Flaws in the debt portal exposed systems to account takeovers before being patched.
YDUQS Participações unit Estácio corrected two security flaws that could have exposed student data and enabled unauthorized account access. The vulnerabilities were reported anonymously to TecMundo in January by an ethical researcher and former student.
The issues were located in the debt portal Portal Recupera Estácio. The first vulnerability involved an insecure direct object reference that let users query third-party national registry numbers (CPF) and potentially access sensitive student and staff records. The second flaw involved an exposed authentication token on a Google-indexed subdomain, which allowed access without a password and enabled account takeovers.
Estácio serves more than one million students across in-person campuses and distance-learning centers. Yduqs maintains a market valuation exceeding BRL 3.06 billion.
Estácio confirmed it applied fixes to the systems. In a statement to TecMundo, the institution denied any cyber incident occurred and asserted there is no evidence of platform data leaks, operating under the rules of Brazil's General Data Protection Law.
Newsletter
Markets in your inbox, weekly
LATAM-focused analysis, investing ideas, and the week in finance.
Keep reading