Claim details
INC Ransom claimed the attack; provider did not identify the group in the reviewed communication.
OnSolve’s legacy CodeRED alerting platform was damaged in a November 2025 cyberattack, disrupting emergency notification capabilities for customer jurisdictions. The provider decommissioned that system, moved customers to a separate replacement and said associated account data had been removed by attackers.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
A specific application or software platform became unavailable or unusable.
Emergency notification, public warning, radio, alerting, 911, or emergency coordination communications were unavailable or impaired.
The incident materially affected services delivered by or through a vendor, managed service provider, contractor, partner, or other third party.
The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.
Our Nov. 15 report documented widespread restrictions and outages affecting the legacy CodeRED alert platform while Crisis24 investigated possible security issues. A later Camden County notice relayed OnSolve’s finding that an organized criminal group had targeted and damaged the legacy platform. That provider account supports confirmed cyber involvement. The affected system belonged to OnSolve CodeRED, not the municipal and county networks that used it.
CodeRED customers reported limited or unavailable emergency-notification functions in multiple states. Local agencies used alternate channels while the vendor restricted access. The provider permanently decommissioned the damaged legacy platform and accelerated migration to a separate CodeRED by Crisis24 environment. Camden County said backup data used for the replacement was current only through March 31, 2025, creating a reenrollment and data-continuity concern for users added later. The Alpharetta office location identifies the vendor’s physical anchor; the affected alert service was used nationally, but this record does not claim that every customer experienced the same outage.
A November Camden County notice relaying OnSolve’s initial account said attackers removed legacy platform data and listed potentially affected names, addresses, email addresses, phone numbers and alert-profile passwords. A later forensic update relayed by St. Mary’s County narrowed the potentially exposed data and said investigators found no evidence confirming exfiltration. The two provider accounts differ, so actual data transfer and scope remain unresolved. BleepingComputer reported that INC Ransom claimed the attack; that attribution remains a threat-actor claim, not a provider confirmation.
The legacy environment was permanently retired and the replacement platform launched. Because the reviewed material describes continuing customer migration rather than a universal final all-clear, operational status is presumed resolved, pending confirmation of full transition.
Confidence is high in the damaged platform, customer alert disruption and provider-reported data removal because official customer communications describe them. A Feb. 9, 2026, St. Mary’s County update relaying CodeRED’s forensic findings dates unauthorized access as early as Oct. 31, 2025, and ransomware deployment to Nov. 10. It reported no forensic confirmation of exfiltration despite a data-transfer tool being found. It described two limited exposed data sets: usernames, phone numbers and inactive passwords changed in 2015; and usernames with encrypted unreadable passwords, with no evidence encryption keys were accessed. This narrows the earlier broad data-removal account relayed by Camden County; neither communication independently proves public posting or misuse of data. Precise access path, full affected population and INC Ransom’s responsibility remain uncertain. The ransomware claim search tool timed out, so the group claim is based on secondary reporting.
INC Ransom claimed the attack; provider did not identify the group in the reviewed communication.

Crisis24 has limited access to its CodeRED emergency alert platform while the company reviews potential vulnerabilities, according to notices from local agencies that use the system.
OnSolve CodeRED has informed us that its legacy alerting environment was targeted and damaged in a cyberattack by an organized criminal group. OnSolve has advised that data associated with its legacy CodeRED system was removed by the attackers.
The ransomware gang claims to have breached OnSolve’s systems on November 1, 2025, and encrypted files on November 10.
Signed-in members can report an error, update, or missing source.