FCC Issues Cybersecurity Public Notice After Broadcast Hacks in Texas and Other States
posted on 12.01.2025The FCC’s Public Safety and Homeland Security Bureau issued a Nov. 26 Public Notice reminding broadcasters of their responsibility to ensure the security of their broadcast networks and systems. The notice cited published reports of station hacks in Houston and Richmond, Virginia.
The commission said “bad actors have targeted poorly secured air-chain equipment including Studio Transmitter Links (STL), resulting in unauthorized access to radio station infrastructure and the broadcast of EAS tones combined with offensive audio content to the public over the air. These attacks can compromise trust in EAS and pose a risk to public safety.”
A Houston FM station’s studio-transmitter link (STL) was compromised on Nov. 23. The FCC said, “threat actors” accessed “improperly secured Barix equipment” and reconfigured it to “receive attacker-controlled audio in lieu of station programming.”
Stations in other states were subjected to inserted audio of “an actual or simulated Attention Signal and EAS alert tones,” as well as profanity.
The FCC is urging all broadcasters, especially those using Barix equipment, to:
- Install software security patches issued by the equipment manufacturer as soon as they become available, and upgrade equipment firmware and software to the most recent versions recommended by the manufacturer.
- Change their devices’ default passwords and replace them with robust alternatives and regularly change passwords to promote continued security.
- Where reasonably feasible, install EAS, Barix, and other equipment interconnected to the broadcast signal processing system behind network firewalls, and utilize VPNs that are configured to limit remote management access to only authorized devices.
- Continually monitor EAS equipment and software and review audit logs to detect and report incidents of unauthorized access.
- Review the list of recommended best practices to address potential data security vulnerabilities issued by the Communications Security, Reliability, and Interoperability Council in 2014.
The commission also encourages broadcasters to contact their EAS equipment manufacturers with any specific questions regarding the security of EAS equipment, especially if a station suspects broadcast equipment has been subject to attempts at unauthorized access.
Broadcasters who suspect unlawful access to their systems also should notify the FCC Operations Center at 202-418-1122 or FCCOPCenter@fcc.gov and report any cyberattacks to Federal Bureau of Investigation’s Internet Crime Complaint Center (IC3) at https://www.ic3.gov/.
Questions? Contact TAB’s Michael Schneider or call (512) 322-9944.
« Back to Latest News