Case file · DALLAS SIRENS 2017

Why every Dallas tornado siren went off at midnight: a radio signal nobody checked

Published 2026-09-29 · 4 min read · Missing control: Authenticate commands sent to field devices

For about an hour and a half on a spring night in 2017, all 156 of Dallas's outdoor warning sirens wailed at once, and no computer had been broken into.[1][3] This case file covers how a radio signal set them off, what it cost the city's 911 center, and the one control that was missing.

What happened

Late on Friday, April 7, 2017, Dallas residents were woken by the city's outdoor sirens, the ones meant to warn people of tornadoes and other emergencies. There was no storm. All 156 sirens in the system had been triggered, and they kept sounding, going quiet and starting again, more than a dozen times over roughly 90 minutes.[1][2][5]

City staff could not simply switch the alarm off from a desk. They had to shut the whole system down by hand to make it stop.[1] By then many people assumed the worst. Some thought a tornado was coming; others wondered whether the city was under attack.

On Monday, April 10, city officials said the sirens had been set off deliberately and that the signal most likely came from somewhere in the Dallas area. The police department began investigating with the FBI, and the city coordinated with the Federal Communications Commission, which polices the radio airwaves.[1][2] Two days later, on April 12, the City Council approved $100,000 to harden the siren system.[3][4]

How it worked

The Dallas sirens, a network of units installed in 2007, were controlled by radio rather than over the internet.[3] The city sent out a set of audio tones on a radio frequency, and each siren listened for that pattern. When a siren heard the right tones, it switched on.[3]

The weakness was that a siren had no way to tell who was sending the tones. Anyone who could reproduce the pattern and broadcast it with enough power could give the same order the city gives. City Manager T.C. Broadnax summed it up bluntly: it was a radio system, not a computer issue.[3] Officials also acknowledged that problems in how the city itself operated the system had allowed the intrusion, though they did not spell out what those were.[2]

That is why the city was confident the culprit was local. A radio signal of this kind only reaches so far, so whoever sent it had to be within range of the sirens.[1][2]

What it cost

The biggest cost landed on the emergency call center. Between 11:30 p.m. Friday and 3 a.m. Saturday, Dallas 911 took about 4,400 calls, roughly double the usual 2,200 for those hours. About 800 calls came in during a single 15-minute window just after midnight, and the longest wait to reach a call-taker was 6 minutes.[1] Every one of those extra calls was a worried resident tying up a line that someone with a real emergency might have needed.

The city's direct fix was cheaper. Officials said the transmitters already used encryption and that they strengthened it when the system was restarted over the weekend, then the council added the $100,000 for further upgrades.[1][3][4] The city had separately budgeted about $567,000 for siren repair and maintenance over 6 years back in November 2016.[2]

No one had been publicly identified as the person who sent the signal when the city reported the vulnerability fixed.[2]

The missing control

The missing control: authentication of commands sent to field devices. The sirens obeyed any transmission that sounded right, without checking that it really came from the city.

If each activation order had carried a secret that only the city's transmitter knew, a replayed or copied signal would have been ignored, and the sirens would have stayed silent. That is essentially what the city added after the fact by tightening encryption.[1][3] A second, smaller control would have shortened the night: a quick way to cancel a false alarm centrally instead of shutting down the system by hand.[1]

The lesson reaches well beyond sirens. Door controllers, alarm panels, building systems and older wireless gear often assume that any command they receive is legitimate. That assumption holds only until someone else learns to speak the same language.

What to do in your business

Watch the case
Why every Dallas tornado siren went off near midnightDrops 2027-01-07
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More patching and monitoring cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. KERA News: Dallas officials say emergency sirens were set off by broadcast signal, not computer hack
  2. StateScoop: Dallas official reports siren vulnerability fixed, admits city error in operation
  3. TechCrunch: Dallas approves $100,000 emergency system upgrade after radio hack
  4. KERA News: Dallas City Council approves $100,000 to boost security of city's emergency sirens
  5. CSO Online: City officials claim a hack set off all emergency warning sirens for about 90 minutes