Case file · ZOMBIE ALERT 2013

The zombie emergency alert: how default passwords let hoaxers take over TV

Published 2026-09-29 · 4 min read · Missing control: Change default passwords before deployment

In February 2013 viewers in Montana heard an official-sounding emergency alert announce that the dead were rising from their graves. The alert was fake, but the equipment that sent it was real, and it was protected by passwords printed in its own user manual.[1][2] This case file covers what happened, how the hoaxers got in, how regulators responded, and the one control that was missing.

What happened

The Emergency Alert System is how US broadcasters interrupt programming to warn the public about storms, floods and other dangers. Each station has a device that receives alerts and can put them on the air automatically, with the familiar harsh tones and a scrolling message.

At about 2:30 p.m. on February 11, 2013, the alert device at KRTV, a CBS affiliate in Great Falls, Montana, broke into a daytime talk show. The message named several Montana counties and said civil authorities had reported the bodies of the dead rising and attacking the living. It warned viewers not to approach them.[1]

It was not an isolated prank. Later that afternoon, 2 stations in Marquette, Michigan, and a station in La Crosse, Wisconsin, aired the same hoax, and that evening a station in Portales, New Mexico, did too.[1][2] FEMA said the hoax did not affect the government's ability to send real alerts.[2]

How they got in

The stations' alert devices were connected to the internet so engineers could manage them remotely. Many of them still used the default passwords set at the factory, and those passwords were listed in user manuals anyone could find online.[1][2]

A security researcher estimated that about 30 of these systems could be found through ordinary web searches.[2] Anyone who found one and tried the manual's password could log in as if they were the station's engineer and schedule an alert. The equipment had no way to tell a hoaxer from a station employee, because both were using the same key.

The weakness had been reported before the attack. About a month earlier, a researcher at a security firm had sent the US Computer Emergency Readiness Team a report describing ways to get around the login on this type of equipment, and advised disconnecting the devices from networks until they were fixed.[2]

How it was caught

There was nothing subtle to catch. The hoax was broadcast to thousands of viewers, and stations quickly apologized and pulled the messages. Local and federal authorities investigated, and early reports said the activity was traced to an overseas source.[1] No one has been publicly charged.[1]

What it cost

No one was hurt, and there was no known dollar loss. The damage was to trust in a system people are supposed to believe without question. A former head of public safety at the Federal Communications Commission put the cause down to poor computer hygiene, and the head of the Michigan broadcasters' association warned the intruders could have done real harm.[2]

The FCC issued an urgent advisory telling every broadcaster that takes part in the alert system to change its equipment passwords right away, make sure the devices sat behind a firewall, and check for fake alerts already queued to go out.[2] The same kind of hoax surfaced again years later: in 2017 a radio station in Indiana aired the same zombie message after its alert system was taken over.[1]

The missing control

The missing control: changing default passwords before putting equipment into service. The devices shipped with factory passwords that were published in their manuals, and stations connected them to the internet without replacing them.[1][2]

A default password is not a secret. It is shared with every customer who bought the same model and often with anyone who downloads the manual. Replacing it with a unique, strong password on day one, and keeping the device off the open internet, would have left the hoaxers with nothing to type. This was a cheap, 5-minute fix for each station.

What to do in your business

Watch the case
The emergency alert that warned of a zombie attackDrops 2027-01-03
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More identity and access cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. Wikipedia: 2013 Emergency Alert System hijackings
  2. NBC News: Security experts say zombie TV warning exposes flaws