Particle.news
Download on the App Store

False Civil‑Defense Alerts Reach Millions and Reveal Widespread Federal Cybersecurity Gaps

Polícia Federal has opened a probe after accounts linked to Pará were used to send extreme-level messages that investigators say were enabled by leaked credentials and weak access controls.

Overview

  • Over the weekend of June 20–21, the federal alert platform IDAP sent at least ten false extreme‑level messages containing the word “misantropia” to millions of cellphones across seven states and the Federal District.
  • A Ministry document and police inquiries show two Defesa Civil–Pará accounts were used to fire the messages, and investigators have identified one account as belonging to a former Pará military firefighter.
  • The government temporarily deactivated the IDAP system and ordered password changes in affected states while the Federal Police’s cybercrimes unit probes whether credentials were traded on the deep web or hacker forums.
  • CTIR.Gov data through May 31 show 6,774 reported incidents this year (about 45 per day), with most attacks relying on social engineering or abusive content rather than technical intrusions, underscoring that human and process weaknesses are the main risk vectors.
  • Security experts and officials are urging immediate fixes such as mandatory multi‑factor authentication, regular credential rotation, territorial access limits, and dual authorization for public alerts, while critics point to a 2024 TCU audit that found broad shortfalls across federal bodies.