Skip to content

Oklahoma Manufacturing Alliance Ransomware Incident

Summary

Oklahoma Manufacturing Alliance logo

Oklahoma Manufacturing Alliance said ransomware activity targeted two employee computers and affected a limited portion of its local network on July 15, 2026. Staff isolated the systems and restored access through a separate secure network later that morning, while OMA said it found no evidence of data removal or compromised client records.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted location

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

Data impacts

  • No known data impact

    Available evidence indicates that the incident did not materially affect the confidentiality, integrity, or availability of data.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

Extortion indicators

  • Data-theft extortion

    The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.

  • Public leak threat

    The actor explicitly threatened to publish or publicly release victim data or incident details.

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Oklahoma Manufacturing Alliance experienced a contained ransomware incident on July 15, 2026. OMA told News 9 that ransomware activity targeted two employee computers and affected a limited portion of its local network. Its IT team identified and isolated the affected systems, then restored access through a separate secure network later that morning.

OMA’s direct ransomware characterization supports confirmed ransomware at the organizational-reporting level. The public record does not identify the ransomware family, encryption behavior, initial access vector, affected files, compromised credentials or specific security controls involved in containment.

Operational significance

The incident temporarily disrupted access to part of OMA’s local network, but the available reporting indicates a narrow internal impact rather than a prolonged or statewide service interruption. Access was restored the same morning, and no source reports closure of the organization, interruption of its manufacturer-support programs or downstream effects at client companies.

OMA is a statewide manufacturing-support organization rather than a production facility. Its official website describes a network of experts that provides assessments, training, engineering, supply-chain, workforce and technical services to manufacturers. The operational significance therefore lies in the temporary loss of internal business-network access, not disruption of industrial production or control systems.

Disclosure posture

News 9 published the first identified news report on Aug. 8, more than three weeks after the July 15 event. The report attributed the incident date, ransomware characterization, containment, restoration and data-impact statement directly to OMA. The reviewed sources do not show a separate contemporaneous public incident notice from the organization.

Booba Project publicly claimed it breached OMA, obtained 10 gigabytes of data and would release the material if a ransom was not paid, according to News 9. DysruptionHub treats those statements as unverified threat-actor claims. OMA said it found no evidence that information was removed and that client records were maintained on a separate system not involved in the incident.

Current status

The operational disruption is resolved because OMA restored access through a separate secure network on July 15. The organization continued working with IT professionals to review the event and strengthen security measures, but no later source identified renewed disruption.

Confidence and uncertainty

Confidence is high that ransomware affected two employee computers and a limited network segment because OMA directly confirmed those facts. Confidence is also high that access was restored the same morning.

Confidence in Booba Project attribution is low. A cybersecurity consultant documented the group’s public claim, but the available evidence does not independently establish that the claimant operated the ransomware found on OMA’s computers or verify the alleged 10-gigabyte theft. Data theft remains unconfirmed: the group alleged exfiltration and threatened publication, while OMA said its review found no evidence of removal and no compromise of separately stored client records.

Analytic gaps

The public record does not establish the initial access vector, phishing involvement, compromised account, exploited vulnerability, malware family, encryption scope, affected files, lateral movement, persistence, forensic indicators, ransom amount, direct victim contact, payment status, proof of the claimed 10-gigabyte dataset, publication status or law-enforcement involvement. It also does not identify which internal functions lost access or whether any non-client administrative information was viewed or copied.

Threat actor and claim

Listed as: Oklahoma Manufacturing AllianceSource: ransomware.livePublished: Discovered:

Claim details

Booba Project claimed it breached Oklahoma Manufacturing Alliance, obtained 10 gigabytes of data and would release the material if a ransom was not paid. News 9 attributed the claim to a cybersecurity consultant who observed the group’s post. OMA said it found no evidence that information was removed and that client records were maintained on a separate system not involved in the incident. The claim is recorded as an allegation, not confirmed attribution or confirmed data theft.

Screenshot documenting Booba Project claim

Organizations involved

Impacted location

Sources

Oklahoma Manufacturing Alliance restores access after ransomware activity

DysruptionHub reported that ransomware affected two OMA employee computers and a limited portion of its local network on July 15. Access returned through a separate secure network later that morning, while OMA said it found no evidence of removed information or compromised client records; Booba Project’s claimed 10-gigabyte theft remained unverified.

Oklahoma Manufacturing Alliance targeted in ransomware attack

News 9 reported that OMA said ransomware targeted two employee computers on July 15, affected a limited part of its local network, and was isolated before access returned through a separate secure network later that morning. Booba Project claimed 10 GB of theft and threatened release, but OMA said it found no evidence of removal or compromised client records.

See something that needs correction?

Signed-in members can report an error, update, or missing source.