The City of Coweta, Oklahoma said a ransomware attack caused a system-wide outage across city computers, files, and computer-based services, disrupting municipal operations while leaving the city website and a third-party online billing portal accessible. Officials said the intrusion affected city systems broadly, prompting an immediate response with the city's contracted IT provider and additional cybersecurity professionals to secure the environment, contain further intrusion, and begin recovery efforts.
City officials said the Coweta Police Department and Fire Department were not affected because they operate through off-site systems, and emergency services including 911 remained operational throughout the incident. The city also said it has an offsite backup and plans to use it to restore data once systems are cleared and deemed safe for recovery.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
In its public notice, the City of Coweta said it had retained specialized legal counsel and reported the ransomware incident to local and state authorities, while federal reporting was underway. These steps were disclosed as part of the city's response to the August 5 attack.
The city issued a statement dated August 7 saying it was responding to the ransomware attack and that an offsite backup exists for restoring data once systems are cleared and safe to recover. The statement also confirmed ongoing outages to city computers, files, and computer-based services.
After discovering the attack, the city immediately contacted its contracted IT provider and brought in additional cybersecurity professionals. Their response focused on securing systems, preventing further intrusion, and beginning recovery efforts.
City of Coweta, Oklahoma said a system-wide ransomware attack occurred on Wednesday, August 5, affecting all city computers, files, and computer-based services. The city website, third-party online billing portal, and off-site police and fire systems remained unaffected, and 911 services stayed operational.
City of Coweta said it would not pay the attackers' ransom demand following the system-wide ransomware attack. The decision was reportedly influenced by the city manager's prior experience with another municipality that paid a ransom and was reinfected weeks later.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcecityofcoweta-ok.gov
Open sourcemalware.news
Open sourcedysruptionhub.com
Open sourcemalware.news
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.