Radio on Vinyl: Cyberattack Cripples Dutch Broadcaster RTV Noord, Forcing Manual Operation
The regional broadcasting company RTV Noord, based in the Netherlands, has suffered a large-scale cyberattack that crippled much of its digital infrastructure. The incident has severely disrupted broadcasting operations and the publication of content across all of the organization’s media platforms. The technical team, working alongside external specialists, is currently striving to restore system functionality, though the timeline for full recovery remains uncertain.
The first signs of the breach were noticed in the early hours of November 6 by the staff of the radio show De Ochtendploeg. According to the editor-in-chief, the hosts suddenly lost access to the editorial systems and were forced to continue broadcasting manually—playing music from vinyl records to keep the show on air. Despite the emergency, the radio transmission remained operational, and RTV Noord’s status as an emergency broadcaster was not compromised.
Television broadcasting has since been partially restored. That evening, the program Noord Vandaag aired, recorded through temporary workarounds. However, issues with digital platforms persist: the website and mobile app have effectively halted publications. News updates are now posted only through alternative channels, while live radio and television streams remain offline. RTV Noord continues to update its audience via social media, albeit in a limited capacity.
According to reports, the attackers left a message within the broadcaster’s system, though management has chosen not to disclose its contents. Preliminary assessments indicate that there is no evidence of extortion or data leaks at this stage, but experts are thoroughly examining all affected servers. Law enforcement has not yet been involved in the investigation—the primary focus remains on restoring the technical infrastructure. A company spokesperson stated that once operations are stabilized, the channel will proceed with a comprehensive analysis of the incident and work to identify the perpetrators.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.