The City of Coweta, Oklahoma, a Wagoner County municipality of roughly 11,472 residents southeast of Tulsa, confirmed on Friday, August 7, 2026 that a ransomware attack had taken all city computers, files and computer-based services offline. The city says it will not pay and will not even open a channel with the attackers. Recovery is being driven from an off-site backup. Emergency services, including 911, police and fire, were never affected because they run on separate off-site systems. All available reporting on this incident is regional broadcast press and aggregators; no vendor advisory, CERT bulletin or regulator filing has been published, and the strongest primary material is the city's own Facebook statement and on-camera remarks from City Manager Julie Casteen.
What Happened
The intrusion is dated to Wednesday, August 5, 2026. According to reporting from DysruptionHub, the city initially disclosed only a systemwide computer outage that day, saying City Hall could not process or accept transactions or issue building permits. Two days later, on Friday, officials identified ransomware as the cause and stated that it had affected all city computers, files and computer-based services except those hosted off-site.
KTUL, whose report was syndicated verbatim by National Cyber Security Consulting, describes the payload as encrypting local files, Word documents, Excel spreadsheets and municipal financial systems across City Hall. Those two sources are the only ones that name a strain, identifying it as Anubis. News On 6, KJRH and DysruptionHub do not name a family, and no researcher or vendor attribution has been published, so the Anubis identification should be treated as single-source reporting rather than confirmed attribution.
The city's published impact list, as relayed by News On 6, covers all city computers and computer files, computer-based city services, staff access to electronic records, and credit and debit card utility payments taken in person at City Hall. Services that stayed up include 911 and emergency dispatch, Coweta Police and Fire operations that depend on off-site systems such as LexisNexis, the city website, and Xpress Bill Pay, the third-party online billing portal. Residents can still pay utility bills online or by check, and the city said water service would not be disconnected while systems are down.
The refusal to pay is unusually blunt. "They've demanded a ransom," Casteen told KTUL. "We don't know what the amount is because we're not communicating with them. We just refuse to do that." She grounded the position in prior experience at another municipality: "I've been through that process before with another city and we actually got reinfected two weeks after we paid the ransom."
What Was Taken
No confirmed data theft has been reported, and no volume figure exists in any source. This is an encryption-impact incident as currently disclosed, not a confirmed exfiltration and leak-site case. No Anubis leak-site listing for Coweta has been reported by any of the sources.
Officials have been consistent and specific on one point across News On 6, KJRH, DysruptionHub and KTUL: resident credit card and other payment information is not stored on city servers and was not accessed. Casteen stated that "there has been no infiltration onto our city payment system. That is a separate system held in the cloud and we can assure you that no citizen payment information has been accessed."
That claim is narrower than it may sound. DysruptionHub reports that cybersecurity attorneys and IT specialists are still assessing what other data, if any, may have been accessed. Municipal file shares typically hold utility account records, HR and payroll files, permit and code enforcement records, court and citation data and vendor banking details, none of which are covered by the payment-card carve-out. Treat the scope of any data compromise as open until the assessment concludes.
Why It Matters
Coweta is a clean demonstration of segmentation working. Because 911 dispatch, police and fire systems and payment processing were hosted off-site and on independent infrastructure, a payload that reached "all city computers" still failed to touch life-safety services or cardholder data. For a city of about 11,000 residents with a contracted IT provider rather than a full internal security team, that architecture is the single decision that kept a bad week from becoming a public-safety event.
It is also a rare public refusal-to-pay with a named rationale from the decision maker. Casteen's reinfection anecdote is the practitioner argument against payment stated plainly by an official who has lived it, and it is worth citing in tabletop exercises where the payment decision usually gets waved through as a finance question.
The backup posture is what makes the refusal credible. Multiple outlets report the city holds an off-site backup that will be used to restore files and records once affected systems are cleared of ransomware and deemed safe. No timetable for full restoration has been given. Refusal without recoverable backups is a press release; refusal with them is a strategy.
Context matters here on two fronts. First, a naming collision worth flagging for anyone tracking this: DysruptionHub separately reported that hackers gained remote access on July 27 to the Coweta County Water and Sewerage Authority in Newnan, Georgia, an entirely different jurisdiction. In that incident, attackers reached operational technology controlling valves and pump stations via what CEO Jay Boren described to Atlanta News First as "cellular channels," changed passwords and shut down controls; operators reverted to manual control, and officials said water service, water quality and customer data were unaffected. WSB Radio reported the attackers attempted to cycle valves. That intrusion fell inside a wider pattern in which the FBI and EPA warned on July 30 that water and wastewater utilities in at least seven states had reported incidents since July 27 involving internet-facing programmable logic controllers. Two separate Cowetas, two separate incidents, and they should not be conflated.
Second, Oklahoma's regulatory floor changed this year. Amendments to the state's Security Breach Notification Act under SB 626 took effect January 1, 2026, broadening the definition of personal information, tightening notification expectations and, per Constangy's analysis, adding notice obligations to the Oklahoma Attorney General's office and the credit reporting agencies that the prior version did not require. Any Coweta notification decision will be made against that newer, stricter standard.
The Attack Technique
The initial access vector is not known. DysruptionHub and KTUL both report that contracted IT professionals, cyber insurance experts, outside cybersecurity attorneys, local police and the FBI are reviewing server logs to determine how the intrusion occurred. The incident has been reported to local and state authorities, with notification of federal authorities in progress as of August 7.
What is observable from the impact pattern: the payload propagated broadly enough to reach essentially every on-premise Windows endpoint and file store across City Hall, encrypting productivity documents and financial system data alike. That breadth is typical of an operator who obtained domain-level or broadly privileged credentials before deploying, rather than a single-host commodity infection. Common precursors in comparable small-municipality cases are exposed remote access, unpatched perimeter appliances and credential phishing, but nothing in the public record identifies which applied here. Do not build detections on the Anubis label alone until it is corroborated by more than one outlet.
What Organizations Should Do
- Verify that emergency and life-safety systems are genuinely independent of the corporate domain, including authentication. Coweta's 911, police and fire systems survived because they were off-site and separately administered. Test that assumption rather than assuming the network diagram is accurate.
- Confirm backups are off-site, offline or immutable, and restore-tested to a known clock. Coweta's refusal to pay is only viable because a usable off-site backup exists. Time a full restore of a representative file server and record the number.
- Make the payment decision before the incident. Write the position into the incident response plan with named approvers, and have counsel and the cyber insurance carrier engaged in advance, as Coweta did.
- Keep cardholder and payment processing in a segmented third-party environment. Coweta's card data was untouched because it never lived on city servers. Reduce what is on-premise so the blast radius shrinks by design.
- Ensure logging is retained off the encrypted estate. Investigators are reconstructing the intrusion from server logs; if those logs were encrypted alongside everything else, root cause becomes unknowable. Ship logs off-host with retention that outlasts dwell time.
- Small-city IT teams should map their regulatory obligations now. In Oklahoma, that means reviewing SB 626 changes effective January 1, 2026, including the expanded personal information definition and the new attorney general and credit bureau notice requirements.
- Do not assume the payment-card carve-out equals no data exposure. Enumerate what actually sits on municipal file shares, HR, court, permitting, vendor banking, and scope the forensic assessment to those repositories explicitly.
Sources: City of Coweta refuses to pay ransom after system-wide cyberattack... | City of Coweta refuses to pay ransom after system-wide cyberattack | Coweta officials share details into ransomware attack | Ransomware attack targets Coweta | Coweta, Oklahoma, ransomware shuts down city computers | Coweta Oklahoma Hit by System-Wide Ransomware Attack With Backups A... | Hackers accessed Coweta County water controls in Georgia | Oklahoma SB 626 Breach Law Changes