An 'extreme' emergency alert reading misantropi4 briefly flashed across phones in Paraná, São Paulo and Rio de Janeiro, forcing Brazil to take its national warning system offline. The National Protection and Civil Defense Secretariat said the platform was disabled at about 1:30 a.m. local time while investigators probe a probable hacking incident. Local civil defence offices in the affected states denied issuing the warning, and there have been no reports of any real-world emergency tied to the alert. The Secretariat said it will hand over data to the Federal Police and only restore the system once security conditions are reestablished.
Officials cut the notification service after an 'extreme' warning containing the alphanumeric string misantropi4 was pushed to phones, the National Protection and Civil Defense Secretariat said, and they traced the cause to a probable hacker attack on the system.
The alert first appeared in early reports from the southern state of Paraná, and later affected users in Brazil's largest states, São Paulo and Rio de Janeiro, the agency said. The message was flagged as an extreme alert by the platform and used the spelling misantropi4, a leetspeak variant of the Portuguese word misantropia, which translates to misanthropy in English. After the false alert was sent, the Secretariat said it disabled the countrywide notification tool while security checks and an investigation take place.
Authorities said cellbroadcast alerts reached devices in the targeted areas. Cellbroadcast is the system that pushes location-targeted emergency messages directly to mobile devices regardless of phone number or carrier, similar to the United States Wireless Emergency Alerts used for AMBER notices and other urgent public-safety messages.
Local civil defence offices rushed to distance themselves from the notification. São Paulo Civil Defense issued a statement saying it had not issued the alert and that it had contacted other institutions involved in the system's operation to investigate. Rio de Janeiro Civil Defense attributed the incident to instability in the alert-sending system managed by the National Civil Defense. Paraná's state government likewise said its Civil Defense didn't trigger the message and that no severe events were forecast for Curitiba.
Investigation and next steps
The National Protection and Civil Defense Secretariat said federal law enforcement will take charge of the technical probe and that it will hand over the unauthorized alert and related data to the Federal Police. Officials haven't named any suspects and provided no technical details about the vector of the intrusion, only saying the incident appears to be the result of a probable hacker attack. Reuters reported the system was taken offline at around 1:30 a.m. local time and that the government intends to restore the notification service as soon as possible.
So far there are no reports of any real-world event that would justify issuing an extreme alert. Civil defence offices in the affected states reiterated that no incident requiring emergency notification occurred, and public statements have been limited to agency releases. The Secretariat said the warning service will only come back online once security conditions are reestablished and the necessary checks are complete.
The episode shows a practical vulnerability in automatic emergency messaging systems: when the mechanism that allows authorities to reach millions of people quickly is compromised, the immediate response can be to cut the service entirely to prevent further unauthorised messages. That step protects the integrity of future alerts, but it also means legitimate warnings can't be sent until officials are confident the system is secure.
For now the immediate priorities listed by authorities are technical analysis, coordination with telecommunications regulators and other institutions involved in the platform's operation, and a formal transfer of investigative material to the Federal Police. The Secretariat said it will restore the tool once investigators complete security checks and officials are satisfied that the system can't be manipulated again.
Related Articles
- AusAlert trial sounds sirens, exposes patchy delivery in regional towns
- OpenAI loses senior enterprise sales lead as Barret Zoph departs
- Data centre boom: A$300bn reshapes NSW and Victoria
The next formal step is the transfer of the incident file and the alert data to the Federal Police, after which authorities said they will only restore the notification platform once security checks are completed. Originally reported by CNN.
This article was created with AI assistance.