All incidents

Ransomware attack on City of Coweta, Oklahoma

malwareopenAug 7, 2026 — Aug 8, 2026

THE City of Coweta in Oklahoma confirmed a ransomware infection that began on 5 August 2026, encrypting municipal computers and financial systems while officials said they would not meet any ransom demand (source).

The malware involved has been identified as the Anubis strain, which locked down workstations across the city network but left the public website and third‑party billing portal untouched because they run on separate infrastructure (source).

Emergency services including 911 remained operational as police and fire departments rely on off‑site servers, and the city said it possessed an offline backup that will be used to restore data once the environment is declared clean.

City Manager Julie Casteen explained that the refusal to pay follows a previous incident where payment resulted in reinfection, and the administration has chosen not to open a dialogue with the attackers to ascertain a ransom amount.

No CVE has been linked to the Anubis variant in this case and no specific threat actor has been attributed, though the ransomware was active from the first sighting on 7 August 2026 to the last observed activity on 8 August 2026.

For other organisations, the Coweta case underlines the value of maintaining segregated, offline backups, separating public‑facing services from internal networks and regularly testing restoration procedures to avoid dependence on decryption keys.

Intelligence briefing updated Aug 8, 2026

Timeline Coverage

Swipe to explore timeline