Skip to content

Kenaitze Indian Tribe cybersecurity incident

Summary

Kenaitze Indian Tribe logo

A cybersecurity incident disrupted the Kenaitze Indian Tribe’s computers, internet, email and phones beginning no later than July 27, limiting health, elder, education, transit and social services. The Tribe’s website still described the technical outage as unresolved Sept. 11; The Gentlemen’s claim remained unconfirmed as to responsibility, ransomware, encryption, data theft or a ransom demand.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Internet access disruption

    The organization lost or materially restricted internet connectivity.

  • Email disruption

    Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Scheduling disruption

    Appointment, booking, reservation, dispatch, staffing, or other scheduling functions were unavailable or impaired.

  • Healthcare operations disrupted

    Clinical, diagnostic, pharmacy, patient-care, medical-record, or other healthcare operations were materially affected.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

Extortion indicators

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that the Kenaitze Indian Tribe experienced malicious cyber activity that disrupted its computer and communications environment. The Tribe’s public statement connected the prolonged technical outage to a cybersecurity incident, said outside experts were assisting and acknowledged that an unknown actor had claimed responsibility. KDLL reported that the Tribe entered a second week of internet disruption after first reporting internet and phone outages in late July.

Ransomware.live preserved a July 31 leak-site claim by The Gentlemen against the Tribe. That stable claim is concrete external cyber evidence, but it does not confirm that The Gentlemen caused the outage, deployed ransomware or obtained the data it claimed.

Operational significance

The outage affected communications and public access across a tribal government providing health care, education, transit, elder and social services. The Tribe’s official website still said Sept. 2 that work continued to resolve the technical outage. It listed temporary numbers for primary care, behavioral health, dental care, education, transit, housing and family and social services.

Those workarounds kept important services available but document material degradation: normal computer, internet, email and phone access was disrupted, and members had to use alternate contact channels. The public record does not establish interruption to emergency response, inpatient care or the physical operation of transit.

Disclosure posture

The Tribe publicly connected the technical outage to a cybersecurity incident July 31 and acknowledged an unknown actor’s responsibility claim. That affected-organization disclosure preceded the named The Gentlemen claim’s wider reporting and supports organization-first cyber and disruption transparency.

Current status

The incident remained active Sept. 11. The Tribe’s website continued to say it was working with external experts to resolve the technical outage and could not yet provide additional details.

Confidence and uncertainty

Confidence is high that the incident was cyber-related and caused material disruption because the Tribe acknowledged both and documented its workarounds. Confidence remains low that ransomware was involved and low that The Gentlemen was responsible. The actor claim is preserved with contrary evidence: the Tribe described the claimant as unknown and said the claim was under investigation.

System and email unavailability establish a data-availability impact. Data theft remains unconfirmed. The Tribe has not confirmed unauthorized data access, exfiltration, affected data categories, a ransom demand or a notification process.

Analytic gaps

The public record does not establish when malicious access began, the access vector, vulnerability, compromised account or device, malware family, affected-system inventory, encryption scope, dwell time, persistence, exfiltration, affected data, ransom activity, containment actions, restoration method or final recovery date. It also does not resolve whether The Gentlemen’s claim reflects direct involvement, an affiliate, false attribution or information obtained from another source.

Threat actor and claim

Listed as: Kenaitze Indian TribeSource: ransomware.livePublished: Discovered:

Claim details

Ransomware.live recorded a The Gentlemen leak-site claim against the Kenaitze Indian Tribe. The Tribe acknowledged that an unknown actor had claimed responsibility and said the claim was under investigation, but it did not confirm The Gentlemen, ransomware, data theft or a ransom demand.

Organizations involved

Impacted locations

Sources

Cybersecurity incident limits Kenaitze Indian Tribe services in Alaska

We reported that a cybersecurity incident had disrupted the Tribe’s phones, email and computers for more than a week, forcing temporary phone lines and service limits. Ransomware.live attributed the incident to The Gentlemen, while the Tribe had not confirmed ransomware, data theft or a ransom demand.

Kenaitze Indian Tribe cybersecurity incident update

The Kenaitze Indian Tribe said it connected a prolonged technical outage to a cybersecurity incident, enlisted external experts, and was aware that an unknown actor had claimed responsibility. The Tribe said the claim was part of its investigation and that the ongoing matter limited additional detail.

Victim: Kenaitze Indian Tribe – thegentlemen

Ransomware.live recorded that Kenaitze Indian Tribe was claimed by the Thegentlemen ransomware group and listed the claim as discovered on July 31, 2026 at 18:30 UTC. The page identifies kenaitze.org and the United States, but the listing is an actor claim rather than victim confirmation.

Cybersecurity incident disrupts Kenaitze services

KDLL reported that the Tribe was in its second week of disrupted internet service, had first reported internet and phone outages in late July, and later linked the outages to a cybersecurity incident. The report documented temporary phone numbers, limited wellness and elder services, and the communications manager’s decision not to provide further detail.

Kenaitze Indian Tribe technical outage notice

The Tribe’s homepage said it continued working with external experts to resolve a technical outage and could not provide additional details while the matter remained ongoing.

Kenaitze Indian Tribe service and contact update

As reviewed Sept. 2, the Tribe’s official website said work continued to resolve the technical outage and listed temporary numbers for primary care, behavioral health, dental care, education, transit, housing and family and social services.

See something that needs correction?

Signed-in members can report an error, update, or missing source.