On the 23rd of November 2025, ESPN 97.5 in Houston went off script in the middle of their broadcast.
During an NFL game, the station’s signal was hijacked and replaced with racist messages and unauthorised audio. Engineers had it back within an hour, but the damage was done, and the cause was very telling: a power outage the previous day had damaged transmission equipment, and when backup came online, hackers got in through unsecured Barix gear. It was treated as more than an isolated event, and broadcasters running on ageing, internet-connected infrastructure realised that a major threat that has been flagged by engineering teams for years is real.
Where the Exposure Is
The transmitter chain is not the only exposure here, and it is rarely the first thing checked after an incident. A good share of the risk in a modern radio operation is in normal computers, where the machine runs playout automation, the producer uses it to cut promos, and the shared drive holds all the show archives and more. Smaller stations are now building production setups around Mac hardware, and it is worth knowing how to run a virus scan on your Mac before a big broadcast. People should also focus on checking activity logs and rotating passwords the same way one would on any other networked system.
This seems mundane and tedious, and it rarely gets as much attention as the transmitter does, but it has security risks that are much easier to manage than to handle later.
Why Broadcast Chains Keep Getting Targeted
Looking back at the Houston breach, the equipment that was targeted was a Barix studio-transmitter link (STL), which is pretty standard equipment for small and mid-sized radio stations. It’s part of the radio technology infrastructure that, in many ways, hasn’t changed much over the past few decades. STL send the audio signal from the studio to the transmitter, often through the internet. Many of these systems were installed years ago, long before cybersecurity was a major concern. As a result, some were never properly protected with firewalls or other security measures. Emergency Alert System (EAS) encoders often run on the same networks, so if someone finds a vulnerability, they can potentially use it to send out fake alerts with manipulated or hijacked audio.
The problem itself isn’t exactly new. In 2013, an EAS system at a Montana radio station was hacked and used to broadcast a fake warning about a zombie outbreak. Then, in 2016, a coordinated cyberattack targeted STL equipment at multiple stations. A year later, KQED in San Francisco lost weeks of work after ransomware spread through its newsroom.
What has changed, though, is the scale of the problem. More stations now rely on remote monitoring, and staff members regularly access systems from outside the station. These tools make everyday operations much easier, but the security risks that come with them often don’t receive much attention or funding until something actually goes wrong.
After the Houston incident, the advice given to broadcasters was fairly straightforward: fix vulnerable Barix devices, update their firmware, stop using default or common login credentials, require a VPN for remote access, and report anything unusual as soon as possible. None of this was particularly groundbreaking advice. The bigger difference was that engineering departments were seeing these recommendations presented as formal regulatory requirements rather than simply as best practices passed around within the industry.
It’s No Longer Optional
Regulators eventually started treating this as a compliance issue rather than just a recommendation. In 2026, the FCC adopted rules requiring EAS equipment to either have a firewall or operate on a segmented network. The rules also require passwords to be at least fifteen characters long, making it harder for stations to rely on common or reused passcodes. These changes were a direct response to the pattern of vulnerabilities that had been building for years. The FCC estimated that bringing stations into compliance would cost the industry around $26 million, which gives some indication of how many systems still needed to be updated.
The specific requirements are outlined in the FCC’s notice in the Federal Register. The notice also covers proposed changes aimed at modernising the broader alerting system. It is worth looking at, especially for stations that have not reviewed their security settings since their equipment was first installed. The rules apply across the industry, meaning there is no distinction between a large broadcasting network and a small community station operating on a single frequency.
Closing Notes
The incidents behind the rule tell their own story, as industry bodies now keep a running study of cyber security incidents across the broadcast sector. Also, the frequency has picked up enough that reviewing past cases has become routine for engineering staff, rather than a once-a-decade auditing exercise.
While the Houston station was back on air within the hour, it’s often the best outcome everyone reading this could wish for. What decided the outcome wasn’t luck, but someone patching something or backing it up. This changes the focus to not treating the technical side of radio as separate from the broadcast, but as the thing that keeps it possible at all.



