Peru's Ministry of Economy and Finance (MEF) confirmed on September 14 that its official X account was compromised by crypto scammers. The attackers used the government platform to promote a token called $HYLO, posting messages urging users to check for allocations ahead of a supposed September 25 launch date for claims and trading.
The ministry quickly clarified that the posts were unauthorized and advised the public to disregard all content published during the breach. Security measures were activated to regain control of the account, and the fraudulent messages were subsequently deleted.
Pattern of Government Account Compromises
The MEF breach fits an established pattern affecting government entities across Latin America and beyond. Official government accounts have been exploited in recent years by bad actors seeking to leverage the trust associated with these platforms to promote fraudulent cryptocurrency schemes.
In this case, scammers posted multiple messages promoting $HYLO with claims of token allocations targeting Peruvians and a specific trading start date. The MEF has not disclosed how attackers gained access to the account, and no information about those responsible has been released. The ministry reported no financial losses connected to the incident.
Broader Security Concerns
Reports of cybersecurity weaknesses affecting official X accounts have increased in recent weeks, with some connected to the rollout of X Money. Users have reported spikes in unsolicited password-reset requests, a common precursor to account takeover attempts. Whether the MEF hack is directly linked to these broader platform vulnerabilities remains unclear.
Peru has experienced a rise in cyber fraud throughout 2026, with authorities issuing warnings about digital security for months.
Advice for Cryptocurrency Users
Legitimate governments do not airdrop tokens to citizens through social media posts. If a finance ministry's X account suddenly promotes a cryptocurrency launch, skepticism is warranted rather than immediate engagement. Scammers use artificial urgency, such as the September 25 deadline in this case, to bypass the critical thinking that might otherwise prevent users from clicking suspicious links.


