The OnSolve CodeRED emergency alert platform, widely used by city, county, and state government agencies for issuing critical notifications, was shut down following a ransomware attack attributed to the Inc ransomware gang. The attackers reportedly gained access to the CodeRED environment on November 1, 2025, and encrypted platform files on November 10, leading to a full suspension of the service. Crisis24, the platform's operator, confirmed that the breach was contained to the CodeRED environment and that all customers were transitioned to a new version of the platform. The ransomware group also claimed to have stolen sensitive subscriber data and rejected a $100,000 ransom offer from Crisis24 during negotiations.
The incident caused significant disruption to emergency notification capabilities during the Thanksgiving holiday period, raising concerns about the resilience of critical public safety infrastructure. The breach and subsequent outage were widely reported in security news roundups, with additional coverage highlighting the risks to millions of users and the broader impact on government agencies' ability to communicate during emergencies. Authorities, including the French National Cybersecurity Agency (ANSSI) and the French Data Protection Authority (CNIL), were notified, and the incident has prompted renewed scrutiny of cybersecurity practices in essential service platforms.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Amid disruption and dissatisfaction with Crisis24's handling of the incident, Douglas County, Colorado terminated its contract for the CodeRED service. The move reflected customer fallout from the platform outage and breach response.
As details of the breach emerged, officials and the company warned subscribers to change reused passwords, enable MFA where available, and watch for phishing or fraudulent emergency alerts. Advisories said exposed data could include names, addresses, emails, phone numbers, and CodeRED account passwords.
After rejecting what was described as a $100,000 offer, the Inc ransomware group advertised allegedly stolen CodeRED subscriber data for sale. The data was said to include sensitive subscriber information, while GardaWorld said it believed data may have been stolen but had not confirmed the leaked samples came from CodeRED.
Following the cyberattack, GardaWorld and Crisis24 suspended access to the CodeRED emergency alert platform and ultimately decommissioned the affected environment. Government customers were told to transition to a new CodeRED environment as the company worked to contain the incident.
According to the threat actor's claims, the attackers deployed encryption in the CodeRED environment on November 10, 2025. The attack damaged the platform and contributed to its later shutdown and replacement.
The Inc ransomware group claimed it obtained initial access to Crisis24's CodeRED emergency notification platform on November 1, 2025. This marked the start of the intrusion that later led to service disruption and suspected data theft.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
malwarebytes.com
Open sourcesherpaintelligence.substack.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.