Brazilian authorities are investigating a suspected cyberattack on the national Civil Defense alert network after unauthorized "extreme" emergency warnings were pushed to mobile phones across multiple regions. The false alerts, which included the word misanthropy/misantropi4, triggered loud alarm tones even on devices set to silent mode. Officials said at least 10 unauthorized messages were sent, including nine via cell broadcast and one by SMS, and confirmed there was no real public safety threat tied to the warning.
In response, Defesa Civil Nacional took its dispatch platform offline after detecting the breach, while authorities blocked external access to the Public Alert Dissemination Interface and launched a joint investigation involving the Federal Police and telecom regulator Anatel. Officials said the alerts were remotely triggered by someone outside the National System of Protection and Civil Defense, but added there is no evidence of structural damage to the core infrastructure. Brazil said the affected platform will be relaunched after security improvements, and a more secure replacement system was already under development.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
Reporting cited vx-underground as attributing the fake Brazil emergency alerts to an individual using the name “mizanthropiaz.” The report also alleged the attacker exploited weak security controls and credentials exposed by infostealer malware on a government employee’s computer in 2016.
Authorities said the affected emergency alert platform was being restored after security checks following the suspected compromise. Officials also reported that a more secure dispatch system was being developed.
Brazilian authorities, including the Federal Police, began investigating suspected unauthorized remote access to the national emergency alert system. Officials said the alerts were triggered by someone outside the national civil defense network and stated there was no public safety threat or evidence of structural damage to core infrastructure.
Defesa Civil Nacional said it took its dispatch platform offline at 01:30 after detecting the breach. Authorities also blocked external access to the Public Alert Dissemination Interface while responding to the incident.
On June 20, unauthorized high-priority alerts were broadcast to mobile devices across multiple Brazilian regions through the Civil Defense alert system. Authorities said at least 10 false alerts were sent, including nine via cell broadcast and one via SMS, and the messages included the word "misanthropy."
The first fraudulent emergency alert in the Brazil Civil Defence system was reportedly issued in Paraná at about 23:40 on June 19, preceding the wider wave of false alerts sent across multiple regions. The message formed part of the same compromise that later broadcast 'misanthropy' alerts via cell broadcast and SMS.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
7 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcehackread.com
Open sourcescworld.com
Open sourcetherecord.media
Open sourcetheregister.com
Open sourcemalware.news
Open sourcebitdefender.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.