Skip to content

Coweta, Oklahoma, ransomware shuts down city computers

City Hall cannot take card utility payments, while 911, off-site police and fire systems, and online bill pay remain available.

Exterior of Coweta City Hall in Oklahoma, with parked vehicles, flagpoles and the City of Coweta sign above the entrance.
Coweta City Hall in Coweta, Oklahoma. (City of Coweta)
Published:

A ransomware attack knocked Coweta, Oklahoma, city computers and files offline Wednesday, disrupting payment processing at City Hall while 911 and off-site police and fire systems continued operating normally, city officials said Friday.

Coweta, a Wagoner County city southeast of Tulsa, had an estimated population of 11,472 in 2025. The disruption affects computer-based municipal services, although the city website and third-party online billing portal remain available.

The city initially disclosed a systemwide computer outage Wednesday, saying City Hall could not process or accept transactions or issue building permits. On Friday, officials identified ransomware as the cause and said it affected all city computers, files and computer-based services except systems hosted off-site.

Coweta said it brought in its contracted IT provider and additional cybersecurity specialists to secure its systems, prevent further intrusion and begin recovery. Outside cybersecurity attorneys are also assisting. The incident has been reported to local and state authorities, and the city said notification of appropriate federal authorities was in progress.

Screenshot of an Aug. 7 Facebook post from the City of Coweta describing a ransomware attack that affected city computers and files while 911, the city website and online bill pay remained available.
The City of Coweta said in an Aug. 7 Facebook post that a ransomware attack had taken city computers, files and computer-based services offline while 911 and other off-site systems remained operational. (City of Coweta/Facebook)

Officials said credit card and other payment information is not stored on city servers and was not accessed in the attack. Cybersecurity attorneys and IT specialists are assessing what other data, if any, may have been accessed.

An off-site backup of city data will be used to restore files and records after affected systems have been cleared of ransomware and deemed safe for restoration, the city said. No timetable for full restoration has been announced. Officials said another public update is planned early next week, with additional updates when significant developments occur.

Residents can continue paying bills through Xpress Bill Pay, a third-party service hosted outside the city’s network that was not affected. The city said its website, also hosted off-site, remains online and safe to use.

Chip in once
If this reporting helped you, a one-time tip helps cover hosting, tools and future investigations.

Tip us

Support us monthly
A small monthly pledge keeps independent coverage and our reader tools online for everyone.

Become a Supporter

City Hall cannot accept credit or debit card utility payments while its computers are unavailable, but checks are being accepted. City employees can also help residents who normally pay by card in person use the online payment portal. Coweta said it will not disconnect water service for nonpayment while the systems are down.

The Police Department and Fire Department use off-site systems for processing data that were not affected, according to the city. Emergency services, including 911, are operating normally.

Coweta is not the first Oklahoma city to face ransomware-related service disruptions recently. A June 2025 ransomware attack on Durant disrupted digital and credit card payments and some administrative systems before the city restored payment services about a week later.

Coweta has not publicly identified a threat actor, disclosed whether it received a ransom demand or said how the ransomware entered its systems. Officials also have not determined whether data other than the payment information they said was unaffected was accessed or stolen.

Attribution note: DysruptionHub credits upstream reporting and primary sources—see citations above. If this report informed your coverage, please cite DysruptionHub with a link.
DysruptionHub Staff

DysruptionHub Staff

A collaborative project to bring you the latest cyberattacks impacting the availability of services and goods in the United States.

All articles

More in Government

See all

More from DysruptionHub Staff

See all