Skip to content

Coweta, Oklahoma, ransomware incident

Summary

City of Coweta logo

Ransomware disabled Coweta, Oklahoma, computers, files and administrative services beginning August 5, 2026, disrupting City Hall transactions, building permits and in-person card payments while 911 and off-site systems remained available. By August 18, day-to-day operations and utility-payment channels were normal; limited internal restoration and plain-text utility bills remained but were not expected to affect public services. No later public-service impact was found by August 30, so the incident is presumed resolved while technical recovery and the data review may continue.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

Extortion indicators

  • Ransom demand

    The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.

  • Encryption-based extortion

    The extortion activity involved unauthorized encryption of systems or data, with restoration or decryption conditioned on payment.

  • Direct victim contact

    The actor directly contacted the victim through a ransom note, email, chat portal, telephone call, messaging platform, or other communication channel.

  • Payment denied

    An authoritative source stated that no ransom or extortion payment was made.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that the City of Coweta experienced ransomware affecting municipal administrative systems. The city’s Aug. 7 notice said the Aug. 5 incident affected all city computers, files and computer-based services except systems hosted off-site. The earlier service notice documented the initial systemwide outage without naming the cause.

Coweta engaged its IT provider, cybersecurity specialists and outside counsel to secure systems and begin recovery. KRMG identified the ransomware strain as Anubis and quoted City Manager Julie Casteen saying the attackers sent ransom messages, the city did not know the amount because it was not communicating with them, and Coweta refused to pay. The reporting supports the demand and nonpayment decision, but no stable actor claim or independent technical report establishes who deployed the malware.

Operational significance

The incident made city computers and files unavailable and disrupted City Hall transactions, building permits and in-person credit and debit card payments. Staff accepted checks and directed residents to the unaffected third-party payment portal. The city suspended water shutoffs for nonpayment while normal systems were unavailable.

Coweta said 911 and emergency services continued operating because police and fire data-processing systems were hosted off-site. The city website and online billing also remained available.

In an Aug. 18 update, the city said day-to-day operations had returned to normal and customers could again pay utility bills in person or online. A limited number of systems used for internal work were still being restored, and utility bills were issued in plain text because the normal formatting and printing system had not yet returned to service. The city said those remaining limitations were not expected to affect public services.

Disclosure posture

Coweta first disclosed a systemwide outage Aug. 5 without identifying a cause. Its Aug. 7 update identified ransomware, described affected and unaffected systems, explained payment alternatives and outlined recovery. The affected organization’s disclosure therefore supplies both the cyber characterization and the documented disruption.

Current status

The incident is presumed resolved. Coweta said Aug. 18 that day-to-day operations had returned to normal and that its remaining internal limitations were not expected to affect public services. No later public-service disruption tied to the incident was found by Aug. 30. The city had not announced complete technical recovery, so the status does not mean every internal system was confirmed restored.

Aug. 18 remains the last supported impact date because a temporary utility-bill formatting workaround was still in use. Neither continued internal restoration nor the data review, without a documented service effect, extends the operational incident.

Confidence and uncertainty

Confidence is high that ransomware caused a material administrative-service disruption because the city confirmed both the mechanism and the effects. Confidence is medium in presumed resolution because the city reported normal day-to-day operations and no later impact was found, but it did not publish a final technical all-clear.

The city said payment data was not stored on city servers and was not accessed, but the scope of any other data access remains unresolved. The city manager’s direct statements establish that attackers sent ransom messages and that Coweta refused to communicate or pay. The public record does not establish the demand amount or a stable actor identity. KRMG’s Anubis label supports recording the reported ransomware family in narrative, not confirming attribution to the Anubis operation.

Analytic gaps

The public record does not establish the access vector, compromised account or device, vulnerability, dwell time, persistence, complete encryption scope, non-payment data access or exfiltration, threat actor, ransom amount, final technical restoration time or forensic conclusion.

Organizations involved

Impacted location

  • Coweta, Oklahoma

    The affected entity is the municipal government serving Coweta.

Sources

Coweta, Oklahoma, ransomware shuts down city computers

We reported that ransomware knocked Coweta city computers and files offline, disrupted City Hall payment processing, transactions and permitting, and prompted backup-based recovery. Our reporting documented preserved 911 and off-site services and unresolved questions about other data access, attribution, ransom activity and initial access.

City Hall Experiencing Temporary Computer System Outage

Coweta said it was experiencing a systemwide computer outage that temporarily prevented City Hall from processing or accepting transactions and issuing building permits. Online utility payments remained available, and staff were working to restore service.

City of Coweta Experiencing Ransomware Attack

The city confirmed that an August 5 systemwide ransomware attack made city computers, files and computer-based services inoperable. It said 911, emergency services, off-site police and fire systems, its website and third-party billing portal were unaffected. Payment data was not stored on city servers and was not accessed, while specialists continued assessing what other data, if any, was accessed and restoring from an off-site backup.

City of Coweta refuses to pay ransom after system-wide cyberattack

KRMG identified the ransomware strain as Anubis and quoted City Manager Julie Casteen saying attackers sent ransom messages, the city did not know the amount because it was not communicating with them and Coweta refused to pay. She said payment data and emergency services remained on unaffected systems.

City of Coweta ransomware recovery nears completion

Coweta said recovery was nearing completion, financial software had remained available and the primary remaining impact was limited access to everyday staff files. The city expected full functionality by the end of Aug. 17 and said cyber insurance should cover most recovery costs.

Most City of Coweta Systems Restored Following Ransomware Attack

Coweta said August 18 that day-to-day operations had returned to normal and in-person and online utility payments were available. A limited number of internal systems and the normal utility-bill formatting and printing system were still being restored, but the city said those limitations were not expected to affect public services.

See something that needs correction?

Signed-in members can report an error, update, or missing source.