This work presents a review of attack methodologies targeting Pix, the instant payment system launched by the Central Bank of Brazil in 2020. The study aims to identify and classify the main types of fraud affecting users and financial institutions, highlighting the evolution and increasing sophistication of these techniques. The methodology combines a structured literature review with exploratory interviews conducted with professionals from the banking sector. The results show that fraud schemes have evolved from purely social engineering approaches to hybrid strategies that integrate human manipulation with technical exploitation. The study concludes that security measures must advance at the same pace as the growing complexity of attack methodologies, with particular emphasis on adaptive defenses and continuous user awareness.
翻译:本文综述了针对巴西中央银行于2020年推出的即时支付系统Pix的攻击方法。本研究旨在识别并分类影响用户和金融机构的主要欺诈类型,重点揭示这些技术手段的演进与日益复杂化的趋势。研究方法结合了结构化文献综述与对银行业专业人士的探索性访谈。结果表明,欺诈方案已从纯粹的社会工程学手段演变为融合人为操纵与技术利用的混合策略。研究结论指出,安全措施必须与攻击方法日益增长的复杂性同步发展,尤其需要强调适应性防御机制和持续的用户安全意识教育。