2026 City of Coweta (OK) — Anubis ransomware Aug 5; city refuses to pay (ops down)
Data compromised
Not confirmed as of city statement — incident framed as encryption/ops disruption with recovery from backup. Personal-data exfiltration not attested — recordsAffected 0.
Technical writeup
City-confirmed ransomware — Coweta, Oklahoma said that on Wednesday, August 5, 2026 it experienced a system-wide attack, contacted its IT provider and cybersecurity help, and began containment and recovery. All city computers, files and computer-based services were affected except the city website and third-party online billing portal; police and fire off-site processing systems and 911 remained available. Officials stated an offsite backup exists and will be used once systems are cleared of ransomware. No public confirmation of data theft or resident notification count at indexing — catalogued as confirmed ransomware with recordsAffected 0 pending any later breach notice. August 8 update (KTUL / DataBreaches): strain identified as Anubis; City Manager Julie Casteen said Coweta will not pay or open talks with attackers, citing prior experience of reinfection after payment at another city.
Root cause
Anubis ransomware system-wide attack August 5, 2026 encrypting city files and financial systems. City refuses to communicate or pay (manager cites prior reinfection after payment elsewhere). Offsite backups for restore; website/billing portal/911 stayed up.
References
- https://www.cityofcoweta-ok.gov/m/newsflash/home/detail/607
- https://ktul.com/news/local/city-of-coweta-hit-with-system-wide-ransomware-attack-08-07-2026
- https://databreaches.net/2026/08/07/city-of-coweta-hit-with-system-wide-ransomware-attack-has-backup/
- https://databreaches.net/2026/08/08/city-of-coweta-refuses-to-pay-ransom-after-system-wide-cyberattack/