Overview
On February 11, 2013, a coordinated series of broadcast interruptions affected the Emergency Alert System (EAS) across multiple television stations in the United States. The incidents occurred simultaneously in the states of Montana, Michigan, Wisconsin, and New Mexico, disrupting local television programming with a recurring emergency message. This event represented one of the most widespread and notable hijackings of the national alert infrastructure, drawing significant attention from media outlets and emergency management officials.
The broadcast interruption featured a local area emergency message that warned viewers of "bodies of the dead" who were "attacking the living." This specific phrasing referenced themes commonly associated with a "zombie apocalypse," creating a distinct and memorable disruption for audiences tuning into local news and network programming. The message was designed to mimic the standard format of an EAS alert, utilizing the familiar audio tones and visual crawls that signal an immediate threat to the local population.
Local authorities in the affected states subsequently declared the message to be a hoax. Investigations pointed to hackers gaining unauthorized access to the Emergency Alert System equipment at various television stations. The technical vulnerability allowed external operators to inject the custom message into the broadcast feed, effectively overriding the standard programming with the emergency alert. This method of intrusion highlighted potential security gaps in the digital transition of the EAS infrastructure at the time.
The simultaneous nature of the hijackings across four different states suggested a coordinated effort rather than isolated technical failures. The geographic spread—covering regions from the Mountain West to the Midwest and the Southwest—indicated that the hackers had targeted multiple entry points within the EAS network. This event served as a case study for emergency management agencies regarding the resilience of broadcast infrastructure against digital intrusions.
Chronology of the February 11, 2013 hijackings
On February 11, 2013, a coordinated series of Emergency Alert System (EAS) hijackings disrupted television broadcasts across five U.S. states. The incidents involved stations in Montana, Michigan, Wisconsin, and New Mexico. In each case, the EAS equipment was accessed by hackers, interrupting local programming with a recurring audio-visual message. The alert warned viewers that "bodies of the dead" were "attacking the living." Local authorities subsequently declared the alerts to be a hoax.
Station-specific timeline
The following table details the five confirmed station hijackings on February 11, 2013. The timing and location data are derived from the reported events across the affected states.
| Station | Location | State | Event Description |
|---|---|---|---|
| KRTV | Great Falls | Montana | EAS alert interrupted broadcast with "bodies of the dead" message. |
| WKBT-DT | La Crosse | Wisconsin | EAS alert interrupted broadcast with "bodies of the dead" message. |
| WBUP | Traverse City | Michigan | EAS alert interrupted broadcast with "bodies of the dead" message. |
| WNMU | Marquette | Michigan | EAS alert interrupted broadcast with "bodies of the dead" message. |
| KENW | Albuquerque | New Mexico | EAS alert interrupted broadcast with "bodies of the dead" message. |
The simultaneous nature of these alerts across multiple states suggested a coordinated effort. Hackers gained access to the EAS equipment at each station, triggering the local area emergency messages. The consistent content of the alerts — specifically the warning about "bodies of the dead" attacking the living — linked the five incidents. Local authorities in each state investigated the alerts and confirmed them as a hoax. The incidents highlighted vulnerabilities in the EAS infrastructure, where physical or digital access to station equipment could trigger widespread public alerts.
How did the hackers bypass EAS security?
The technical vulnerabilities exploited during the February 11, 2013, Emergency Alert System (EAS) hijackings primarily stemmed from inadequate authentication protocols and reliance on default credentials across various television stations in Montana, Michigan, Wisconsin, and New Mexico. According to reports from CBS, ABC, and PBS engineers, many of the affected broadcast facilities had not updated the security settings on their EAS equipment, leaving them susceptible to remote access by hackers. These engineers noted that the EAS encoders and decoders used by the stations often utilized default passwords that had rarely been changed since installation, creating a significant point of entry for unauthorized users.
Authentication Bypass and Default Credentials
A critical flaw identified in the post-incident analysis was the widespread use of default passwords for the EAS control interfaces. In several cases, the passwords remained at their factory-set values, such as "admin" or "1234," which were easily guessed or brute-forced by the hackers. The CBS engineering team highlighted that the lack of mandatory password rotation policies contributed to the ease with which the hackers gained access to the systems. Similarly, ABC engineers pointed out that some stations had not implemented multi-factor authentication, relying solely on simple username and password combinations that were vulnerable to basic intrusion techniques.
Remote Access Vulnerabilities
The hackers were able to bypass the EAS security by exploiting the remote access features of the EAS equipment. Many of the stations used internet-connected EAS encoders that allowed for remote monitoring and control. However, the security configurations for these remote access points were often minimal, with some stations using unencrypted connections or weak encryption standards. PBS engineers reported that the hackers likely used these remote access points to inject the hoax message, which warned viewers of "bodies of the dead" attacking the living, into the broadcast stream. The ability to remotely trigger the EAS without physical presence at the station underscored the need for more robust network security measures.
Impact on Broadcast Security Protocols
The 2013 EAS hijackings exposed significant gaps in the security protocols of the Emergency Alert System, prompting a reevaluation of best practices across the broadcasting industry. The incidents highlighted the importance of regular security audits, mandatory password updates, and the implementation of stronger authentication mechanisms. In the aftermath, many stations upgraded their EAS equipment to include enhanced security features, such as digital signatures for alert messages and more secure remote access configurations. The events served as a wake-up call for the industry, emphasizing the need for continuous vigilance and adaptation to evolving technological threats.
The 2013 La Crosse relay incident
On February 13, 2013, a distinct Emergency Alert System (EAS) incident occurred in La Crosse, Wisconsin, involving radio station WIZM-FM and television station WKBT-DT. This event took place just two days after the widespread "Dead Bodies" hoax that had affected multiple states, heightening public and technical scrutiny of EAS protocols. The incident was characterized not by an external hacker injecting audio, but by a technical failure in the transmission of Specific Area Message Encoding (SAME) tones.
Technical Failure Mechanism
The root cause of the La Crosse relay incident was identified as unedited SAME tones. WIZM-FM, a local radio station, triggered the EAS on WKBT-DT, a television station, through this technical anomaly. The Emergency Alert System relies on precise digital coding to ensure that alerts are directed to the correct geographic areas and media outlets. In this instance, the SAME tones transmitted by WIZM-FM were not properly edited or verified before triggering the receiving equipment at WKBT-DT. This lack of editing caused WKBT-DT's EAS receiver to interpret the signal as a valid emergency broadcast, initiating an automatic interruption of the television feed.
Impact on Broadcast Continuity
As a result of the unedited tones, WKBT-DT's broadcast was interrupted. Viewers tuning into the television station experienced an unscheduled break in programming as the EAS activated. Unlike the previous incident involving the "bodies of the dead" message, this event was primarily a technical glitch rather than a content-based hoax. However, the timing—immediately following a major multi-state EAS hijacking—meant that the interruption drew significant attention. Local authorities and broadcast engineers had to quickly assess whether the alert contained substantive emergency information or was merely a mechanical error. The incident was subsequently declared a result of technical misconfiguration rather than malicious external hacking.
Context within the 2013 EAS Anomalies
This incident highlights the vulnerability of the EAS infrastructure to both human error and technical misconfiguration. While the February 11, 2013 events in Montana, Michigan, Wisconsin, and New Mexico were attributed to hackers gaining access to EAS equipment, the La Crosse incident demonstrated that internal procedural failures could also disrupt broadcast continuity. The involvement of WIZM-FM and WKBT-DT underscores the interconnected nature of local media markets, where radio and television stations often share or relay EAS signals. The unedited SAME tones served as a critical failure point, proving that rigorous verification of alert signals is essential to prevent false activations. This event contributed to broader discussions on EAS reliability and the need for standardized protocols to distinguish between genuine emergencies and technical artifacts.
What were the government and regulatory responses?
Following the February 11, 2013, Emergency Alert System (EAS) hijackings, federal and local authorities initiated a coordinated response to mitigate public confusion and investigate the security vulnerabilities of the broadcast infrastructure. The incidents, which affected television stations in Montana, Michigan, Wisconsin, and New Mexico, prompted immediate action from the Federal Communications Commission (FCC), the Federal Emergency Management Agency (FEMA), and local law enforcement agencies.
Federal Regulatory Actions
The Federal Communications Commission (FCC) played a central role in the regulatory response. The agency monitored the situation closely and issued guidance to broadcast stations to ensure the integrity of the EAS. The FCC emphasized the need for stations to verify the source of incoming alert signals and to maintain strict access controls over their EAS equipment. Although specific fines or decrees were not immediately announced in the initial reports, the FCC used the incident to highlight the importance of compliance with existing EAS rules and to encourage stations to review their security protocols.
The Federal Emergency Management Agency (FEMA), which oversees the national EAS, worked with the FCC to assess the impact of the hoax on the system's credibility. FEMA's response focused on ensuring that the false messages did not trigger unnecessary large-scale evacuations or resource deployments. The agency also reviewed the technical aspects of the hijackings to determine if the intrusion was a localized issue or a potential systemic vulnerability. FEMA's involvement underscored the interagency cooperation required to manage national emergency communication systems.
Local Law Enforcement Response
Local authorities were the first to respond to the public confusion caused by the "bodies of the dead" message. In Great Falls, Montana, the Great Falls Police Department issued statements to calm residents and confirmed that the alert was a hoax. The police department worked with local television stations to verify that the emergency was not an immediate physical threat. Similarly, in Wisconsin, the Randolph County Sheriff's Office responded to the alert by dispatching officers to monitor the situation and communicate with the public. These local efforts were crucial in preventing panic and ensuring that emergency services were not overwhelmed by false reports.
Security Standards and Mitigation
The hijackings highlighted significant security gaps in the EAS infrastructure. The reports indicated that hackers had gained access to the EAS equipment of various television stations, suggesting that physical and digital security measures were insufficient. In response, the FCC and FEMA encouraged stations to implement stricter access controls, such as password protection and physical locks on EAS consoles. The incident also led to a broader discussion about the need for updated security standards for the EAS, including the potential for digital encryption and redundant verification systems. These measures aimed to prevent future intrusions and maintain public trust in the emergency alert system.
Similar incidents and the 2017 WZZY hijacking
The pattern of Emergency Alert System (EAS) hijackings observed in 2013 recurred several years later, demonstrating the persistent vulnerability of broadcast infrastructure to digital intrusion. On February 28, 2017, a notable incident occurred involving the radio station WZZY, located in Indiana. This event is widely recognized for its striking similarity to the earlier 2013 television station breaches, particularly in the content of the broadcast message.
During the 2017 incident, the WZZY broadcast was interrupted by the same hoax audio message that had previously alarmed viewers in Montana, Michigan, Wisconsin, and New Mexico. The message warned listeners of "bodies of the dead" who were "attacking the living." The recurrence of this specific phrasing suggested a deliberate reuse of the hoax material, potentially by the same group of hackers or by imitators leveraging the initial 2013 event for continued media attention. The use of the EAS equipment allowed the message to override standard programming, forcing the audio to play across the station’s frequency.
Local authorities in Indiana subsequently declared the WZZY broadcast a hoax, mirroring the official responses seen during the 2013 multi-state television interruptions. The incident highlighted that the threat to the EAS was not limited to television networks or specific geographic regions. Radio stations, such as WZZY, remained susceptible to the same types of digital access breaches that had affected television stations years earlier. The consistency of the message content between the 2013 and 2017 events provided investigators with a clear link between the two separate breaches of the national alert system.
The 2017 WZZY hijacking served as a reminder of the need for continuous security updates for EAS equipment. The fact that the same audio file was used indicated that the initial 2013 breach had not fully resolved the underlying security gaps in the system. Broadcast engineers and local authorities had to respond to the disruption by verifying the authenticity of the alert and communicating with the public to prevent widespread panic. The incident in Indiana remained a key case study in the ongoing history of EAS vulnerabilities in the United States.
Why it matters
The 2013 Emergency Alert System (EAS) hijackings serve as a critical case study in the vulnerability of national emergency infrastructure to relatively low-tech cyber intrusions. The incident, which affected television stations across Montana, Michigan, Wisconsin, and New Mexico, demonstrated that the reliability of the EAS—a cornerstone of U.S. emergency communication—was heavily dependent on the cybersecurity hygiene of individual local broadcasters rather than a centralized, hardened federal network. The broadcast of a message warning of "bodies of the dead" attacking the living was not merely a novelty; it exposed how easily critical alerting channels could be co-opted to induce public anxiety or confusion during a crisis.
Cybersecurity Weaknesses in Local Infrastructure
Investigations into the incident revealed that the primary vector for the hijackings was the reliance on default settings on EAS equipment. Many of the affected stations had not updated the default passwords on their EAS decoders or encoders, allowing hackers to gain access to the system with minimal effort. This highlighted a systemic issue where the national emergency alert framework was only as secure as its weakest local link. The fact that five different stations in four different states were compromised simultaneously suggested a coordinated effort that exploited common, yet overlooked, configuration errors.
Implications for National Resilience
The 2013 event underscored the need for standardized cybersecurity protocols across all EAS participants. It prompted a re-evaluation of how emergency messages are authenticated and displayed, leading to greater emphasis on software updates and password management practices among broadcasters. The incident also raised questions about the potential for future hijackings to disrupt not just local broadcasts, but the entire national alert system, particularly as the EAS evolved to integrate with mobile devices and other digital platforms. The reliance on default settings was identified as a critical weakness that could be leveraged by future attackers to broadcast false alarms or critical updates, potentially leading to widespread public reaction or apathy depending on the nature of the message.
See also
- International Framework for Nuclear Energy Cooperation
- Los Angeles Green New Deal
- Williams Olefins Plant explosion
- Inflation Reduction Act: Climate Investment and Energy Policy
- Glidden Doman: Helicopter Pioneer and Wind Turbine Innovator