Skip to content

Oklahoma Manufacturing Alliance restores access after ransomware activity

OMA said ransomware affected two employee computers July 15, but access was restored that morning and it found no evidence that data or client records were compromised.

Exterior sign for the Oklahoma Manufacturing Alliance’s Advanced Manufacturing Center at the Tulsa Port of Catoosa.
The Oklahoma Manufacturing Alliance’s Advanced Manufacturing Center at the Tulsa Port of Catoosa in Oklahoma. (Oklahoma Manufacturing Alliance)

The Oklahoma Manufacturing Alliance detected ransomware activity on two employee computers July 15, disrupting a limited portion of its local network before staff isolated the affected systems, the organization said.

Access returned through a separate, secure network later that morning. OMA said it found no evidence that information was removed or client records were compromised. Client information was maintained on a separate system that was not involved in the incident, the organization said.

OMA is a Tulsa-based public-private partnership that provides technical and business assistance to manufacturers through the federal Manufacturing Extension Partnership. The National Institute of Standards and Technology says OMA serves all 77 Oklahoma counties through manufacturing extension agents and applications engineers.

Chip in once
If this reporting helped you, a one-time tip helps cover hosting, tools and future investigations.

Tip us

Support us monthly
A small monthly pledge keeps independent coverage and our reader tools online for everyone.

Become a Supporter

A ransomware operation calling itself Booba Project later listed OMA on a leak site. Ransomware tracking services recorded the listing July 28, nearly two weeks after the organization detected the activity.

Booba Project claimed it obtained 10 gigabytes of data and threatened to publish the material unless a ransom was paid, News 9 reported, citing cybersecurity consultant Ron Vaughn. The claim conflicts with OMA’s finding, and no public evidence has independently verified the alleged data theft.

OMA said it is continuing to work with information technology professionals to review the incident and strengthen its security measures. It has not identified the ransomware family, initial access method, ransom amount or payment, and whether any non-client administrative information was accessed or removed remains unresolved.

Attribution note: DysruptionHub credits upstream reporting and primary sources—see citations above. If this report informed your coverage, please cite DysruptionHub with a link.
DysruptionHub Staff

DysruptionHub Staff

A collaborative project to bring you the latest cyberattacks impacting the availability of services and goods in the United States.

All articles

More in Private Sector

See all

More from DysruptionHub Staff

See all