Hackers breach Sismate and launch false alert of 8.7 earthquake and tsunami in Peru
Peru's official early-warning alert system was hacked, sending false messages of earthquake and tsunami to thousands of mobile phones. The Transport Ministry attributed the breach to Everbridge Consortium.

Sismate hack generates panic with false earthquake and tsunami alert
Thousands of Peruvians received an unexpected alarm on their mobile phones on the night of Wednesday, 20 May, issued through Sismate, the Peruvian state's official early-warning alert system. The message warned of an alleged earthquake of magnitude 8.7 off the central coast of the country and an "imminent danger of tsunami" along the entire coastline. The situation generated fear and confusion in different regions, according to infobae.com.
The first message, attributed to the Emergency Early Warning Messaging System (Sismate), stated: "Large-magnitude earthquake 8.7 off the central coast of Peru", and urged citizens to evacuate immediately to high areas and away from the sea and rivers. At the end of the text appeared an external link purportedly linked to a Telegram channel, something unusual in this type of official communication.
Political messages and mentions of Curwen
Minutes later, a second alert arrived that was even more unusual. The text, dated 20 May 2026 at 7:53 p.m., began with the phrase: "HELLO PERUVIANS, DEFACEPERU SPEAKING TO YOU". The message included references to "electoral fraud" and directly mentioned Curwen, a popular Peruvian streamer and content creator.
The mass distribution of that second notice ultimately confirmed the Sismate hack. Numerous users questioned how a message with political content could be distributed through a tool designed exclusively for emergencies. The impact was immediate: Sismate automatically interrupts the screen of mobile phones with sound and vibration, without requiring internet or phone credit, thanks to Cell Broadcast technology.
The Transport Ministry confirms unauthorised access
The Ministry of Transport and Communications (MTC) reported that Sismate suffered unauthorised access on Monday, 20 May, between 7 and 8 p.m., which allowed unknown agents to send mass messages to mobile phones across the country. According to the ministry's statement, the breach occurred through an account of the system's provider, Everbridge Consortium, from which the false earthquake and tsunami alerts were issued.
After detecting the breach, Everbridge Consortium applied security measures to identify the origin of the incident and determine its scope. The MTC implemented control, containment and review actions to clarify what occurred and strengthen cybersecurity of the national alert system. The ministry also initiated procedures to assign responsibility and identify the access routes used to breach the mass-distribution channels.
In its statement, the MTC urged the public to "remain calm and stay informed solely through official institutional channels", and warned about the circulation of misleading messages in messaging applications. Both the Ministry of Transport and Communications and the National Institute for Civil Defence (Indeci) were preparing an official statement on what occurred.
The incident took place in the context of the Peruvian electoral process, days before the second round of the presidential run-off on 7 June, although the ministry did not establish any link between the two events in its statement.
Who is "Deface Peru"
The name "Deface Peru" is not new in the Peruvian digital sphere. It is a collective of hackers linked to hacktivism activities and cyber-attacks against public entities and state platforms. The group operates primarily through Telegram and in recent months has been associated with document leaks and breaches of government portals.
Among the most well-known cases attributed to the collective is the attack on the website of the Municipality of Arequipa in May 2025, where they distributed messages against municipal management and leaked internal files. Subsequently, they were also identified as having intervened in sites linked to the Colombian Government during the diplomatic conflict over Santa Rosa island.
In September 2025, the group distributed documents related to the Intelligence Directorate of Peru's National Police and published information about officers deployed to social protests. The collective was also linked to attacks against state platforms such as the official journal El Peruano.
Questions about the security of the alert system
To date, the authorities have not detailed precisely how the hack occurred or how many users received the false alerts. The fact that the second message directly mentioned "Deface Peru" increased attention on the group's capabilities and on the security of the state's digital platforms.
The case raises questions about the protection of Sismate, a tool implemented by the MTC and operated by Indeci to warn the population about imminent risks such as tsunamis, landslides, flooding or large-scale seismic events. Its main characteristic—the ability to automatically interrupt mobile devices without requiring internet connection—is also what amplifies the impact of any misuse of the system.
Source: Google News PE — Crime