Tech

Hackers breach Brazil’s national emergency alert system, sending false warnings to millions

The first unauthorised alert was registered at approximately 11:40 pm on Friday, June 19, in the state of Paraná. Within hours, similar alerts reached devices in São Paulo, Rio de Janeiro, the Federal District (Brasília), Bahia, Pará, Mato Grosso do Sul, and Acre. National Secretary of Protection and Civil Defense Wolnei Wolff confirmed that a total of 10 alerts were tracked, with nine transmitted via Cell Broadcast technology and one distributed via SMS. The message displayed on phones read “Defesa Civil: misantropi4,” a leetspeak variation of the Portuguese word “misantropia,” which translates to misanthropy or hatred of humanity. No dangerous instructions accompanied the text, but the use of the “Extreme” category, reserved for imminent natural disasters, caused widespread alarm among recipients who were jolted awake by the emergency sound.

Authorities stated that the alerts were remotely triggered by an individual or group outside the National Civil Protection and Defense System. Wolff noted that attackers managed to regain access to the system after an initial attempt to block them, leading to the complete suspension of the platform. While officials confirmed there is no evidence of “structural damage” to the core infrastructure, the specific vulnerability exploited has not been publicly disclosed. Cybersecurity experts suggest the breach may have originated from an employee’s computer running an end-of-life Windows 7 operating system that lacked antivirus protection and Single Sign-On, though this remains a hypothesis under investigation. The Federal Police have been activated to investigate the incident, but no suspects have been identified, and no timeline has been provided for when the system will be fully restored.

Photo by Brett Sayles / Pexels

Brazil’s Cell Broadcast system is relatively new, mandated by the National Telecommunications Agency (Anatel) in 2022. It was piloted in 11 cities in August 2024 and expanded to cover the entire national territory by October 2025. The technology allows authorities to broadcast alerts to all devices within a cell tower’s range without requiring phone numbers or prior registration. Four major operators—Algar, Claro, TIM, and Vivo—were involved in the overnight response alongside Anatel. Security researchers have previously noted that Cell Broadcast systems globally often lack cryptographic authentication, meaning devices cannot independently verify whether an alert was genuinely sent by civil defense authorities. Academic research since 2019 has demonstrated that fake alerts can potentially be transmitted using relatively inexpensive equipment, such as software-defined radios. Whether the Brazilian attack exploited the central government platform or used a clandestine transmitter remains unclear.

Anatel advised the public to disregard the messages, clarifying that they were not issued by competent authorities. A more secure version of the platform is already under development and is expected to be activated once all digital security conditions are re-established. Wolff stated that the ministry is handling the case with “utmost technical rigor” to ensure the alert systems function with complete reliability for the protection of the population.

Thomas Reed

Thomas Reed writes about the technology industry with a focus on AI, digital services, cybersecurity, software, and emerging technologies. He follows company announcements, product changes, technical developments, and regulatory issues shaping the sector. Thomas aims to translate technical developments into clear reporting without oversimplifying important details or presenting early claims as established facts.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button