INVESTIGATIONS INTO FALSE CIVIL DEFENSE ALERT ADVANCE
Whoever was woken up by the emergency siren on Friday night (19) is still waiting for answers to two central questions: who sent the messages and how did they manage to access the platform?
Until the most recent official update, published on Sunday (21), the Federal Police were investigating the incident with the collaboration of the National Secretariat for Civil Protection and Defense. The government informed that the details will be released at the end of the work, so as not to compromise the investigation. For now, there is no publicly confirmed authorship.
The Civil Defense Alert has already started working again, but under a restricted regime. Only the National Risk and Disaster Management Center, Cenad, can operate the tool. State access remains suspended and, if a real alert is necessary, local Civil Defenses must request it to be sent to the national center. There is no deadline for full resumption.
Investigation seeks origin and method of accessThe investigation attempts to identify the origin of the action and the path used to access the Public Alert Disclosure Interface, known as IDAP. It is through this platform that authorized bodies prepare and send emergency messages.
As an immediate reaction, all external access to the interface was blocked, the accounts involved in the episode were suspended and access records were preserved for forensic examination. The Government Cyber Incident Prevention, Treatment and Response Center was also notified. According to the Ministry of Integration and Regional Development, there is, to date, no evidence of structural damage to the national alert system.
The ministry states that it has not yet confirmed hypotheses about the authorship or dynamics of the cyber incident. This means that versions about leaked passwords, specific credentials or the participation of a person or group remain outside the officially proven framework.
What has already been confirmedThe initial technical survey identified ten unauthorized shipments between 11:41 pm on Friday and 1:23 am on Saturday. Nine used Cell Broadcast technology and were classified as "extreme". The tenth was sent by SMS.
There were official reports in São Paulo, Mato Grosso do Sul, Rio de Janeiro, Paraná and the Federal District. At 1:30 am, a few minutes after the last identified shipment, the platform was taken offline preventively.
One of the confirmed messages contained only the word "misanthropy", a term associated with aversion or contempt for humanity. The text did not present any information about the disaster, risk area or protection measure.
It is not yet known how many devices received the warnings or all the cities affected. MIDR itself states that the irregular behavior of the shots prevents, for now, a safe calculation of the range. Therefore, estimates of tens of millions of cell phones and broader numbers of affected states are not officially confirmed.
What is extreme alert for? Cell Broadcast sends a message simultaneously to cell phones connected to antennas in a specific geographic area. There is no need to know each phone number, register, install an app or share personal location data. The message can reach a large region or a very small area, depending on the emergency.
In Brazil, the system is free and works on compatible devices connected to 4G or 5G networks, without depending on a data package or Wi-Fi. The extreme alert is reserved for situations of serious and immediate risk to life or property. Therefore, it produces its own sound even when the device is in silent mode and keeps the message highlighted until the user closes it.
The technology is adopted internationally because it can transmit directions to all compatible cell phones in an area within a few seconds, including during network congestion. The World Meteorological Organization highlights, however, that an efficient warning needs to be fast, accurate, reliable and provide clear guidance on what the population should do.
Trust is also part of safety. False triggering does not make the tool unnecessary. Early warning systems are used precisely because a few minutes' notice can make a difference in floods, landslides, dam breaks and other emergencies.
The episode, however, shows that technological reach without access control can turn into an equally broad problem. The International Telecommunications Union recommends secure connections, encryption, barriers against external access, permissions defined by role, real-time monitoring, frequent audits, penetration tests and complete recording of all attempts to enter the system.
The investigation still needs to clarify how access occurred, what permissions were used, what the real range of the shots was and what changes will be adopted before full reopening.
An emergency alert needs to be rare, targeted and, above all, clear. Because when a siren reserved for extreme risk rings, the public needs to trust that there is a real danger - and know immediately how to act.
Source: Antena 1