Incident: Cyberattack on Cox Media Group's Television and Radio Stations

Published Date: 2021-06-09

Postmortem Analysis
Timeline 1. The software failure incident involving Cox Media Group's television and radio stations across the US happened last week, as mentioned in the article [115614]. 2. The article was published on 2021-06-09. 3. Therefore, the software failure incident occurred in the last week of May 2021.
System 1. Systems used by the Cox Media Group's television and radio stations were impacted, leading to station operations being disrupted [115614]. 2. Digital video library access was down [115614]. 3. Weather computers were not working for at least two stations [115614]. 4. Email systems were affected, with some employees still unable to recover their emails [115614]. 5. Phone lines and broadcast software failed at one station [115614].
Responsible Organization 1. The cyberattack on Cox Media Group's television and radio stations in the US was caused by unknown hackers or a criminal group [115614].
Impacted Organization 1. Cox Media Group's television and radio stations across the US [115614]
Software Causes 1. The software causes of the failure incident were related to a cyberattack on Cox Media Group's television and radio stations, impacting systems used by the stations, disrupting station operations, and leading to multiple systems being down, including access to the digital video library and weather computers [115614].
Non-software Causes 1. The failure incident was caused by a cyberattack, specifically a ransomware attack, on Cox Media Group's television and radio stations across the US [115614]. 2. The attack disrupted station operations, impacting systems used by the stations, including access to the digital video library and weather computers [115614]. 3. The attack led to issues such as email systems not being recovered, phone lines failing, and broadcast software not working properly [115614]. 4. The incident also affected the feed from one of the Cox stations, leading to complaints about a change in programming on Hulu [115614].
Impacts 1. Systems used by Cox Media Group's television and radio stations across the US were impacted, leading to disruptions in station operations, including multiple systems still being down, such as access to the digital video library and weather computers [115614]. 2. Station employees faced challenges such as not having recovered email access and having to work on workarounds, with some stations experiencing new issues like phone lines and broadcast software failures [115614]. 3. Hulu reported an issue with the feed from one of the Cox stations, leading to complaints about a change in programming [115614].
Preventions 1. Implementing robust cybersecurity measures such as regular security audits, penetration testing, and network monitoring to detect and prevent cyber intrusions [115614]. 2. Ensuring all software and systems are regularly updated with the latest security patches to address known vulnerabilities [115614]. 3. Providing comprehensive cybersecurity training to employees to recognize and respond to potential threats like phishing emails or suspicious activities [115614]. 4. Having a robust incident response plan in place to quickly mitigate the impact of a cyberattack and restore operations efficiently [115614].
Fixes 1. Implementing robust cybersecurity measures to prevent future cyberattacks [115614] 2. Conducting a thorough investigation to identify the root cause of the incident and address any vulnerabilities in the systems [115614] 3. Enhancing network security protocols and monitoring systems to detect and respond to potential threats more effectively [115614]
References 1. Two sources familiar with the situation 2. Employees from two stations 3. Allan Liska of Recorded Future 4. Energy Secretary Jennifer Granholm 5. Hulu's Twitter account 6. The White House 7. The FBI 8. The US Cybersecurity and Infrastructure Security Agency (CISA) 9. The Justice Department 10. Cox Media Group and its parent company 11. Cox and Apollo Global Management [115614]

Software Taxonomy of Faults

Category Option Rationale
Recurring one_organization, multiple_organization (a) The software failure incident having happened again at one_organization: - Cox Media Group's television and radio stations across the US were hit by a cyberattack, impacting systems and disrupting station operations [115614]. - Cox Media Group and its parent company have not publicly commented about the attack, and no official statement has been released to staff [115614]. (b) The software failure incident having happened again at multiple_organization: - The US has seen a sharp increase in cyber breaches and ransomware attacks targeting various sectors, including food, gas, water, hospitals, and transport [115614]. - Among recent ransomware attacks was one against Colonial Pipeline, prompting its shutdown, and another on JBS USA, one of the world's largest food companies [115614].
Phase (Design/Operation) design, operation (a) The software failure incident in the Cox Media Group cyberattack can be attributed to the design phase. The incident was caused by a cyberattack that impacted systems used by the stations, leading to disruptions in station operations [115614]. This indicates that contributing factors introduced during the system development or updates played a role in the failure. (b) Additionally, the software failure incident can also be linked to the operation phase. The attack resulted in multiple systems being down, including access to the digital video library and weather computers not working for some stations. Employees were facing issues such as not being able to recover email and experiencing failures in phone lines and broadcast software. These issues point to contributing factors introduced by the operation or misuse of the system [115614].
Boundary (Internal/External) within_system (a) within_system: The software failure incident reported in the article is likely within the system, as it mentions that multiple systems used by the Cox Media Group's television and radio stations were impacted by a cyberattack. The attack disrupted station operations, with systems like the digital video library and weather computers being down. Additionally, internal systems being affected indicate a ransomware attack, which is a type of cyber intrusion that originates from within the system [115614].
Nature (Human/Non-human) non-human_actions (a) The software failure incident occurring due to non-human actions: - The Cox Media Group's television and radio stations across the US were hit by a cyberattack, impacting systems used by the stations and disrupting station operations. The attack is being investigated by federal law enforcement, and multiple systems, including access to the digital video library and weather computers, were down [115614]. - The attack on Cox Media Group's stations was not attributed to any specific human actions but rather to a cyber intrusion that impacted the systems [115614]. (b) The software failure incident occurring due to human actions: - The article does not provide any information indicating that the software failure incident was caused by human actions. The focus is on the cyberattack and its impact on the stations' systems and operations [115614].
Dimension (Hardware/Software) software (a) The software failure incident reported in the article is primarily related to a cyberattack on Cox Media Group's television and radio stations across the US. The attack impacted systems used by the stations, leading to disruptions in station operations. Specific issues mentioned include multiple systems being down, access to the digital video library being unavailable, weather computers not working for some stations, email systems not yet recovered, and phone lines and broadcast software failing for at least one station [115614]. (b) The software failure incident is also related to software issues as a result of the cyberattack. The attack affected internal systems, indicating a potential ransomware attack according to Allan Liska of Recorded Future. The impact included disruptions in station operations, with employees facing challenges such as not being able to access email, using workarounds, and experiencing failures in phone lines and broadcast software [115614].
Objective (Malicious/Non-malicious) malicious (a) The software failure incident reported in the article is malicious in nature. It was a cyberattack on Cox Media Group's television and radio stations across the US, impacting systems used by the stations and disrupting station operations. The attack is being investigated by federal law enforcement, and there are indications that it could be ransomware as internal systems were affected. Additionally, there have been recent ransomware attacks targeting various sectors in the US, indicating a trend of malicious cyber breaches and ransomware attacks [115614].
Intent (Poor/Accidental Decisions) unknown The software failure incident reported in the articles does not provide specific information about whether the incident was due to poor decisions or accidental decisions. The articles mainly focus on the cyberattack on Cox Media Group's television and radio stations, the impact on station operations, ongoing investigations, and the broader context of cyber breaches and ransomware attacks in the US. Therefore, it is unknown whether the software failure incident was a result of poor decisions or accidental decisions.
Capability (Incompetence/Accidental) accidental (a) The software failure incident related to development incompetence is not explicitly mentioned in the provided article [115614]. (b) The software failure incident related to accidental factors is evident in the article as Cox Media Group's television and radio stations across the US were hit by a cyberattack. The sources did not specify if it was a ransomware attack or some other cyber intrusion, indicating an accidental external attack that impacted the systems used by the stations and disrupted station operations [115614].
Duration temporary The software failure incident reported in Article 115614 was temporary. The incident involved a cyberattack on Cox Media Group's television and radio stations across the US, impacting systems used by the stations and disrupting station operations. Multiple systems were down, including access to the digital video library and weather computers, and employees were facing issues such as not being able to recover email and experiencing failures in phone lines and broadcast software. The incident was still ongoing at the time of reporting, with stations implementing workarounds and precautions like not opening email on phones [115614].
Behaviour crash, omission, value (a) crash: The software failure incident in the Cox Media Group cyberattack resulted in systems used by the stations being impacted and station operations being disrupted, with multiple systems still down, including access to the digital video library and weather computers not working for at least two stations. Additionally, phone lines and broadcast software were failing at one station [115614]. (b) omission: Employees from two stations mentioned that they have not yet recovered email and are working on workarounds. Stations have asked staff not to open email on their phones, indicating an omission in the email system functionality [115614]. (d) value: The software failure incident led to the system performing its intended functions incorrectly, as seen in the case of complaints about a change in programming on Hulu due to an issue with the feed from one of the Cox stations [115614].

IoT System Layer

Layer Option Rationale
Perception None None
Communication None None
Application None None

Other Details

Category Option Rationale
Consequence property, delay, non-human (d) property: People's material goods, money, or data was impacted due to the software failure - Cox Media Group's television and radio stations across the US were hit by a cyberattack, impacting systems used by the stations and disrupting station operations [115614]. - Multiple systems were still down, including access to the digital video library and weather computers for at least two stations [115614]. - Some station employees had not yet recovered email and were working on workarounds, with stations asking staff not to open email on their phones [115614]. - One station experienced new issues, including phone lines and broadcast software failing [115614]. - Hulu mentioned an issue with the feed from one of the Cox stations, affecting the programming [115614].
Domain information (a) The failed system was intended to support the industry of information, specifically the production and distribution of information. The Cox Media Group's television and radio stations across the US were impacted by a cyberattack, leading to disruptions in station operations and affecting systems used by the stations [Article 115614]. The attack resulted in issues such as the digital video library being inaccessible, weather computers not working, email systems not yet recovered, and phone lines and broadcast software failing at one station. Additionally, there were complaints about a change in programming from one of the Cox stations, indicating disruptions in the distribution of information [Article 115614].

Sources

Back to List