Report from FCC's inspector general refutes controversial claims by senior FCC officials that a cyberattack hobbled its comment system in May 2017
Context & Ripple Effects
This closes a year-long arc over what really took down the FCC's comment system during the 2017 net neutrality fight. Former Chairman Tom Wheeler had already said the system wasn't hit by a DDoS in the earlier 2014 episode either, contradicting the ex-FCC IT chief's account ([[a:930387]]), and Ajit Pai preemptively distanced himself from the claim the day before this report landed, saying his former CIO gave him inaccurate information ([[a:932170]]).
The inspector general's finding matters because the alleged attack was used to explain away millions of suspicious comments in the net neutrality docket — and because Pai later testified he doubted the attack story all along but stayed quiet at the IG's request ([[a:932516]]).
First-order effects
- Senior FCC officials' cyberattack explanation for the May 2017 comment-system outage is now officially refuted, leaving Pai's agency owning both the false claim and its reliance on a former CIO it now says misled him.
- The finding revives scrutiny of the net neutrality proceeding itself, since the outage narrative was the commission's defense against evidence of manipulated public comments.
Second-order effects
- Under FOIA pressure, the FCC has already conceded in court that its Electronic Comment Filing System cannot track where comments come from ([[a:939721]]) — with no attack to blame, the system's inability to verify authenticity becomes the central problem.
- That admission points directly at replacement: sources report the FCC plans to scrap and rebuild ECFS entirely after the fake-comments controversy ([[a:947908]]).
Third-order effects
- If the pattern holds, federal rulemaking dockets get treated as integrity infrastructure rather than inbox software — with identity verification and source tracking becoming baseline requirements for agencies accepting mass public input.
- Agencies also face an accountability question the FCC's handling illustrates: internal claims about security incidents now get independently audited, and officials who repeat unverified ones own the correction.
The trend: Public-comment infrastructure is moving from unaudited web forms toward verifiable, source-tracked systems as agencies confront organized comment manipulation.