo Estado, under Brazil's freedom-of-information law.

It's worth pinning down the roles, because public debate tends to blur them. The flag attaches to the key and to the CPF or CNPJ, as the Banco Central's own FAQ states. The flagging is done by the participating institution. The DICT, operated by the Banco Central, stores the flag and replicates it to every other institution. And the flagged person cannot read it. The regulator makes a point of saying so on the Pix security page: "The Banco Central does not flag or unflag fraud on Pix keys or users. Contact your institution." That is why the question in this piece is not why it flags, but why it does not show.

What was promised, and the caveat that came with it

In May 2025, at a press conference on new citizen-facing services, the Banco Central announced that Pix key flagging would be added to Registrato the following year, alongside reports on consórcios and Open Finance. Izabela Correa, Director of Relationship, Citizenship and Conduct Supervision, presented the timeline.

At the same press conference came the caveat, delivered by Carlos Eduardo Gomes, head of the Institutional Support Department: Registrato would not carry the reason for the flag. It would show that the key is flagged and which institution flagged it, and it would be up to the citizen to contact that institution.

It's worth registering what that means, because it is what separates this piece from the coverage at the time. What was promised was already a partial lookup — the person would know they had been flagged and by whom, not why. Even so, it would have been progress: without knowing the flag exists, and without knowing whom to approach, there is nothing to contest at all.

Not even the partial version arrived.

The other two didn't arrive either

On September 7, 2026, Registrato offers five reports: SCR, accounts and relationships, Pix keys, bounced checks, and foreign exchange. There is no fraud flag. There are also no consórcios, and no Open Finance.

Of the three reports announced for 2026, none exists.

There is a second indication, and it comes from the Banco Central itself. At the 28th Plenary Meeting of the Fórum Pix, held on March 26, 2026, the authority presented its tally of security measures completed and under way — restrictions applied to keys associated with fraud flags, MED 2.0, refinements to the risk matrix. The document runs to dozens of pages of timelines.

The word "Registrato" does not appear in it once.

That is an indication, not proof. The Fórum Pix agenda concerns the scheme itself and is aimed at participants, while Registrato is a citizen-facing service run by a different directorate; the promised lookup could be progressing outside it. What weighs is the sum: ten months after the announcement, with no regulation governing it, no report in the menu, and no mention in the only public timeline the regulator has presented.

The Banco Central knows how to do this

In that same logged-in area, two clicks away from the keys report, sits BC Protege+. The regulator describes it as "a communication service between you and the Sistema Financeiro Nacional": through it, a person tells banks that they have no interest in opening accounts and that they will not accept being listed as a responsible party, holder, or representative on third-party accounts. It's free, and it has an on-off switch.

Next to the switch, two boxes.

The first is the activation history — when the protection was switched on and off. The second is the query history, and the description is literal: "see which institution checked whether you have the protection switched on." Both retain the last six months.

In other words: the Banco Central has built, on the same screen, for the same citizen, a record that says which institution touched your data. The capability is neither hypothetical nor out for public consultation. It is deployed, working, and on offer.

It exists so you can find out who checked your protection against account opening. It does not exist so you can find out who flagged your CPF as fraud.

Before you can contest, you have to know there is something to contest

The flag comes with no notice. The Pix Regulation imposes a single duty to notify the user: when the registration of a key is rejected, the institution must state the reason. Outside that scenario, nothing obliges anyone to tell a person that they have been flagged.

What reaches the person is the effect. A refused Pix, a key that won't register, an account closed at the institution's discretion. The communication the rules require in those cases is about the institution's decision, not about the flag that prompted it and that keeps circulating. Someone who receives a closure notice has no way of knowing that behind it lies a record consulted by hundreds of other institutions, and that it will remain visible for 60 months.

The Pix security page itself describes the only signal a citizen can expect: "If someone receives a scam alert when trying to send you a Pix, contact the institutions you hold relationships with to check whether there is an active fraud flag linked to your name or to your Pix keys." The warning, when it comes, comes from a third party.

Someone who doesn't know they've been flagged approaches no one. And whoever does find out, from the symptom, runs into the second problem: finding out who did the flagging.

The Pix security page on the Banco Central's website tells anyone with a blocked or restricted account to consult the Accounts and Relationships Report in Registrato — the CCS — and to contact the institutions listed there. The CCS shows where a person holds or has held an account. It does not show flags.

Credit where the design is due: whoever applied the flag is always an institution with which the person holds or has held an account. The DICT Operational Manual is clear on this. A standalone flag can only be applied to a user "who is its client," and a flag arising from an infraction notification is closed by the participant "that holds the relationship with the user who received the flag." The CCS list, therefore, contains the right institution.

What the CCS doesn't say is which one. The list shows every relationship, current or closed, with no field pointing to the flag. The person gets a list of doors to knock on, not the data. No rule obliges an institution to disclose the flag when asked; the only mandatory communication is the reason for rejecting a key. And when the account that applied the flag has already been closed and is one among dozens, the search begins blind.

The official routes demand what they don't have

That leaves the formal petition. The Sistema de Registro de Demandas do Cidadão, or RDR, governed by Resolução BCB nº 222 of March 30, 2022, sits in that same logged-in area and is the channel through which a submission to the Banco Central travels.

The system's manual defines it as intended for the registration and forwarding of complaints and grievances submitted to the BCB by customers against financial institutions, payment institutions, consórcio administrators, and other authorized institutions.

The channel is built around naming the institution.

The Banco Central's own FAQ on Pix key flagging, updated in February 2026, offers a third route: in case of an improper flag, "contact your relationship institution" to request cancellation. The next sentence says who decides: "the institution that applied the flag may request documents proving the transaction." The Pix security page completes the picture: "Only the institution that applied the flag can cancel it, upon proof that no fraud occurred." All three texts presuppose the same thing: that the person knows which of their relationship institutions that is.

The Pix security page closes the loop. In its guidance to anyone with a blocked or restricted account, it says to consult Registrato and then instructs: "Also check whether there are active fraud flags applied by the institution." Registrato does not show flags. The official instruction presupposes the very lookup the regulator promised for 2026 and did not deliver.

Add the instruction in the keys report — contact the institution shown in it — and you have four official routes with the same point of entry: the person must know who flagged them. That is precisely the information none of them delivers.

It isn't that channels are missing. It's that the existing channels demand, as input, the data the system does not provide.

What's left

As of the date of this piece, there is no Banco Central regulation governing the promised lookup, and it does not appear in the timeline the regulator presented to the market in March.

Meanwhile, the arrangement in force has every component of a restrictive registry and none of the safeguards Brazilian law requires of registries that restrict access to a service. The record exists, stays visible for 60 months, circulates among all participating institutions, and produces concrete effects in the life of the person recorded. There is no prior notice, no right of access, and the official channels for contesting it work only for those who already know what the system refuses to show: who flagged them.

The 2026 promise was an acknowledgment of the problem. On September 10, 2026, there are fewer than four months left in the year.

Sources

About the author

Robert F.

Robert F. is the founder of CyberX, a digital intelligence operation applied to investigation, based in Brazil with cross-border reach.

He works in OSINT, on-chain tracing and antifraud for legal teams, corporate compliance, banking antifraud and public authorities.

In CyberX publications we write about what can be said in public — fraud and scam typologies, digital threats, on-chain tracing, regulation, and what separates an investigation from a database lookup. Never about a case we work on, clients, matters under judicial secrecy, or operational detail that would compromise an investigation in progress — ours or anyone else's. A third party's case enters through the public official act, and through what it teaches, not through what it exposed.

Related reading

CyberX works in digital intelligence applied to investigation — OSINT, on-chain tracing, and fraud prevention. This content is informational and does not constitute legal advice.

how we write →