The Cheyenne and Arapaho Tribes (a federally recognized tribal government headquartered in Concho, Oklahoma) reported a ransomware incident that forced shutdown of tribal computer networks and disrupted critical services, including email and phone systems, with the impact extending to tribal operations and schools. Tribal officials said the intrusion activity was detected in early December 2025, systems were taken offline as part of containment, and recovery proceeded with support from an insurance provider and involvement from federal authorities; the tribal governor publicly stated the tribe did not negotiate or pay.
The Rhysida ransomware group subsequently claimed responsibility and listed the tribe on its leak/auction site, demanding 10 BTC (reported as roughly $660,000) in exchange for not releasing allegedly stolen data. Reporting noted that while Rhysida’s listing set a 10 BTC price and an auction countdown, it did not clearly provide proof of data theft in the public post, and attribution was not uniformly confirmed by authorities at the time of publication; however, Rhysida publicly took credit and threatened data leakage as part of the extortion attempt.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Governor Reggie Wassana publicly said the tribe would not negotiate with or pay the attackers, describing the incident as a 'terrorist attack.' He also confirmed that the tribes had been targeted and that recovery work was underway.
The Rhysida ransomware group listed the Cheyenne and Arapaho Tribes on its leak or auction site, demanding 10 bitcoin to prevent release of allegedly stolen data. Reports said the posting included a six-day countdown but no proof of compromise or details on the data.
As the tribes worked to restore systems, they involved federal authorities in the investigation and coordinated recovery with their insurance provider. Tribal leadership said response and recovery efforts were ongoing.
Operational impacts from the ransomware incident persisted into January, with schools and government services still affected. The Department of Education reported outages and said students would not be penalized for assignment delays caused by the disruption.
Following the intrusion, tribal officials shut down computer networks to contain the incident, disrupting email, phone, internet, schools, and other critical systems. Some tribal operations were temporarily suspended while recovery began.
The Cheyenne and Arapaho Tribes in Oklahoma first detected intrusion activity tied to a ransomware incident on December 8, 2025. Officials described it as an attempted infiltration that led to an immediate response.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetherecord.media
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.