Skip to content

Cheyenne and Arapaho Tribes in Oklahoma report attempted cyber intrusion

The tribes took systems offline after a December 2025 intrusion attempt. Rhysida later claimed the incident, but ransomware and data theft remain unconfirmed.

Sign reading “Cheyenne & Arapaho Tribes” with tribal design elements and the Cheyenne-language name below.
A sign for the Cheyenne and Arapaho Tribes in Oklahoma. (Photo courtesy TravelOK.com, Oklahoma Tourism & Recreation Department)
Published:

The Cheyenne and Arapaho Tribes of Oklahoma took their systems offline after identifying an attempted cybersecurity intrusion on or about Dec. 8, 2025. The shutdown disrupted computers, email and phones as the tribes assessed and restored their network.

In a Jan. 2 statement, the tribes called it an “attempted cybersecurity intrusion” and said, “Out of an abundance of caution, all systems were taken offline.” They reported no confirmed data loss and said the shutdown did not mean every system was compromised. The statement did not identify an attacker or say ransomware was involved.

A third-party cybersecurity firm worked with the tribal IT department to assess, clean and restore systems. About 80% of tribal employee users at the Concho headquarters had their systems fully restored by Jan. 2, the tribes said, while work on remaining systems continued in phases.

Notices from the tribe’s higher education program said the outage limited access to computers, email and phones and warned of possible delays in spring 2026 scholarship processing. The program said students would not be penalized for delays related to the disruption.

Chip in once
If this reporting helped you, a one-time tip helps cover hosting, tools and future investigations.

Tip us

Support us monthly
A small monthly pledge keeps independent coverage and our reader tools online for everyone.

Become a Supporter

On social media, the tribe posted alternate phone numbers for contacting officials during the disruption. A commenter asked whether computers and phones were back up in Clinton, Oklahoma, where the tribes operate a Lucky Star Casino. DysruptionHub reviewed a screenshot of the comment thread.

On Feb. 17, the Rhysida ransomware group listed the tribes as an alleged victim, demanded 10 bitcoin and claimed to have stolen data. The tribes have not publicly confirmed ransomware, Rhysida’s involvement or data theft. The group’s claims remain unverified.

As of mid-February, tribe-related Facebook posts still directed the public to alternate phone numbers for some government functions. The full duration and scope of the service disruption were not clear from the public notices.

The Cheyenne and Arapaho Tribes are a federally recognized tribal government headquartered in Concho, Oklahoma, with more than 12,000 enrolled citizens and a jurisdictional area spanning multiple western Oklahoma counties.

A separate ransomware attack disrupted Lucky Star Casinos in June 2021, temporarily closing the casinos operated by the tribes. The Cheyenne and Arapaho Tribal Tribune reported at the time that tribal government offices were unaffected because they used servers separate from the casinos.

In a statement by Gov. Reggie Wassana about the 2021 attack, Wassana wrote, “WE DID NOT NEGOTIATE NOR SURRENDER,” and said “every employee of the Casinos continues to receive their full pay and benefits.”

DysruptionHub Staff

DysruptionHub Staff

DysruptionHub Staff is the publication’s organizational byline for reports based on public statements, government records, regulatory filings and other available material when no single journalist contributed substantial original reporting.

All articles

More in Government

See all

More from DysruptionHub Staff

See all