Skip to content

Cleveland County Sheriff's Office Ransomware Incident

Summary

Cleveland County Sheriff's Office logo

The Cleveland County Sheriff’s Office reported ransomware affecting parts of its internal computer system in November 2025. It said 911 and deputy response continued; Rhysida later claimed responsibility and data theft, which the office has not verified.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

Extortion indicators

  • Ransom demand

    The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

  • Data sample published

    The actor published or shared a sample of allegedly stolen victim data to substantiate the extortion claim.

Incident narrative

Analyst assessment

The Cleveland County Sheriff’s Office reported ransomware affecting parts of its internal computer system in November 2025. Its acknowledgment supports a confirmed cyber assessment and confirmed ransomware involvement. Officials did not identify the initial access method, specific affected applications or whether records were accessed.

Operational significance

The disruption was confined in public reporting to parts of the sheriff’s internal computer system. County IT personnel worked to restore it. The office said 911 service, deputy response and daily public safety operations continued. The county service area and Norman office anchor are geographic context; they do not imply countywide emergency communications failed.

Later extortion claim

Comparitech reported on Dec. 2 that Rhysida listed the office, demanded nine bitcoin and posted sample images it described as stolen records. Those are the group’s claims; the sheriff’s office did not confirm Rhysida’s responsibility, data theft or the authenticity of the samples. The claim is recorded separately from confirmed incident facts.

Current status

At the time of the Nov. 20 report, restoration and assessment were ongoing. No reviewed official source gives a final restoration date. With no later documented operational outage, the incident is presumed resolved, not formally resolved.

Confidence and uncertainty

Confidence is high in the office’s ransomware acknowledgment and internal computer disruption. Attribution to Rhysida is low confidence pending independent verification. The public record does not establish confirmed exfiltration, exact data categories, number of affected records or payment. A ransomware.live listing also records the Rhysida claim discovered Dec. 2, 2025. The sheriff’s office has not confirmed the actor or data theft.

Threat actor and claim

Listed as: Cleveland County Sheriff's OfficeSource: otherPublished:

Claim details

Rhysida claimed the sheriff’s office as a victim and alleged data theft; the victim has not verified attribution or exfiltration.

Organizations involved

Impacted locations

Sources

Oklahoma's Cleveland County Sheriff's Office hit by ransomware

The Cleveland County Sheriff’s Office in Oklahoma says a ransomware attack hit parts of its internal computer system but did not disrupt 911 service, deputy response or other public safety operations.

Ransomware gang demands sheriff of Cleveland County, OK pay almost $800,000 in one week

Rhysida says it stole data from the sheriff’s office during the attack and is demanding 9 bitcoin within the next seven days. The group posted sample images of what it says are stolen documents.

See something that needs correction?

Signed-in members can report an error, update, or missing source.