The zombie emergency alert: how default passwords let hoaxers take over TV
In February 2013 viewers in Montana heard an official-sounding emergency alert announce that the dead were rising from their graves. The alert was fake, but the equipment that sent it was real, and it was protected by passwords printed in its own user manual.[1][2] This case file covers what happened, how the hoaxers got in, how regulators responded, and the one control that was missing.
What happened
The Emergency Alert System is how US broadcasters interrupt programming to warn the public about storms, floods and other dangers. Each station has a device that receives alerts and can put them on the air automatically, with the familiar harsh tones and a scrolling message.
At about 2:30 p.m. on February 11, 2013, the alert device at KRTV, a CBS affiliate in Great Falls, Montana, broke into a daytime talk show. The message named several Montana counties and said civil authorities had reported the bodies of the dead rising and attacking the living. It warned viewers not to approach them.[1]
It was not an isolated prank. Later that afternoon, 2 stations in Marquette, Michigan, and a station in La Crosse, Wisconsin, aired the same hoax, and that evening a station in Portales, New Mexico, did too.[1][2] FEMA said the hoax did not affect the government's ability to send real alerts.[2]
How they got in
The stations' alert devices were connected to the internet so engineers could manage them remotely. Many of them still used the default passwords set at the factory, and those passwords were listed in user manuals anyone could find online.[1][2]
A security researcher estimated that about 30 of these systems could be found through ordinary web searches.[2] Anyone who found one and tried the manual's password could log in as if they were the station's engineer and schedule an alert. The equipment had no way to tell a hoaxer from a station employee, because both were using the same key.
The weakness had been reported before the attack. About a month earlier, a researcher at a security firm had sent the US Computer Emergency Readiness Team a report describing ways to get around the login on this type of equipment, and advised disconnecting the devices from networks until they were fixed.[2]
How it was caught
There was nothing subtle to catch. The hoax was broadcast to thousands of viewers, and stations quickly apologized and pulled the messages. Local and federal authorities investigated, and early reports said the activity was traced to an overseas source.[1] No one has been publicly charged.[1]
What it cost
No one was hurt, and there was no known dollar loss. The damage was to trust in a system people are supposed to believe without question. A former head of public safety at the Federal Communications Commission put the cause down to poor computer hygiene, and the head of the Michigan broadcasters' association warned the intruders could have done real harm.[2]
The FCC issued an urgent advisory telling every broadcaster that takes part in the alert system to change its equipment passwords right away, make sure the devices sat behind a firewall, and check for fake alerts already queued to go out.[2] The same kind of hoax surfaced again years later: in 2017 a radio station in Indiana aired the same zombie message after its alert system was taken over.[1]
The missing control
The missing control: changing default passwords before putting equipment into service. The devices shipped with factory passwords that were published in their manuals, and stations connected them to the internet without replacing them.[1][2]
A default password is not a secret. It is shared with every customer who bought the same model and often with anyone who downloads the manual. Replacing it with a unique, strong password on day one, and keeping the device off the open internet, would have left the hoaxers with nothing to type. This was a cheap, 5-minute fix for each station.
What to do in your business
- List every device with a login. Routers, cameras, printers, door systems, alarm panels and card terminals all have admin passwords. Write down each one you own.
- Change the defaults today. Replace every factory password with a unique one and store it in a password manager, not on a sticky note on the device.
- Make it part of setup. Add a rule that no new device goes live until its default password is changed, whether you install it or a vendor does.
- Keep admin screens off the internet. Ask your IT provider to put devices behind a firewall and to reach them through a secure connection rather than an open web page.
- Read the warnings. Sign up for security notices from the makers of your key equipment, and apply fixes when they are released.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.