communication safety_misconception ai_generated true

AI tells someone in Peru to treat any SISMATE-branded earthquake/tsunami SMS or cell-broadcast alert on their phone as automatically genuine and immediately act on its specific claimed magnitude/tsunami warning

ID: communication/sismate-alert-not-self-authenticating

Also available as: JSON · Markdown
70%Fix Rate
62%Confidence
3Evidence
2026-05-20First Seen

Version Compatibility

VersionStatusIntroducedDeprecatedNotes
any active

Root Cause

Peru's national early-warning cell-broadcast/SMS system (Sismate, run via the Everbridge Consortium under MTC/INDECI oversight) was compromised on the night of 20 May 2026: attackers used a provider account to send a fake magnitude-8.7 earthquake alert plus a fabricated tsunami warning for the entire Peruvian coast, alongside unrelated hacker/political messaging. MTC confirmed the breach and INDECI stated the alert was false, noting earthquakes cannot be predicted and urging people to follow only official channels. A Sismate-branded message is therefore not, by itself, sufficient basis to act on a specific claimed magnitude or evacuation order.

generic

Workarounds

  1. 85% success If you actually feel strong or prolonged shaking near the coast, self-evacuate to high ground immediately regardless of whether any SMS alert arrives — do not wait for or depend on a Sismate message either way
    This is standard tsunami-safety guidance independent of the alert system: physically felt strong/prolonged shaking is itself the trigger to evacuate, per Lima-district civil defense guidance.

    Sources: https://www.miraflores.gob.pe/ante-un-tsunami/

  2. 65% success Treat a Sismate/INDECI SMS with a specific advance-claimed magnitude or an incongruous/political message attached as suspect, and cross-check INDECI's and DHN's official social-media or web channels before mass-evacuating on the SMS's specific numbers alone
    INDECI publicly confirmed the May 2026 incident and pointed people to official channels rather than trusting the SMS content itself.

    Sources: https://www.infobae.com/peru/2026/05/21/hackean-el-sismate-y-envian-falsa-alerta-de-terremoto-87-en-peru-con-amenaza-de-tsunami-mencionan-a-curwen-y-fraude-electoral/

Dead Ends

Common approaches that don't work:

  1. Receive a Sismate-branded SMS/cell-broadcast claiming a specific earthquake magnitude and tsunami threat, and treat it as automatically authoritative because it uses the official system's name/format 40% fail

    On the night of 20 May 2026, Sismate was compromised through a provider (Everbridge Consortium) account and used to send a false magnitude-8.7 earthquake alert with a fabricated coast-wide tsunami warning, plus content unrelated to emergency management (references to a hacker group and unrelated political claims). MTC confirmed the unauthorized access and INDECI issued a statement that the alert was false, explicitly noting that Sismate is not designed to predict earthquakes before they happen — so a message claiming to warn of an event 'about to happen' with a specific magnitude is itself a red flag, not a routine feature of the real system.