Claim details
Rhysida claimed the tribes and demanded 10 bitcoin; the tribe did not confirm attribution.
A ransomware attack beginning Dec. 8, 2025, disrupted computers, email, phones, schools and tribal operations for the Cheyenne and Arapaho Tribes in Oklahoma. Rhysida claimed the attack in February 2026, demanded 10 bitcoin and alleged data theft, while the tribe said it paid nothing.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
Data was rendered inaccessible through unauthorized encryption, including ransomware-related encryption.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
Internal or external network connectivity was unavailable or materially impaired.
Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.
The extortion activity involved unauthorized encryption of systems or data, with restoration or decryption conditioned on payment.
The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.
The actor explicitly threatened to publish or publicly release victim data or incident details.
The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.
The actor imposed a deadline or public countdown before increasing the demand, publishing data, deleting keys, or taking another threatened action.
The actor directly contacted the victim through a ransom note, email, chat portal, telephone call, messaging platform, or other communication channel.
An authoritative source stated that no ransom or extortion payment was made.
Our reporting confirms with high confidence that the Cheyenne and Arapaho Tribes experienced a ransomware attack beginning Dec. 8, 2025. The tribal government publicly identified ransomware, and Rhysida later claimed responsibility; attribution remains a medium-confidence actor claim rather than a confirmed finding.
The tribe shut down networks and experienced disruptions to computers, email, phones, schools and other government operations. Restoration proceeded in phases, with most users at tribal headquarters restored by early January, although alternate phone arrangements remained in use into February.
The documented facility municipality is Concho in Canadian County, Oklahoma, where tribal headquarters is located. References to Clinton in public commentary do not establish a separately impacted facility.
Confidence is high that ransomware caused the disruption because the tribe explicitly confirmed it. Confidence is medium in Rhysida attribution and its alleged theft because the group made the claim and demanded 10 bitcoin, but the tribe did not confirm the actor or the data assertion.
The affected organization confirmed both cyber involvement and operational effects, supporting organization-confirmed cyber and disruption transparency.
The incident is presumed resolved because core systems were largely restored and no continuing material outage was located, although no final all-clear date was published.
The public record does not establish initial access, the full system inventory, the data allegedly stolen, whether samples were authentic, or the final restoration date.
Rhysida claimed the tribes and demanded 10 bitcoin; the tribe did not confirm attribution.

DysruptionHub reported the tribal government ransomware confirmation, operational disruption, restoration and Rhysida claim.
Rhysida listed the tribes, demanded 10 bitcoin and alleged stolen data.
The Record reported the Dec. 8 attack, phased recovery, Rhysida claim and the tribe’s statement that it did not pay.
Signed-in members can report an error, update, or missing source.