The Oklahoma Manufacturing Alliance detected ransomware activity on two employee computers July 15, disrupting a limited portion of its local network before staff isolated the affected systems, the organization said.
Access returned through a separate, secure network later that morning. OMA said it found no evidence that information was removed or client records were compromised. Client information was maintained on a separate system that was not involved in the incident, the organization said.
OMA is a Tulsa-based public-private partnership that provides technical and business assistance to manufacturers through the federal Manufacturing Extension Partnership. The National Institute of Standards and Technology says OMA serves all 77 Oklahoma counties through manufacturing extension agents and applications engineers.
A ransomware operation calling itself Booba Project later listed OMA on a leak site. Ransomware tracking services recorded the listing July 28, nearly two weeks after the organization detected the activity.
Booba Project claimed it obtained 10 gigabytes of data and threatened to publish the material unless a ransom was paid, News 9 reported, citing cybersecurity consultant Ron Vaughn. The claim conflicts with OMA’s finding, and no public evidence has independently verified the alleged data theft.
OMA said it is continuing to work with information technology professionals to review the incident and strengthen its security measures. It has not identified the ransomware family, initial access method, ransom amount or payment, and whether any non-client administrative information was accessed or removed remains unresolved.