---
title: "Cyberattack on Brazil: Hackers Breach Emergency Alert System to Broadcast Misanthropy"
description: "🇧🇷 Hackers breached Brazil's emergency alert system! On the morning of June 20, residents received a mass notification with the text \"misantropi4\". Authorities shut down the system and launched an investigation, considering theories of data leaks and insider actions. 📱🚫"
date: 2026-06-28T00:01:47.000Z
lang: en
url: https://xab.info/en/posts/cyberattack-on-brazil-hackers-breach-emergency-alert-system-misantropi4
tags: []
publisher: "XAB.info"
---

# Cyberattack on Brazil: Hackers Breach Emergency Alert System to Broadcast Misanthropy

![Brazilian operations center: staff analyzes data on screens following cyberattack on emergency alert system](https://xab.info/media/2026/06/28/kiberataka-na-braziliyu-vzлом-sistemy-opoveshcheniy-misantropi4/kiberataka-na-braziliyu-vzлом-sistemy-opoveshcheniy-misantropi4-1.webp)

On the morning of June 20, 2026, an event occurred in Brazil that threatened public trust in state security systems. Simultaneously across the country, citizens' mobile phones rang with a loud system notification containing the text "misantropi4". The incident led to a complete shutdown of the national emergency alert platform.

The Brazilian Ministry of Communications, the National Civil Defense Agency, and the Federal Police immediately initiated a large-scale investigation. Authorities confirmed the fact of unauthorized access to state infrastructure used to warn the population about natural disasters and catastrophes.

### Attack Technology: How Cell Broadcast Was Hacked

According to the Information Security Department of the Federal Network Regulation Agency (Anatel), the perpetrators used the Cell Broadcast protocol. This is a cellular broadcasting technology with unique characteristics: messages are transmitted directly to devices, ignoring "silent mode" settings and notification blocking. Usually, this channel is used exclusively for critical emergency warnings.

It was precisely this feature that made the attack so resonant — the message broke through to the screens of millions of smartphones with high volume, causing panic and bewilderment. The chronology of events, reconstructed from system logs, is as follows:

    - **08:14** — Generation of an unauthorized data packet was recorded. Automatic gateway verification systems reacted to the anomaly.

    - **08:17** — Mass delivery of the "misantropi4" message to user devices. Monitoring of the load on cellular towers began.

    - **08:35** — Localization of the compromised node. For security reasons, the decision was made to completely disconnect the alert platform servers.

### Motives and Investigation Theories

The content of the encrypted message became the subject of close attention by experts. The text used a word that is a distorted version of the Portuguese term *misantropia* (misanthropy — hatred or alienation towards humanity), where the last letter was replaced with the digit "4".

At the moment, no financial or political demands from the hackers have been recorded. Investigative bodies are considering two main versions of what happened:

    - **External Intrusion:** Exploitation of a vulnerability in the software of a third-party contractor responsible for server technical support.

    - **Internal Compromise:** Unauthorized use of legitimate administrative accounts by an insider.

### Government Response and Legal Consequences

Representatives of the Ministry of Communications assured the public that the core of the civil defense database remained protected. The incident affected only the broadcast transmission interface (Broadcast Gateway). Nevertheless, the head of the department announced the creation of an interdepartmental cybersecurity commission to conduct a full audit of the network architecture.

Simultaneously, official requests were sent to the largest mobile operators — Vivo, Claro, and TIM — demanding the provision of data packet transmission logs at the base station level to accurately determine the source of the attack.

The National Civil Defense Agency issued a press release calling on citizens to remain calm. Until the system is restored, the population was asked to rely on alternative verified channels: official social media of the departments and state radio broadcasting.

The government's legal department classified the incident as a criminal offense. The organizers of the attack may be held accountable under articles of the Brazilian Penal Code regulating crimes against the security of public services. The Cybersecurity Law (known as the Dilma Rousseff / Carolina Dieckmann Law) in the version with amendments from 2021–2025 is being applied, which provides for long prison sentences.

According to the regulations of the International Telecommunication Union (ITU), emergency alert systems belong to Tier 1 critical information infrastructure. Consequently, the fact of violation of their integrity requires mandatory notification of international cyber threat response centers (CERT).