Claim details
Rhysida claimed the sheriff’s office as a victim and alleged data theft; the victim has not verified attribution or exfiltration.
The Cleveland County Sheriff’s Office reported ransomware affecting parts of its internal computer system in November 2025. It said 911 and deputy response continued; Rhysida later claimed responsibility and data theft, which the office has not verified.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
Internal business, administrative, operational, or staff-facing systems were unavailable.
The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.
The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.
The actor published or shared a sample of allegedly stolen victim data to substantiate the extortion claim.
The Cleveland County Sheriff’s Office reported ransomware affecting parts of its internal computer system in November 2025. Its acknowledgment supports a confirmed cyber assessment and confirmed ransomware involvement. Officials did not identify the initial access method, specific affected applications or whether records were accessed.
The disruption was confined in public reporting to parts of the sheriff’s internal computer system. County IT personnel worked to restore it. The office said 911 service, deputy response and daily public safety operations continued. The county service area and Norman office anchor are geographic context; they do not imply countywide emergency communications failed.
Comparitech reported on Dec. 2 that Rhysida listed the office, demanded nine bitcoin and posted sample images it described as stolen records. Those are the group’s claims; the sheriff’s office did not confirm Rhysida’s responsibility, data theft or the authenticity of the samples. The claim is recorded separately from confirmed incident facts.
At the time of the Nov. 20 report, restoration and assessment were ongoing. No reviewed official source gives a final restoration date. With no later documented operational outage, the incident is presumed resolved, not formally resolved.
Confidence is high in the office’s ransomware acknowledgment and internal computer disruption. Attribution to Rhysida is low confidence pending independent verification. The public record does not establish confirmed exfiltration, exact data categories, number of affected records or payment. A ransomware.live listing also records the Rhysida claim discovered Dec. 2, 2025. The sheriff’s office has not confirmed the actor or data theft.
Rhysida claimed the sheriff’s office as a victim and alleged data theft; the victim has not verified attribution or exfiltration.

The Cleveland County Sheriff’s Office in Oklahoma says a ransomware attack hit parts of its internal computer system but did not disrupt 911 service, deputy response or other public safety operations.
Rhysida says it stole data from the sheriff’s office during the attack and is demanding 9 bitcoin within the next seven days. The group posted sample images of what it says are stolen documents.
Signed-in members can report an error, update, or missing source.