Cox Media Group suffers cyber attack
Live feeds on TV and radio stations go offline during incident
Cox Media Group appeared to be struggling with a ransomware attack on Thursday after many of its live streams went down.
Sources within the company told cyber security news site The Record that they had been ordered to shut down all of their computers to stop the problem from spreading. Live streams from the company's TV and radio stations also went down as the company reportedly had to suspend some live programming.
Some employee tweets yesterday apologizing for feeds being down were unavailable today. However, a tweet from streaming TV operation Hulu reporting issues with feeds from Cox-owned properties was still viewable this morning.
Cox is a large US media conglomerate, comprising 54 radio stations in 10 markets and 33 TV stations in 20 markets. It also operates the conservative news site rare.us, which appears to be unaffected.
Live feeds still appeared to be down on some Cox-owned radio sites, including WHIO 1290 this morning.
Sources reportedly described the incident as a ransomware attack to The Record. The cyber event comes on the heels of unrelated attacks on large meat producer JBS and the Colonial Pipeline. The latter disrupted gasoline supplies in some parts of the US.
RELATED RESOURCE
The US has recently increased its ransomware attacks scrutiny as they begin to pose a more visible national security threat.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
On Thursday, National Security Council official Anne Neuberger, the deputy national security advisor for cyber and emerging technology, sent an open letter to US businesses urging them to be more resilient after the JBS and Colonial attacks. The letter laid out a series of protective steps, including backing up data, segmenting their networks, and maintaining an incident response plan.
The Department of Justice also sent internal guidance yesterday elevating ransomware attack investigations to a similar priority level as terrorism, reported Reuters.
Danny Bradbury has been a print journalist specialising in technology since 1989 and a freelance writer since 1994. He has written for national publications on both sides of the Atlantic and has won awards for his investigative cybersecurity journalism work and his arts and culture writing.
Danny writes about many different technology issues for audiences ranging from consumers through to software developers and CIOs. He also ghostwrites articles for many C-suite business executives in the technology sector and has worked as a presenter for multiple webinars and podcasts.
-
Companies are still paying ransoms to cyber criminals despite official adviceNews A Proofpoint survey found evolving ransomware techniques and the use of AI is exacerbating the situation for victims
-
This one cyber crime group accounted for nearly a fifth of all ransomware attacks in JuneNews The Gentlemen, a ransomware a service operator, now accounts for 17% of published attacks
-
Working with the enemy: Ransomware negotiator-turned cyber criminal jailed after working with hackers to extort clientsNews Angelo Martino was supposed to be negotiating on behalf of victims, but was secretly working for ransomware operators
-
Hackers are posing as Interpol to target small businesses – here's what you need to knowNews Small businesses are warned to think twice before clicking on links
-
‘Every hour ransomware goes undetected drastically increases its potential blast radius’: Hackers are breaching networks and laying low for longer – and nearly half of firms don’t realize until data is stolenNews An ExtraHop survey found more intrusions are going undetected, leading to longer dwell times
-
Ransomware cartels are fragmenting into volatile splinter groups, warns Met Police cyber chiefNews Commoditized "cyber crime bazaars" and AI data mining are forcing law enforcement to rewrite its playbook
-
New ransomware threat group, The Gentlemen, has become one of the most active ransomware operators, accounting for 10% of all attacksNews NTT researchers warn that the RaaS group is leveraging SystemBC malware to establish covert tunnelling, evade detection, and support rapid lateral movement across enterprise environments
-
Instructure chose to a pay ransom following the Canvas cyber attack – research shows more than half of security leaders would follow suitAnalysis Opting to pay ransoms creates huge risks for enterprises – you’re relying on the word of criminals

