The City of Coweta, Oklahoma, a Wagoner County suburb southeast of Tulsa with an estimated 2025 population of 11,472, has confirmed a systemwide ransomware attack that began Aug. 5, 2026 and took down every city computer, file and computer-based service. According to the city's own news release, quoted across local and trade coverage, only two things stayed up: the city website and a third-party online billing portal (identified by Undercode News as Xpress Bill Pay). Emergency services, including 911 dispatch, police and fire, ran on separate off-site networks and were never interrupted. City Manager Julie Casteen has publicly refused to negotiate or pay, and the investigation into what data may have been accessed was still open as of Aug. 11.
What Happened
The timeline that emerges across the sources is consistent, though the city's disclosure came in two stages. On Wednesday, Aug. 5, Coweta first announced a systemwide computer outage, telling residents that City Hall could not process or accept transactions or issue building permits. Two days later, on Friday, Aug. 7, officials identified the cause as ransomware in a Facebook post and news release, saying the attack had hit all city computers, files and computer-based services except systems hosted off-site.
Fox23 and Radio Oklahoma News both report the strain as Anubis, and both describe the same impact set: encrypted local files, Word documents, Excel spreadsheets and municipal financial systems across city hall. No source in this set attributes the attack to a named affiliate or crew, and no ransomware leak-site listing has been reported.
The city said it immediately engaged its contracted IT provider plus additional cybersecurity professionals to secure systems, prevent further intrusion and begin recovery, with outside cybersecurity attorneys also assisting. Dysruption Hub reports the incident was disclosed to local and state authorities with federal notification in progress; Fox23 reports contracted IT professionals, cyber insurance experts, local police and the FBI reviewing servers. Casteen told the Tulsa World the FBI has been contacted, adding a blunt assessment of what she expects from it: "I think they might be able to figure out how it was done, but not who did it."
On the ransom, the sources are close but not identical, and the difference is worth preserving. Fox23 and Radio Oklahoma News both quote Casteen saying "They've demanded a ransom. We don't know what the amount is because we're not communicating with them. We just refuse to do that." The Tulsa World account, published Aug. 11, renders it as no specific amount having been demanded. Either way, no dollar figure is on the record. Casteen grounded the refusal in direct experience: she says a prior municipality she worked for paid a ransom and was reinfected two weeks later.
Recovery expectations also differ by source and by date. Dysruption Hub, reporting Aug. 7, said the city gave no timetable for full restoration and would rebuild from an off-site backup only after affected systems were cleared of ransomware and deemed safe. Kobaran's Aug. 9 write-up frames it as a vow of full recovery by Monday. By Aug. 11, Casteen told the Tulsa World the incident "should mostly be resolved within the next few days." The honest read: the initial optimistic estimate slipped, which is the normal shape of a municipal ransomware recovery.
What Was Taken
Nothing has been confirmed stolen. That is a meaningfully different statement from nothing was stolen, and the city has been careful about the distinction.
What the city asserts affirmatively: credit card and other payment data are not kept on city servers and were not accessed in this attack. Fox23 reports payment processing runs on an independent cloud service that was not touched, quoting the city that "there has been no infiltration onto our city payment system." Casteen separately told the Tulsa World there has been no financial loss for anyone with utility payments, and that the city itself has suffered no financial loss she is aware of.
What remains open: the city's own release states that it is "working with outside cybersecurity attorneys and IT experts to recover our systems and assess what other data, if any, was accessed." As of the most recent reporting on Aug. 11, that assessment had not concluded. A full municipal file environment plausibly holds employee records, permits, court and code enforcement records, vendor data and internal correspondence, so the exposure question is live even with card data ruled out.
This matters legally. Oklahoma's Security Breach Notification Act, passed by state lawmakers in 2025, requires companies, schools and state agencies to notify the attorney general when a cyberattack breaches the personal data of at least 500 Oklahomans, and to adopt "reasonable safeguards," with civil penalties available for failure. The Oklahoman reported on Aug. 11 that as of July 30, only three entities had filed: Jenks Public Schools, Gordon Cooper Technology Center and the University of Phoenix. Coweta is not among them, which is expected given the attack postdates that cutoff. Whether Coweta files will depend on the outcome of the ongoing data assessment. Cyber experts quoted by The Oklahoman believe several breaches have already gone unreported by Oklahoma entities, so the filing is worth tracking as a signal.
Why It Matters
Coweta is a clean case study in the two-tier reality of small-government IT. The parts of the environment that survived were the parts that were not on the city's own network: the website, the third-party billing portal, and the off-site 911, police and fire systems. Everything the city ran itself was encrypted. That is not a compliment to the city's architecture so much as an accident of outsourcing, but it is the single most important defensive lesson here, and it generalizes.
Second, this is a municipality of roughly 11,500 people whose population grew 18.3 percent since 2020, from 9,696 to 11,472. Small cities in growth corridors accumulate digital service obligations, permits, utility billing, court records, faster than they accumulate security budget or staff. Coweta had no in-house security team to call; it had a contracted IT provider and had to surge in outside specialists, attorneys and insurers after the fact.
Third, the refusal to pay is worth noting as a data point in a sector where paying is still common. Coweta declined even to open a channel with the operators, and its stated reason is operational rather than ideological: payment invites a repeat visit. Backups made that stance affordable. The city said it will restore from an off-site backup once systems are cleared. Refusal without a tested backup is not a policy, it is a bet.
The Attack Technique
Initial access has not been disclosed and appears to be an open question in the investigation. Casteen's own comment about the FBI suggests the city expects to learn how, not who.
The one behavioral detail on the record comes from the Tulsa World, and it is unusual enough to flag while attributing it clearly. Casteen described the ransom being conveyed through a city employee who was typing an email "and then someone else just came in (through the computer) ... and started typing for her." In her words: "It was like there was someone else there, typing." That description is consistent with a hands-on-keyboard operator using a remote access tool or hijacked remote session rather than a purely automated payload drop, which would fit a human-operated intrusion pattern. It is a single-source account from a non-technical official, so treat it as a lead rather than a finding.
The Anubis attribution comes from Fox23 and Radio Oklahoma News. Both describe encryption of local files, Office documents and financial systems across city hall. Neither the city release nor the other coverage names a strain, so the identification rests on those two reports.
The blast radius itself is the most technically instructive element: encryption reached across departments and file shares rather than isolating to one workstation, which points to credentialed lateral movement and a flat internal network with broadly reachable file storage.
What Organizations Should Do
-
Segment the life-critical systems off the corporate network, permanently. Coweta's 911, police and fire systems survived because they live on separate off-site networks. Verify that public safety, SCADA and utility control environments share no domain, no credential store and no flat routing with general office IT, then test that assumption with an actual path-finding exercise rather than a network diagram.
-
Keep off-site, offline, immutable backups and prove you can restore from them. Coweta's ability to refuse the ransom rests entirely on an off-site backup it intends to use once systems are cleared. Run a timed restore drill on your most business-critical file share and financial system this quarter, and record the actual hours it takes.
-
Harden and monitor remote access. Given the reported hands-on-keyboard behavior, inventory every remote access and remote support tool in the environment, including whatever your contracted IT provider uses. Enforce phishing-resistant MFA on all of it, restrict it to allowlisted sources, and alert on any RMM or remote desktop binary executing outside the approved set.
-
Push sensitive data off systems you cannot defend. Coweta's strongest position in this incident is that cardholder data was never on city servers. Apply the same logic to whatever else you hold: if a third party can process it under contract with real security obligations, that is one less encrypted, exfiltrated file set.
-
Write the notification decision tree before you need it. Oklahoma's 2025 Security Breach Notification Act triggers at 500 affected residents and carries civil penalty exposure for inadequate safeguards, and only three entities had filed as of July 30. Know your state's threshold, your clock, who signs, and how you will count affected individuals when your file servers are the thing that is encrypted.
-
Pre-retain counsel, forensics and insurance contacts now. Coweta had to engage outside cybersecurity attorneys, additional cybersecurity professionals and cyber insurance experts after the fact. Small governments and small businesses should have those retainers signed and the phone numbers stored somewhere that is not on the network that just got encrypted.
Sources: Coweta, Okla., Confronts Systemwide Ransomware Attack | Coweta Ransomware Attack Locks City Computers As Officials Refuse T... | City of Coweta refuses to pay ransom after system-wide ... | Oklahoma law requires data breaches to be disclosed. Is ... | Ransomware attack targets Coweta | Coweta, Oklahoma, ransomware shuts down city computers | City of Coweta Hit by Ransomware: Oklahoma Community Faces Major Di... | Coweta Cyberattack: City Refuses Ransom, Vows Full Recovery by Monday