SYS::ONLINE
Wasteland.
Briefs1777
Issues22
SinceFeb 2026
LIVE
█ Ransomware CITY-OF-COWETA 2026-08-08

City of Coweta, Oklahoma: System-Wide Ransomware Attack

"The City of Coweta, Oklahoma, a Wagoner County municipality of roughly 11,472 residents southeast of Tulsa, confirmed on Friday, August 7, 2026 that a ransomware attack had taken all city computers, files and…"

The City of Coweta, Oklahoma, a Wagoner County municipality of roughly 11,472 residents southeast of Tulsa, confirmed on Friday, August 7, 2026 that a ransomware attack had taken all city computers, files and computer-based services offline. The city says it will not pay and will not even open a channel with the attackers. Recovery is being driven from an off-site backup. Emergency services, including 911, police and fire, were never affected because they run on separate off-site systems. All available reporting on this incident is regional broadcast press and aggregators; no vendor advisory, CERT bulletin or regulator filing has been published, and the strongest primary material is the city's own Facebook statement and on-camera remarks from City Manager Julie Casteen.

What Happened

The intrusion is dated to Wednesday, August 5, 2026. According to reporting from DysruptionHub, the city initially disclosed only a systemwide computer outage that day, saying City Hall could not process or accept transactions or issue building permits. Two days later, on Friday, officials identified ransomware as the cause and stated that it had affected all city computers, files and computer-based services except those hosted off-site.

KTUL, whose report was syndicated verbatim by National Cyber Security Consulting, describes the payload as encrypting local files, Word documents, Excel spreadsheets and municipal financial systems across City Hall. Those two sources are the only ones that name a strain, identifying it as Anubis. News On 6, KJRH and DysruptionHub do not name a family, and no researcher or vendor attribution has been published, so the Anubis identification should be treated as single-source reporting rather than confirmed attribution.

The city's published impact list, as relayed by News On 6, covers all city computers and computer files, computer-based city services, staff access to electronic records, and credit and debit card utility payments taken in person at City Hall. Services that stayed up include 911 and emergency dispatch, Coweta Police and Fire operations that depend on off-site systems such as LexisNexis, the city website, and Xpress Bill Pay, the third-party online billing portal. Residents can still pay utility bills online or by check, and the city said water service would not be disconnected while systems are down.

The refusal to pay is unusually blunt. "They've demanded a ransom," Casteen told KTUL. "We don't know what the amount is because we're not communicating with them. We just refuse to do that." She grounded the position in prior experience at another municipality: "I've been through that process before with another city and we actually got reinfected two weeks after we paid the ransom."

What Was Taken

No confirmed data theft has been reported, and no volume figure exists in any source. This is an encryption-impact incident as currently disclosed, not a confirmed exfiltration and leak-site case. No Anubis leak-site listing for Coweta has been reported by any of the sources.

Officials have been consistent and specific on one point across News On 6, KJRH, DysruptionHub and KTUL: resident credit card and other payment information is not stored on city servers and was not accessed. Casteen stated that "there has been no infiltration onto our city payment system. That is a separate system held in the cloud and we can assure you that no citizen payment information has been accessed."

That claim is narrower than it may sound. DysruptionHub reports that cybersecurity attorneys and IT specialists are still assessing what other data, if any, may have been accessed. Municipal file shares typically hold utility account records, HR and payroll files, permit and code enforcement records, court and citation data and vendor banking details, none of which are covered by the payment-card carve-out. Treat the scope of any data compromise as open until the assessment concludes.

Why It Matters

Coweta is a clean demonstration of segmentation working. Because 911 dispatch, police and fire systems and payment processing were hosted off-site and on independent infrastructure, a payload that reached "all city computers" still failed to touch life-safety services or cardholder data. For a city of about 11,000 residents with a contracted IT provider rather than a full internal security team, that architecture is the single decision that kept a bad week from becoming a public-safety event.

It is also a rare public refusal-to-pay with a named rationale from the decision maker. Casteen's reinfection anecdote is the practitioner argument against payment stated plainly by an official who has lived it, and it is worth citing in tabletop exercises where the payment decision usually gets waved through as a finance question.

The backup posture is what makes the refusal credible. Multiple outlets report the city holds an off-site backup that will be used to restore files and records once affected systems are cleared of ransomware and deemed safe. No timetable for full restoration has been given. Refusal without recoverable backups is a press release; refusal with them is a strategy.

Context matters here on two fronts. First, a naming collision worth flagging for anyone tracking this: DysruptionHub separately reported that hackers gained remote access on July 27 to the Coweta County Water and Sewerage Authority in Newnan, Georgia, an entirely different jurisdiction. In that incident, attackers reached operational technology controlling valves and pump stations via what CEO Jay Boren described to Atlanta News First as "cellular channels," changed passwords and shut down controls; operators reverted to manual control, and officials said water service, water quality and customer data were unaffected. WSB Radio reported the attackers attempted to cycle valves. That intrusion fell inside a wider pattern in which the FBI and EPA warned on July 30 that water and wastewater utilities in at least seven states had reported incidents since July 27 involving internet-facing programmable logic controllers. Two separate Cowetas, two separate incidents, and they should not be conflated.

Second, Oklahoma's regulatory floor changed this year. Amendments to the state's Security Breach Notification Act under SB 626 took effect January 1, 2026, broadening the definition of personal information, tightening notification expectations and, per Constangy's analysis, adding notice obligations to the Oklahoma Attorney General's office and the credit reporting agencies that the prior version did not require. Any Coweta notification decision will be made against that newer, stricter standard.

The Attack Technique

The initial access vector is not known. DysruptionHub and KTUL both report that contracted IT professionals, cyber insurance experts, outside cybersecurity attorneys, local police and the FBI are reviewing server logs to determine how the intrusion occurred. The incident has been reported to local and state authorities, with notification of federal authorities in progress as of August 7.

What is observable from the impact pattern: the payload propagated broadly enough to reach essentially every on-premise Windows endpoint and file store across City Hall, encrypting productivity documents and financial system data alike. That breadth is typical of an operator who obtained domain-level or broadly privileged credentials before deploying, rather than a single-host commodity infection. Common precursors in comparable small-municipality cases are exposed remote access, unpatched perimeter appliances and credential phishing, but nothing in the public record identifies which applied here. Do not build detections on the Anubis label alone until it is corroborated by more than one outlet.

What Organizations Should Do

Sources: City of Coweta refuses to pay ransom after system-wide cyberattack... | City of Coweta refuses to pay ransom after system-wide cyberattack | Coweta officials share details into ransomware attack | Ransomware attack targets Coweta | Coweta, Oklahoma, ransomware shuts down city computers | Coweta Oklahoma Hit by System-Wide Ransomware Attack With Backups A... | Hackers accessed Coweta County water controls in Georgia | Oklahoma SB 626 Breach Law Changes