A ransomware attack targeted the OnSolve CodeRED emergency alert platform, operated by Crisis24, causing widespread outages for emergency notification services across numerous U.S. municipalities. The attack disrupted the ability of state, local, police, and fire agencies to send critical alerts, forcing affected regions to resort to alternative communication methods such as social media and door-to-door notifications. Municipalities including those in Colorado, Texas, Missouri, and many other states issued advisories to residents, warning of the service disruption and recommending immediate password changes for CodeRED accounts. Some municipalities, like Douglas County, Colorado, terminated their contracts with Crisis24, while others are awaiting the rollout of a new, more secure platform that Crisis24 claims is hosted in a separate, uncompromised environment.
The attackers stole user data from the CodeRED system, including names, addresses, email addresses, phone numbers, and account passwords. Crisis24 confirmed that the stolen data was published online and emphasized that no financial information was compromised, as CodeRED does not collect such data. Forensic analysis indicated the breach was contained to the CodeRED environment, with no impact on other Crisis24 systems. Municipalities and law enforcement agencies across multiple states have notified residents and advised them to change any reused passwords. Crisis24 is working to bring a new version of the emergency alert platform online, following a comprehensive security audit and additional hardening measures.

See attribution, scope, and your downstream exposure.
8 events from the most recent confirmed update back to the earliest known activity.
In the wake of the disruption and data breach, some jurisdictions, including Douglas County, Colorado, moved to terminate their CodeRED contracts and seek replacement emergency notification services. The incident prompted broader reassessment of reliance on the platform for public-safety communications.
INC Ransom publicly claimed responsibility by posting OnSolve on its leak site, sharing alleged data samples and negotiation details, and threatening to sell the stolen database if no ransom was paid. Reports said the leaked information included personally identifiable information and, in some cases, screenshots suggesting clear-text passwords.
Affected local governments, including University Park, Texas, and Cambridge, issued advisories saying CodeRED user data may have been exposed, including names, addresses, email addresses, phone numbers, and passwords. They emphasized that municipal internal systems were not impacted and urged residents to change reused passwords.
Crisis24 told customers the incident was contained to the CodeRED environment and did not affect other customer systems or the government-run Emergency Alert System. It notified law enforcement, launched a forensic investigation, and engaged external experts for security audits, penetration testing, and hardening of the replacement platform.
After determining the CodeRED environment had been damaged, Crisis24 permanently shut down or decommissioned the affected legacy platform. The company began accelerating migration to a new 'CodeRED by Crisis24' platform in a separate, non-compromised environment.
Following the ransomware attack, Crisis24's OnSolve CodeRED platform went offline or became unreliable for about two weeks, disrupting emergency notifications for towns, cities, law enforcement, and public safety agencies across the United States. Some jurisdictions resorted to social media, alternative systems, or door-to-door notifications.
INC Ransom said it encrypted files in the CodeRED environment on November 10, 2025. The attack damaged the legacy platform and contributed to a prolonged outage affecting municipal emergency notification services.
The INC ransomware group alleged it first gained access to the OnSolve CodeRED environment on November 1, 2025. This date was cited across reports as the start of the intrusion that later disrupted the emergency alert platform.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
6 references tracked. Mallory keeps watching after this page renders.
malwarebytes.com
Open sourcego.theregister.com
Open sourcesecurityaffairs.com
Open sourcetherecord.media
Open sourcescworld.com
Open sourcecyberscoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.