Skip to content

Cheyenne and Arapaho Tribes ransomware attack

Summary

Cheyenne and Arapaho Tribes logo

A ransomware attack beginning Dec. 8, 2025, disrupted computers, email, phones, schools and tribal operations for the Cheyenne and Arapaho Tribes in Oklahoma. Rhysida claimed the attack in February 2026, demanded 10 bitcoin and alleged data theft, while the tribe said it paid nothing.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

Data impacts

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

  • Data encryption

    Data was rendered inaccessible through unauthorized encryption, including ransomware-related encryption.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Email disruption

    Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Educational operations disrupted

    Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

Extortion indicators

  • Ransom demand

    The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.

  • Encryption-based extortion

    The extortion activity involved unauthorized encryption of systems or data, with restoration or decryption conditioned on payment.

  • Data-theft extortion

    The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.

  • Public leak threat

    The actor explicitly threatened to publish or publicly release victim data or incident details.

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

  • Countdown or payment deadline

    The actor imposed a deadline or public countdown before increasing the demand, publishing data, deleting keys, or taking another threatened action.

  • Direct victim contact

    The actor directly contacted the victim through a ransom note, email, chat portal, telephone call, messaging platform, or other communication channel.

  • Payment denied

    An authoritative source stated that no ransom or extortion payment was made.

Incident narrative

Analyst assessment

Our reporting confirms with high confidence that the Cheyenne and Arapaho Tribes experienced a ransomware attack beginning Dec. 8, 2025. The tribal government publicly identified ransomware, and Rhysida later claimed responsibility; attribution remains a medium-confidence actor claim rather than a confirmed finding.

Operational significance

The tribe shut down networks and experienced disruptions to computers, email, phones, schools and other government operations. Restoration proceeded in phases, with most users at tribal headquarters restored by early January, although alternate phone arrangements remained in use into February.

The documented facility municipality is Concho in Canadian County, Oklahoma, where tribal headquarters is located. References to Clinton in public commentary do not establish a separately impacted facility.

Confidence and uncertainty

Confidence is high that ransomware caused the disruption because the tribe explicitly confirmed it. Confidence is medium in Rhysida attribution and its alleged theft because the group made the claim and demanded 10 bitcoin, but the tribe did not confirm the actor or the data assertion.

Disclosure posture

The affected organization confirmed both cyber involvement and operational effects, supporting organization-confirmed cyber and disruption transparency.

Current status

The incident is presumed resolved because core systems were largely restored and no continuing material outage was located, although no final all-clear date was published.

Analytic gaps

The public record does not establish initial access, the full system inventory, the data allegedly stolen, whether samples were authentic, or the final restoration date.

Threat actor and claim

Listed as: Cheyenne & Arapaho TribesSource: ransomware.livePublished:

Claim details

Rhysida claimed the tribes and demanded 10 bitcoin; the tribe did not confirm attribution.

Organizations involved

Impacted locations

Sources

Cheyenne and Arapaho Tribes recover from ransomware attack

DysruptionHub reported the tribal government ransomware confirmation, operational disruption, restoration and Rhysida claim.

Cheyenne & Arapaho Tribes — Rhysida claim

Rhysida listed the tribes, demanded 10 bitcoin and alleged stolen data.

Cheyenne and Arapaho Tribes hit by ransomware

The Record reported the Dec. 8 attack, phased recovery, Rhysida claim and the tribe’s statement that it did not pay.

See something that needs correction?

Signed-in members can report an error, update, or missing source.