When 911 Can't Answer: The Growing Threat of TDoS Attacks on Emergency Services
Picture this. It's a quiet Friday night. Then, without warning, thousands of calls begin pouring into a county's phone lines, all at once, all fake. Within minutes the lines are jammed. And somewhere out there, a real person dials 911, needing help right now, and can't get through.
This isn't a hypothetical. It's a Telephony Denial of Service (TDoS) attack, and emergency call centers across the country are firmly in the crosshairs.
The good news? These attacks are preventable. Let's talk about what TDoS is, why 911 is such a tempting target, and how the right voice security can keep emergency lines open when it matters most.
What Is a TDoS Attack?
A TDoS attack is a Distributed Denial of Service attack aimed at a voice network or phone number. Instead of flooding a website with web traffic, attackers flood a phone system with robocalls, tying up every available line so legitimate calls can't get through.
For a business, that's disruptive and expensive. For a 911 center, it can be a matter of life and death. When the lines are full of bogus calls, a real emergency call may never connect.
As DHS Science and Technology Directorate Program Manager Daniel Massey put it, "the high number of bogus calls effectively ties up system resources so that actual 911 calls may not get through." He added a warning that still rings true today: "As attacks become larger and more sophisticated, it is very important that systems for defense also improve to meet this threat."
Why Attackers Target 911
Why would anyone attack an emergency line? The motives are unsettling but straightforward.
- Ransom. Criminals flood the lines, then demand payment to make it stop.
- Disruption and chaos. Hacktivists and even hostile nation-states see the phone system as a way to strong-arm authorities or simply wreak havoc.
- Distraction. An overwhelmed 911 center can mask other criminal activity happening nearby.
The phone system has become a critical attack surface. Tech-savvy criminals understand that while organizations have spent heavily to secure email and data networks, voice networks have often been left exposed.
The Attacks Are Getting Worse
If you think this is a rare, isolated problem, the recent numbers tell a different story.
- Attacks on emergency call systems climbed from roughly once every 74 days in 2024 to once every 60 days in 2025. (Motorola Solutions)
- Nearly 90% of U.S. emergency communication centers experienced at least one outage in the past year, driven by aging equipment and cyberattacks, including TDoS. (StateScoop)
- A single TDoS incident in August 2024 disrupted seven large counties and 21 public safety agencies. (Intrado)
- Most 911 centers report they are not prepared to handle the escalating flood of fake calls. (StateScoop)
The FBI and CISA have documented how these attacks work in practice: attackers use VoIP to falsify their location and route fake calls into a specific jurisdiction, hijack hospital or business phone systems to dial 911 repeatedly, and bypass location-based routing by dialing 10-digit emergency numbers directly. (CISA/FBI guidance)
The trend line points in one direction, and it's not the one we'd hope for.
A Real Attack, and a Real Recovery: Howard County
You don't have to imagine what a TDoS attack on emergency services looks like. It happened to Howard County, Maryland, part of the greater Washington, D.C. metro area and home to several federal agencies.
The flood of robocalls started on a Friday night, hitting the county's administrative phone lines. The 35,000 malicious calls overwhelmed those lines and shut down the county's public-safety answering points (PSAPs), the call centers that receive emergency calls for police, fire, and ambulance service.
SecureLogix moved fast. After a quote and verbal approval, SecureLogix deployed its Call Defense™ Call Security System the following Tuesday, just four days after the attack started. The platform traced the attack to an international group calling from overseas.
The result? After deployment, Howard County immediately began blocking the malicious calls and fully restored its PSAP operations and 911 services.
Here's a telling detail. Once the attackers realized their calls were blocked, they shifted to neighboring counties, overwhelming their phones and threatening their 911 response too. Those county governments reached out to SecureLogix for the same solution and are now protected against future attacks.
That's the reality of TDoS: it moves to wherever the defenses are weakest.
Research That Stays Ahead of the Threat
SecureLogix hasn't just responded to TDoS attacks. We've spent years studying how to stop them before they start.
For 20+ years, our research team has continuously identified new threats and pioneered technology to defend against them. That work includes partnering with the U.S. Department of Homeland Security (DHS) and Department of Defense (DoD), backed by more than $25 million in DHS and DoD research funding.
As SecureLogix CTO Mark D. Collier described, part of that DHS work focuses on detecting spoofing, differentiating fake calls from legitimate ones, and applying that ability to TDoS attacks. Another project, in conjunction with the University of Houston, examined how the move to Next Generation 911 might affect TDoS risk.
The guiding principle behind it all captures exactly why emergency services are different. In Collier's words: "When you're dealing with 911, this could be a real emergency situation. We want to make sure that we are never dropping the right call."
That's the balance a 911 center needs: block the flood, but never, ever block the caller who genuinely needs help.
How SecureLogix Stops TDoS Attacks
So how do you keep emergency lines open under attack? The answer is to filter good calls from bad in real time, right at the edge of your voice network, before the flood can reach your call takers.
The Call Defense™ Call Security System sits at the edge of your voice network and separates legitimate traffic from malicious traffic in real time. Its key components work together to shut down TDoS attacks:
- Call Firewall blocks bad calls before they reach your network, with enterprise-wide call visibility and unified security policy enforcement.
- Call Intrusion Prevention (IPS) detects call pattern attacks and anomalies, and enforces call volume thresholds and traffic velocity limits, exactly the signatures a TDoS flood produces.
- Reporting and Forensics deliver voice network and call detail record analytics, so you can see attacks as they happen and after the fact.
- The Red List call threat database is a proprietary international dataset of harassing callers, voice spammers, and call attack signatures that continuously improves protection for every customer.
The system protects SIP, TDM, or hybrid networks, works with any voice system vendor, and can be deployed on-premises, virtually, or in the cloud.
For agencies that would rather have experts handle it, the Call Secure™ Managed Call Security Service combines the Call Defense System with the most experienced call security team in the business. Whether you want a fully managed service or urgent help mitigating an active attack, the team is there to solve the problem, just as they did for Howard County in four days.
Emergency Lines Should Always Be Open
TDoS attacks on 911 are rising, more frequent, and more sophisticated. But this is a solvable problem. The technology exists to detect the flood, block it at the edge, and keep the right calls flowing.
SecureLogix has done exactly that for municipalities, government agencies, and some of the largest and most complex voice networks in the world, blocking more than 116 million threatening calls for customers each year. (SecureLogix 2022 Call Security Report)
When someone dials 911, the line has to be open. Let's make sure it is.
Speak with a Voice Security Expert to learn how SecureLogix can protect your emergency lines and voice network from TDoS attacks.
