Brazilian Emergency Alert System Hacked, Sending Unauthorized Message to Phones Across States

The National Protection and Civil Defense Secretariat said the alert was sent at about 1:30 a.m. local time (0430 GMT), a detail included in the government statement reported by Reuters.
One report said the fraudulent notifications were labeled in the system as an “Extreme Alert,” indicating the attackers may have been able to trigger specific severity categories—not just text messages.
Authorities emphasized that the message content “did not originate from any official government communication” and was “likely the result of malicious interference by cybercriminals,” pointing to suspected attacker manipulation rather than an accidental failure.
Beyond restoring the platform, officials also indicated a need to strengthen protections going forward, with the investigation aimed at determining how the breach occurred and “whether any individuals or groups were responsible,” according to coverage of the Brazilian response.
Hackers sent a fake emergency alert to mobile phones across several Brazilian states at 1:30 a.m. Saturday, according to Reuters. The message — classified as an "Extreme Alert," the highest possible severity level — contained just one word: "misanthropy." The Civil Defense notification system was taken offline within the hour to stop further unauthorized transmissions.
The National Protection and Civil Defense Secretariat said the alert "did not originate from any official government communication" and was "likely the result of malicious interference by cybercriminals," CNN reported. Brazil's Federal Police have opened a criminal investigation into the breach.
The attackers did not just send a text. They triggered Brazil's Cell Broadcast Service — technology that pushes messages to every phone in a geographic area at once. The "Extreme Alert" category is reserved for imminent threats to life. It fires a loud alarm even when a phone is on silent or set to "Do Not Disturb." That meant tens of millions of people woke up to blaring alerts in the middle of the night.
Brazil has roughly 210 million active mobile lines. Reports confirmed the alert reached users in at least seven states, including heavily populated São Paulo, Rio de Janeiro, and Minas Gerais, according to Yahoo News. Social media flooded with confused and frightened posts within minutes of the 1:30 a.m. transmission.
Officials said the alert was "ordered remotely," a key detail that shifts how investigators are looking at the breach. That phrase suggests the attackers may not have broken into the system's code at all. Instead, they may have used valid login credentials — pointing to either a stolen password or a phishing attack against an administrator, CNN reported.
Tech outlets noted that if credentials — not a software flaw — were the entry point, the fix is straightforward but embarrassing: the system may have lacked basic protections like multi-factor authentication. Federal technical teams began auditing the platform's access logs and application programming interface, known as an API, to find out exactly how entry was gained.
Brazil's Federal Police are now leading the criminal investigation. Authorities say they are focused on determining how access was gained and "whether any individuals or groups were responsible," according to Reuters. The word "misanthropy" — meaning a hatred or distrust of people — is being analyzed to help identify a motive. Theories range from a lone hacker to a state actor testing Brazilian infrastructure.
The breach follows a pattern of cyberattacks on Brazilian government systems. In 2020, the Superior Court of Justice was hit by ransomware. In 2021, the Ministry of Health lost vaccination records to hackers. Officials are now treating this latest incident under Brazil's internet and data protection laws, with potential criminal charges for "cyber-invasion" and "interruption of public service," Hespress noted.
Cybersecurity experts warned the attack could do lasting damage beyond one sleepless night. When a high-priority alert turns out to be a hoax, people start ignoring future warnings. Analyst Arthur Igreja cautioned that "alert fatigue" — where citizens switch off emergency notifications — could leave millions unprotected during Brazil's frequent floods and landslides.
The Civil Defense system remains offline while technical teams work to secure it, meaning the country's primary disaster-warning tool is currently unavailable. Officials said it will be restored "as soon as possible," Reuters reported. Opposition lawmakers have already called for a congressional hearing, framing the incident as a "national security failure" and demanding stronger protections for critical infrastructure.
Publishers
14
Articles
148
Reach
162