City of Coweta

Ransomware disabled Coweta, Oklahoma, computers, files and administrative services beginning August 5, 2026, disrupting City Hall transactions, building permits and in-person card payments while 911 and off-site systems remained available. By August 18, day-to-day operations and utility-payment channels were normal; limited internal restoration and plain-text utility bills remained but were not expected to affect public services. No later public-service impact was found by August 30, so the incident is presumed resolved while technical recovery and the data review may continue.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
Internal business, administrative, operational, or staff-facing systems were unavailable.
The organization could not process, receive, issue, reconcile, or record payments normally.
Business, financial, customer, administrative, or operational transactions could not be completed normally.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.
The extortion activity involved unauthorized encryption of systems or data, with restoration or decryption conditioned on payment.
The actor directly contacted the victim through a ransom note, email, chat portal, telephone call, messaging platform, or other communication channel.
An authoritative source stated that no ransom or extortion payment was made.
DysruptionHub assesses with high confidence that the City of Coweta experienced ransomware affecting municipal administrative systems. The city’s Aug. 7 notice said the Aug. 5 incident affected all city computers, files and computer-based services except systems hosted off-site. The earlier service notice documented the initial systemwide outage without naming the cause.
Coweta engaged its IT provider, cybersecurity specialists and outside counsel to secure systems and begin recovery. KRMG identified the ransomware strain as Anubis and quoted City Manager Julie Casteen saying the attackers sent ransom messages, the city did not know the amount because it was not communicating with them, and Coweta refused to pay. The reporting supports the demand and nonpayment decision, but no stable actor claim or independent technical report establishes who deployed the malware.
The incident made city computers and files unavailable and disrupted City Hall transactions, building permits and in-person credit and debit card payments. Staff accepted checks and directed residents to the unaffected third-party payment portal. The city suspended water shutoffs for nonpayment while normal systems were unavailable.
Coweta said 911 and emergency services continued operating because police and fire data-processing systems were hosted off-site. The city website and online billing also remained available.
In an Aug. 18 update, the city said day-to-day operations had returned to normal and customers could again pay utility bills in person or online. A limited number of systems used for internal work were still being restored, and utility bills were issued in plain text because the normal formatting and printing system had not yet returned to service. The city said those remaining limitations were not expected to affect public services.
Coweta first disclosed a systemwide outage Aug. 5 without identifying a cause. Its Aug. 7 update identified ransomware, described affected and unaffected systems, explained payment alternatives and outlined recovery. The affected organization’s disclosure therefore supplies both the cyber characterization and the documented disruption.
The incident is presumed resolved. Coweta said Aug. 18 that day-to-day operations had returned to normal and that its remaining internal limitations were not expected to affect public services. No later public-service disruption tied to the incident was found by Aug. 30. The city had not announced complete technical recovery, so the status does not mean every internal system was confirmed restored.
Aug. 18 remains the last supported impact date because a temporary utility-bill formatting workaround was still in use. Neither continued internal restoration nor the data review, without a documented service effect, extends the operational incident.
Confidence is high that ransomware caused a material administrative-service disruption because the city confirmed both the mechanism and the effects. Confidence is medium in presumed resolution because the city reported normal day-to-day operations and no later impact was found, but it did not publish a final technical all-clear.
The city said payment data was not stored on city servers and was not accessed, but the scope of any other data access remains unresolved. The city manager’s direct statements establish that attackers sent ransom messages and that Coweta refused to communicate or pay. The public record does not establish the demand amount or a stable actor identity. KRMG’s Anubis label supports recording the reported ransomware family in narrative, not confirming attribution to the Anubis operation.
The public record does not establish the access vector, compromised account or device, vulnerability, dwell time, persistence, complete encryption scope, non-payment data access or exfiltration, threat actor, ransom amount, final technical restoration time or forensic conclusion.

The affected entity is the municipal government serving Coweta.
We reported that ransomware knocked Coweta city computers and files offline, disrupted City Hall payment processing, transactions and permitting, and prompted backup-based recovery. Our reporting documented preserved 911 and off-site services and unresolved questions about other data access, attribution, ransom activity and initial access.
Coweta said it was experiencing a systemwide computer outage that temporarily prevented City Hall from processing or accepting transactions and issuing building permits. Online utility payments remained available, and staff were working to restore service.
The city confirmed that an August 5 systemwide ransomware attack made city computers, files and computer-based services inoperable. It said 911, emergency services, off-site police and fire systems, its website and third-party billing portal were unaffected. Payment data was not stored on city servers and was not accessed, while specialists continued assessing what other data, if any, was accessed and restoring from an off-site backup.
KRMG identified the ransomware strain as Anubis and quoted City Manager Julie Casteen saying attackers sent ransom messages, the city did not know the amount because it was not communicating with them and Coweta refused to pay. She said payment data and emergency services remained on unaffected systems.
Coweta said recovery was nearing completion, financial software had remained available and the primary remaining impact was limited access to everyday staff files. The city expected full functionality by the end of Aug. 17 and said cyber insurance should cover most recovery costs.
Coweta said August 18 that day-to-day operations had returned to normal and in-person and online utility payments were available. A limited number of internal systems and the normal utility-bill formatting and printing system were still being restored, but the city said those limitations were not expected to affect public services.
Signed-in members can report an error, update, or missing source.