What a scene is, and why Brazil's looks different
A scene is the local version of a culture: the people, the meeting places, the shared history and the arguments that make hacking a community in a particular country rather than a hobby practised alone. Scenes differ by what they organised around, and those differences last. The American underground formed into rival crews and was shaped by prosecution. The German one organised as a formal association and ended up as a technical opposition with standing before its constitutional court.
Brazil organised around access.
The origin: a network built by an NGO
The country's first public internet service was not commercial or academic. Alternex was run by IBASE, the social-research institute founded by Betinho, Marcos Arruda and Carlos Afonso - and it served non-governmental organisations before anyone else. Its public proof came at the 1992 Earth Summit in Rio, where it carried internet mail for conference participants over infrastructure assembled with the newborn RNP.
That founding fact still colours everything. The Brazilian scene has never treated network access as politically neutral plumbing, because the people who built its first access were explicitly doing politics. It is also why the country's governance ended up unusual: the domain registry, the incident response team and the exchange points all sit under a multi-stakeholder committee with civil-society seats, not inside a ministry.
The BBS years, and the fraud underground
Through the 1990s grew where every scene grew - dial-up boards, university labs, IRC channels - with the local twist that long-distance calls were expensive and the phone network was a state monopoly, so phreaking had a strong economic motive.
Then Brazil produced something the rest of the world eventually had to study: an industrial-scale online fraud culture. The country banked online early and enthusiastically, which created both the target and the expertise. The early-2000s card and banking underground - dramatised in the 2026 film O Rei da Internet - matured into the banking trojan families that researchers eventually named the Tetrade when they went international.
This is the uncomfortable half of the history and it should not be softened: for two decades, "Brazilian" in a malware report usually meant banking fraud. But the same conditions built the defensive expertise - the country's researchers became world-class at exactly the thing happening to them, which is why Brazilian names show up disproportionately in banking-malware analysis.
The builders
The scene's defensive side has names worth knowing. chkrootkit, written in 1997 by Nelson Murilo and Klaus Steding-Jessen, is probably the most widely deployed piece of security software ever written in Brazil - packaged by essentially every Linux distribution. Cristine Hoepers has run CERT.br since the late 1990s and was inducted into FIRST's incident-response hall of fame. Rodrigo Rubira Branco showed that low-level vulnerability research could be done from here and taken seriously anywhere.
And the scene has connective tissue: Anchises Moraes - co-founder of Garoa Hacker Clube, the country's first hackerspace, founder of , and a blogger who has documented the local calendar year by year for two decades. Every scene needs someone who keeps the record and introduces people to each other; communities are held together by that work far more than by any single technical finding.
What it looks like now
Dense, and unusually well-balanced between its ends.
H2HC (São Paulo, since 2004) is the deep-research anchor and the oldest security research conference in Latin America - and it just survived the hardest test a volunteer institution faces, when Rodrigo Branco stepped away after twenty-one years and Filipe Balestra took over.
YSTS is the opposite instinct: invite-only, one day, small enough that chief security officers and hackers actually argue with each other.
BSides São Paulo — the local edition of the global BSides circuit — is the answer to being closed - free, community-run, held the weekend before, and now the largest free security event in the country. That pairing is the scene's most characteristic move: when something exclusive appears, someone builds an open counterpart next to it rather than complaining about the door.
RoadSec tours the state capitals so the country does not have to travel to São Paulo. Mind the Sec serves the corporate market. Hackerspaces - Garoa in São Paulo, LHC in Campinas, and others - hold the year-round physical community that conferences cannot. And Latinoware keeps the free-software tradition, which in Brazil was always politically adjacent to the hacker one.
The honest assessment
The strengths are real: a scene with its own institutions, an open governance model other countries study, deep expertise in financial fraud and defence, and a calendar that gives newcomers somewhere to go in most months of the year.
The weaknesses are also real. Almost everything runs on volunteers with day jobs, which makes succession the standing risk. The research community is concentrated in the São Paulo–Campinas axis, and a country this size should not have one centre. Much of the best local work is published in Portuguese and therefore invisible to the international field - a language barrier the scene chose, for good reasons, and pays for anyway.
The scene's own answer to all three has been the same for thirty years: build the open thing next to the closed thing, and write down who did what. This site is, in part, an instance of that habit.