Skip to content

OnSolve CodeRED Cyberattack

Summary

OnSolve logo

OnSolve’s legacy CodeRED alerting platform was damaged in a November 2025 cyberattack, disrupting emergency notification capabilities for customer jurisdictions. The provider decommissioned that system, moved customers to a separate replacement and said associated account data had been removed by attackers.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted location

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

Operational impacts

  • Application unavailable

    A specific application or software platform became unavailable or unusable.

  • Emergency communications disruption

    Emergency notification, public warning, radio, alerting, 911, or emergency coordination communications were unavailable or impaired.

  • Third-party service disruption

    The incident materially affected services delivered by or through a vendor, managed service provider, contractor, partner, or other third party.

Extortion indicators

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

Incident narrative

Analyst assessment

Our Nov. 15 report documented widespread restrictions and outages affecting the legacy CodeRED alert platform while Crisis24 investigated possible security issues. A later Camden County notice relayed OnSolve’s finding that an organized criminal group had targeted and damaged the legacy platform. That provider account supports confirmed cyber involvement. The affected system belonged to OnSolve CodeRED, not the municipal and county networks that used it.

Operational significance

CodeRED customers reported limited or unavailable emergency-notification functions in multiple states. Local agencies used alternate channels while the vendor restricted access. The provider permanently decommissioned the damaged legacy platform and accelerated migration to a separate CodeRED by Crisis24 environment. Camden County said backup data used for the replacement was current only through March 31, 2025, creating a reenrollment and data-continuity concern for users added later. The Alpharetta office location identifies the vendor’s physical anchor; the affected alert service was used nationally, but this record does not claim that every customer experienced the same outage.

Data impact and claim

A November Camden County notice relaying OnSolve’s initial account said attackers removed legacy platform data and listed potentially affected names, addresses, email addresses, phone numbers and alert-profile passwords. A later forensic update relayed by St. Mary’s County narrowed the potentially exposed data and said investigators found no evidence confirming exfiltration. The two provider accounts differ, so actual data transfer and scope remain unresolved. BleepingComputer reported that INC Ransom claimed the attack; that attribution remains a threat-actor claim, not a provider confirmation.

Current status

The legacy environment was permanently retired and the replacement platform launched. Because the reviewed material describes continuing customer migration rather than a universal final all-clear, operational status is presumed resolved, pending confirmation of full transition.

Confidence and uncertainty

Confidence is high in the damaged platform, customer alert disruption and provider-reported data removal because official customer communications describe them. A Feb. 9, 2026, St. Mary’s County update relaying CodeRED’s forensic findings dates unauthorized access as early as Oct. 31, 2025, and ransomware deployment to Nov. 10. It reported no forensic confirmation of exfiltration despite a data-transfer tool being found. It described two limited exposed data sets: usernames, phone numbers and inactive passwords changed in 2015; and usernames with encrypted unreadable passwords, with no evidence encryption keys were accessed. This narrows the earlier broad data-removal account relayed by Camden County; neither communication independently proves public posting or misuse of data. Precise access path, full affected population and INC Ransom’s responsibility remain uncertain. The ransomware claim search tool timed out, so the group claim is based on secondary reporting.

Threat actor and claim

Listed as: OnSolveSource: other

Claim details

INC Ransom claimed the attack; provider did not identify the group in the reviewed communication.

Organizations involved

Impacted location

Sources

CodeRED vendor limits alert platform during security review

Crisis24 has limited access to its CodeRED emergency alert platform while the company reviews potential vulnerabilities, according to notices from local agencies that use the system.

Update on Third-Party CodeRED Cybersecurity Incident

OnSolve CodeRED has informed us that its legacy alerting environment was targeted and damaged in a cyberattack by an organized criminal group. OnSolve has advised that data associated with its legacy CodeRED system was removed by the attackers.

See something that needs correction?

Signed-in members can report an error, update, or missing source.