Automated alerts in Brazil with fake “extreme emergency” calls alarmed the population
ESET analyzes the alleged attack on Brazil’s Civil Defense system, which triggered the sending of false alerts and generated concern
An alleged attack on the Civil Defense alert system, based on Cell Broadcast technology, triggered the sending of false alerts to cell phones in various Brazilian cities, generating concern about the security of critical infrastructure used to protect the population. ESET, a leading company in proactive threat detection, contextualizes the case and analyzes different protection strategies related to this type of system.
According to a report issued by the Brazilian Federal Government and sent to the Federal Police (PF), the first messages were sent to Rio de Janeiro. Subsequently, residents of Curitiba, Brasília, São Paulo, Salvador, and other locations also received notifications classified as “extreme alert,” considered the highest level in the Civil Defense alert system. This type of message is used in situations of imminent risk to life, requiring the population to take immediate protective measures.
In the case of Rio de Janeiro, the message referred to a supposed possibility of landslides, particularly sensitive information in a region historically affected by tragedies related to heavy rains. Messages also circulated mentioning a supposed possibility of a tornado in the Belo Horizonte region (MG) and other unfounded warnings. The texts contained disjointed phrases, corrupted fields, and unusual expressions, including references to a supposed “alien attack.”
The incident occurs at a time when Latin America is facing a sustained increase in extreme weather events. According to the World Meteorological Organization (WMO), in recent years the region has been affected by phenomena such as floods, droughts, hurricanes, and large-scale forest fires, reinforcing the importance of early warning systems to protect the population.
“In this context, several countries in the region are adopting alert systems based on Cell Broadcast, a technology that allows mass messaging to be sent to all mobile devices in a specific area, without the need for applications or an internet connection,” explains Jonathan Ramos, Cybersecurity Researcher at ESET Latin America.
Some implementation examples in the region include:
- Chile is the most established case, with its Emergency Alert System (SAE) fully operational and regularly used in the event of natural disasters, while Brazil already has large-scale mobile alert infrastructure, as evidenced in this incident.
- Mexico has conducted trials in recent years, partially integrating Cell Broadcast into its seismic alert system. Other countries, such as Ecuador, are in the initial or pilot stages.
- Argentina is making progress in deploying its national AlertAR system, based on this technology.
A compromised alert system can generate panic, misinformation, and diminish the credibility of official emergency communications
“As governments adopt more efficient technologies to alert the population, the attack surface on critical systems also increases. A compromised alert system can generate panic, misinformation, and eventually diminish the credibility of official communications in real emergency situations,” highlights Ramos from ESET.
One detail that stood out in this case was the repetition of the word “misanthropy” in various messages, functioning as a kind of signature left by those responsible. The term is used to describe people who express aversion, distrust, or rejection of humanity and social coexistence.
The case is being investigated by the National Civil Defense in conjunction with the National Telecommunications Agency (Anatel). The suspicion is that the incident involved unauthorized access to the Public Alert Dissemination Interface (Idap), a platform used by the Ministry of Integration and Regional Development (MIDR), with the support of the National Civil Defense, to send alerts related to risks of natural disasters and other emergencies.

In the first hours after the incident, a user identified as “Misantropo” on the social network X posted images and a video claiming responsibility for the messages. The disseminated material suggests the use of a government platform to send the alerts.
In an interview with the TecMundo website, the alleged attacker claimed to have used old Idap credentials that had been exposed in previous leaks. According to his account, access was obtained through a technique known as credential stuffing, which involves the automated reuse of username and password combinations previously compromised in other incidents.
“Although the perpetrators and details of the intrusion are still under investigation, the incident reinforces the importance of adopting robust authentication mechanisms, continuous monitoring, and periodic credential reviews in systems considered critical to public safety,” ESET added.
The authorities responded by temporarily deactivating the platform. In an official statement, the Civil Defense of the state of São Paulo reported that the message received by the public was not issued by the agency and that it immediately initiated verification procedures together with the National Civil Defense, Anatel (the Brazilian telecommunications regulator), and other institutions involved in the system’s operation. “To date, there is no record of any event that would justify issuing an extreme alert related to the reported content,” the agency stated.
“The incident highlights the risks associated with protecting government systems responsible for essential services. Cyber incidents on critical infrastructure platforms expose vulnerabilities that transcend the technological sphere, revealing flaws in security policies and procedures. The use of supposedly leaked credentials reinforces the urgency of governance practices, such as the application of the principle of least privilege, mandatory multi-factor authentication (MFA), and the periodic rotation of passwords. For systems with high social impact, the implementation of the Four-Eyes Principle is indispensable. This validation layer mitigates the risk of isolated actions, whether malicious or accidental, preventing false alerts from generating panic and misinformation, and above all, preserving public trust in legitimate state protection mechanisms,” concludes Jonathan Ramos of ESET.
The investigation should clarify whether there was indeed an intrusion into the Civil Defense systems or if the incident was caused by the misuse of valid credentials obtained from previous leaks.
ESET invites you to learn more about cybersecurity by visiting: https://www.welivesecurity.com/es/.
For other useful preventative information, also available in Venezuela at: https://www.eset.com/ve/,, and on their social media channels @eset_ve. Also on Instagram (@esetla) and Facebook (ESET).
With information and images provided by ESET and Comstat Rowland
Follow our news on Google! For current, interesting, and accurate information, click here to see all the content on Bitfinance.news. You can also find us on X/Twitter and Instagram
