Station Compliance›Field Notes
EAS Security
Rules do not appear from nowhere. This one has a footnote trail, and reading it tells you more about your actual exposure than the rule text does.
By Mark Shannon ·
When the FCC adopted § 11.35(d) it did not argue from principle. It argued from a list of things that actually happened, and it put that list in the footnotes.
That list is worth reading, for a reason that has nothing to do with regulatory history: every entry on it is the same attack. Not a sophisticated intrusion, not a targeted campaign against a specific broadcaster — an internet-facing box with a weak or absent password, found by scanning, and used to put audio on a transmitter. If your station has one of those, you are not a hypothetical.
From paragraph 16 of the order:
The cybersecurity requirements we adopt today are narrowly tailored to address vulnerabilities that have been repeatedly exploited through a series of cyberattacks on EAS Participants in recent months. In these attacks, bad actors gained control of radio broadcasters' systems by exploiting improperly secured, remotely accessible equipment in the broadcast signal processing system to transmit unauthorized audio that included EAS alert tones, an offensive song that included racial slurs, and promotional content.
Three things in that sentence are worth pulling out. The equipment was "improperly secured" and "remotely accessible" — those are the two conditions, and both are things a station controls. The audio included EAS alert tones, which is why this became an EAS rulemaking rather than a general broadcast security one. And it happened repeatedly, in recent months, not once in 2013.
The order's footnotes cite these directly.
Autumn 2025 — a wave of Barix hijackings. The Commission cites trade coverage of apparent Barix hacks from September 2025, noting this was "not the first time hijackers have attacked Barix boxes to stream explicit content." Barix Instreamer and Exstreamer units are common in small-market STL paths, and in default configuration they have no password protection at all — which is a different and worse problem than a weak password.
November 2025 — ESPN 97.5 in Houston. Cited to RadioInsight, November 23, 2025, as a Barix hack.
November 2025 — an NPR affiliate in the Richmond area. Cited to WRIC, November 21, 2025: a backup audio signal was hijacked and offensive material was broadcast.
Jefferson County, Washington — false alerts to cable subscribers. Cited to the Peninsula Daily News and KOMO: a false "radiological hazard" alert reached cable subscribers through EAS equipment connected to the internet.
February 2013 — the zombie hoax. The one everybody remembers. Hoax broadcasts about a zombie attack, linked across multiple stations, cited to USA Today. The FCC includes it to make a point about duration: this has been the same failure mode for more than a decade.
2016 — the manufacturer's own warning. The order cites Radio World coverage noting that Barix had instructed customers to set new passwords and ensure devices were behind firewalls, in response to incidents where attackers hijacked broadcast audio streams and transmitted sexually explicit content.
Notice what is absent from that list: any attack that required unusual skill, insider access, or a zero-day. Every documented case runs through a management interface that was reachable from the internet and protected by a default, absent, or guessable credential.
The Commission also documented, pointedly, how much notice the industry had. Its own count:
| When | What |
|---|---|
| April 2020 | Email to EAS Participants urging installation of current security patches |
| August 2022 | Public Notice recommending basic security steps |
| November 23, 2025 | Public Notice DA 25-996, after the autumn attacks |
| May 14, 2026 | A cybersecurity workshop for broadcasters, convened by the Bureau |
And then the sentence that explains why there is now a rule instead of a fourth Public Notice:
Despite our repeated efforts urging EAS Participants to take basic steps to secure their networks... successful attacks have continued into 2026.
That is the whole regulatory logic. Voluntary guidance was tried, four times, over six years, and the attacks did not stop.
The November 2025 Public Notice is worth knowing about because it is effectively a preview of the rule. It urged broadcasters to:
Compare that to the three things § 11.35(d) now requires and the shape is identical. The rule is the Public Notice with the "reasonably feasible" removed.
The useful conclusion is not "be afraid." It is that the threat model here is narrow and legible, which makes it tractable.
The attacks in the FCC's record did not find stations because those stations were interesting. They found them because a scan found an open management port. That means the defence is equally unglamorous, and it is the same defence in every case:
The stations in the FCC's footnotes were not negligent in some exotic way. They had a box on the internet that they had stopped thinking about. That is the entire vulnerability, and it is why a rule this narrow was considered sufficient.
The equipment guide covers which devices are in scope and what the common defaults are, including Barix and Comrex specifically.
Everything on this site is free to read. The Program Chain Compliance Kit is the implementation version — the device-by-device reference, the network patterns for a one-rack station, and the worksheets that leave a paper trail behind the work.
The rules on this site change without warning — a deadline gets waived, a filing window opens, a Public Notice lands on a Friday. Leave an address and you get an email when something changes that affects a small station. Nothing else, and one click to leave.