The Tribunal de Contas da União (TCU) ordered the Instituto Nacional do Seguro Social (INSS) to suspend all new consigned-loan contracts nationwide [1].
This suspension affects millions of social security beneficiaries who rely on these loans for immediate liquidity. The move highlights critical vulnerabilities in the digital infrastructure used to manage payroll-deductible credit, potentially exposing vulnerable citizens to predatory lending and financial fraud.
The decision, announced on April 29, 2026 [2], mandates an immediate halt to new personal loans and credit-card consigned modalities [1]. The TCU said security flaws within the e-Consignado system could be exploited for abusive practices [3]. To address these gaps, the TCU requires the INSS and Dataprev to implement security locks within 45 days [3].
While the audit court identified signs of fraud in these operations [1], other reports indicate the TCU has not concluded that all previous discounts were irregular [4]. The scale of these financial products is significant; total discounts for consigned loans reached nearly R$90 billion in 2023 [4].
The suspension is intended to be comprehensive across Brazil [1]. However, some financial institutions are already challenging the order. The bank C6 said it obtained a court decision allowing it to resume offering consigned loans despite the general INSS suspension [3].
The TCU's intervention focuses on the technical integrity of the system. By forcing a pause, the court aims to ensure that internal security adjustments are fully operational before the public can again access these credit lines [1].
“The TCU ordered the INSS to suspend all new consigned-loan contracts nationwide.”
The suspension represents a systemic clash between the need for rapid digital credit access and the necessity of robust cybersecurity for social welfare beneficiaries. Because consigned loans are deducted directly from pensions, any system flaw can lead to irreversible financial loss for the elderly and disabled. The 45-day window for security upgrades suggests the vulnerabilities are structural rather than superficial, and the legal challenge by C6 indicates a potential fragmented rollout of the suspension.





