cyberx_█
← back to indexCompliance & Regulation7 min read

BCB creates a review process and a notice for anyone flagged for Pix fraud. The notice only takes effect in February 2027

The resolution published on 18 September gives institutions seven days to answer a request to cancel a flag, requires them to keep a record of their reasoning, and sets the flag's lifespan at five years. The duty to notify the flagged person, however, only begins on 1 February 2027 — and does not include the reason.

Robert F.
BCB creates a review process and a notice for anyone flagged for Pix fraud. The notice only takes effect in February 2027
▸In this article

On 18 September 2026 the Banco Central do Brasil published BCB Resolution No. 587, which amends the Pix Regulation on several fronts. One of them touches a point we have been following since the start of the month: the well-founded-suspicion-of-fraud flag, the entry an institution records in the Pix directory against the CPF or CNPJ of one of its own customers and which then becomes visible to every other participant.

Until now, the Regulation stated who could apply a flag and what the flag blocked. It said nothing about the flagged person: not that they had to be notified, not how they could challenge it, not within what deadline they would get an answer. That is what we showed in two analyses published on 3 and 10 September. The new resolution fills part of that gap.

What now exists

The resolution adds three articles to the Pix Regulation and rewrites a fourth.

The rewritten one is art. 78-HA, which since September 2025 has authorised an institution to flag its own customer. The old wording referred to a "transactional fraud flag" for a customer "involved in a fraud episode". The new wording refers to a "well-founded-suspicion-of-transactional-fraud flag" for a customer involved in a transaction "with well-founded suspicion of fraud". The rule now calls the flag what it is: a suspicion, not a finding.

Art. 78-HB defines who answers for the flag: the institution that accepted the infraction report, or the one that created the flag on its own initiative. They are, the text says, "the parties responsible for the respective well-founded-suspicion-of-fraud flag recorded in the DICT", tied to the CPF or CNPJ and, where available, to the Pix key.

Art. 78-HC creates the challenge route. The responsible institution "must ensure that users subject to the flag are able to submit a cancellation request". It falls to that institution to review the request and decide "whether to maintain or cancel the flag within seven days, counted from the date of receipt". The flag "must be cancelled if, after review of the case, no elements remain that justify maintaining the well-founded suspicion of fraud". And the institution "must keep a record of the grounds relied upon for maintaining or cancelling" it.

Art. 78-HD sets the term: the flag stays attached to the CPF or CNPJ "for a period of five years, counted from the date the entry was recorded in the DICT". The five years were already the window covered by the queries institutions run against the directory; they are now written into the Regulation as the lifespan of the flag itself.

The notice, and its date

The duty to notify sits in the sole paragraph of art. 78-HB: the institution that creates the flag "must inform the user that the flag has been applied, stating, at a minimum, the date of the flag, the possibility of review of the measure, and the channel available for clarifications and for requesting review".

Three things in that paragraph deserve attention.

The first is what the minimum does not include: the reason. The person will know they have been flagged, when, and where to complain. Why they were flagged is something the rule obliges no one to disclose — and does not forbid either: explaining the reason is left to the discretion of whoever applied the flag.

The second is the date. Art. 5 of the resolution splits the effective dates, and item I, sub-item g, places exactly this on the list of provisions that only take effect on 1 February 2027: "art. 78-HB, sole paragraph". The main body of the article, which defines who answers for the flag, was not deferred. The other flagging provisions — the seven-day review, the record of grounds, the five years — apply from publication.

The third is scope. The body of the article treats as responsible for the flag both the institution that creates it on its own initiative and the one that accepts an infraction report from another participant. The notice paragraph speaks only of whoever "creates the flag". The text does not clarify whether the duty to notify also covers a flag that originates from accepting a report.

The result is a four-and-a-half-month window in which there is a right to request review of a flag that no one is required to disclose. Until February, those who have been flagged will keep finding out through the effects: a rejected Pix, a key that will not register, an account that gets closed.

What does not change

The cancellation request is reviewed by the same institution that applied the flag. There is no second instance for the user. The appeal the resolution creates, in the new art. 100-A, is of a different nature: it allows institutions to appeal decisions by the Banco Central itself, within ten calendar days, without suspensive effect — unless the authority grants it in the face of a risk of harm that would be difficult to repair.

Users also still cannot query the directory to find out whether they are flagged and by whom. The query announced for Registrato, which we covered in the second analysis, is not part of this resolution.

And what the flag produces remains the same. The resolution reaffirms that the flagging institution must reject all of the user's Pix transactions, whether as payer or as recipient, except refunds (art. 89, § 2), and that it must not register, port, or claim a Pix key in that user's name (arts. 56, § 3, 68, § 2, and 70, § 2). In key registration, the one notice that already existed remains: when rejecting the request, the institution must "inform the user of the reason for the rejection".

The rest of the resolution, briefly

  • Hybrid billing, from 1 February 2027: boleto and Pix Cobrança with a due date on the same document, for the payer to choose between. Offering it is optional. If the Pix is settled when the boleto had already been paid, the recipient's institution refunds the full amount to the payer, out of its own funds, within 24 hours (art. 41-A, § 3).
  • MED disclosure, also on 1 February 2027: institutions will have to publicise the Special Refund Mechanism "with a focus on vulnerable audiences", across their advertising and customer-service channels, "through clear and accessible information" (art. 32, X).
  • Pix Automático on salary accounts, from 1 July 2027: only Pix Automático transactions will be allowed out of a salary account, and the account does not receive Pix, except from the Tesouro Nacional and refunds.
  • Exclusion from Pix: an institution penalised with exclusion in a final decision will be disconnected immediately after notification. The Penalties Manual, from September 2025, allowed thirty days and permitted an extension; the extension has been revoked.
  • Onboarding: the Banco Central may annul the approval of any party that submitted a false or incomplete declaration during the Pix onboarding process (art. 25-B).

Sources

About the author

Robert F.

Robert F. is the founder of CyberX, a digital intelligence operation applied to investigation, based in Brazil with cross-border reach.

He works in OSINT, on-chain tracing and antifraud for legal teams, corporate compliance, banking antifraud and public authorities.

In CyberX publications we write about what can be said in public — fraud and scam typologies, digital threats, on-chain tracing, regulation, and what separates an investigation from a database lookup. Never about a case we work on, clients, matters under judicial secrecy, or operational detail that would compromise an investigation in progress — ours or anyone else's. A third party's case enters through the public official act, and through what it teaches, not through what it exposed.

Related reading

CyberX works in digital intelligence applied to investigation — OSINT, on-chain tracing, and fraud prevention. This content is informational and does not constitute legal advice.

how we write →