Live streams for Cox radio and TV stations were down on Thursday, sources say due to a ransomware attack
Live streams for radio and TV stations owned by the Cox Media Group, one of the largest media conglomerates in the US, have gone down earlier today in what multiple sources have described as a ransomware attack.
Context & Ripple Effects
The Cox Media Group outage fits a pattern the coverage has been tracking for two years: the FBI investigated a ransomware attack that took The Weather Channel off air during severe weather in 2019, and months after Cox, Sinclair confirmed in an SEC filing that ransomware had disrupted its channels after initially blaming technical issues. Cox itself was already on attackers' radar — web-record analysis tied the SolarWinds espionage operation to access at Cox Communications' own networks.
First-order effects
- Viewers and listeners lost live access to Cox Media Group stations across its TV and radio portfolio while engineers scrambled to contain an intrusion that sources identified as ransomware.
Second-order effects
- Rival broadcasters like Sinclair now face pressure to disclose incidents faster rather than defaulting to 'technical issues' explanations, because the Sinclair filing showed regulators and investors expect formal ransomware disclosure.
Third-order effects
- When attribution eventually landed on Iranian hackers behind the Cox stream outage, it signaled that nation-state-linked crews see US broadcasters as viable targets, pushing live-streaming infrastructure toward critical-infrastructure treatment and FBI involvement of the kind seen in the Prospect Medical Holdings investigation.
The trend: US broadcast groups are becoming a recurring ransomware target class, with each outage exposing how much live distribution depends on shared IT and streaming systems.