FCC mandates cybersecurity measures for U.S. emergency alert distributors
The U.S. Federal Communications Commission (FCC) on Thursday approved a set of basic cybersecurity rules for companies that issue emergency alerts. The order, adopted unanimously by three commissioners, mandates that Emergency Alerting System (EAS) operators—such as radio stations, broadcast TV networks, and cable systems—use strong passwords, deploy network firewalls, and promptly apply security patches. The FCC stated the requirements aim to protect EAS from hijacking and preserve public trust. The move follows past incidents, including a 2013 zombie-apocalypse hoax and a 2022 critical vulnerability warning. The FCC also plans further security rules for EAS and Wireless Emergency Alerts (WEA) systems.

The U.S. Federal Communications Commission (FCC) on Thursday approved a set of baseline cybersecurity rules for entities that distribute emergency alerts across the nation. The decision, adopted unanimously by the agency's three commissioners, mandates that operators of the Emergency Alerting System (EAS)—including radio stations, broadcast television networks, and cable systems—implement strong passwords, deploy network firewalls, and promptly apply security patches to their systems.
In an official statement, the commission said the new requirements are designed to protect EAS infrastructure from “hijacking by cybercriminals and our nation’s adversaries,” thereby helping to “preserve the public’s trust in EAS.” The order was released as a public document (DOC-422584A1) on the FCC's website.
EAS has long been a target for cyberattacks. In 2013, hackers commandeered EAS systems at five stations, interrupting local TV broadcasts with fake warnings of a zombie uprising. Investigators later determined that some of the compromised devices were using default passwords that were publicly listed in user manuals. That incident was widely reported at the time by outlets including Dark Reading and Ars Technica.
More recently, in 2022, the FCC and the Federal Emergency Management Agency (FEMA) issued warnings to EAS operators about a critical vulnerability in their equipment, urging them to fix the flaw and take additional steps to secure their systems. The FCC noted that it had previously alerted operators to the issue, which gained renewed attention after a security researcher discussed it at the 2022 DEF CON hacker conference. The FCC's 2022 advisory was published as DA-22-828A1.
More alert security measures on the horizon
The FCC is also planning additional security requirements for EAS operators and for participants in the Wireless Emergency Alerts (WEA) system, which enables government officials to send public-safety messages to smartphones through partnerships with wireless carriers.
A new Further Notice of Proposed Rulemaking would require EAS operators to authenticate alerts before transmitting them and to eliminate what the FCC described as “outdated WEA geotargeting exceptions” that sometimes result in people receiving alerts for the wrong areas. The proposed rule would also require EAS and WEA operators to include standardized symbols in their alerts to help the public better understand the nature of an emergency.