Drooid Logo
Back to story perspectives

Full Breakdown

Cyberattack Disrupts OnSolve CodeRED Emergency Notification System

11/26/2025, 9:47:44 PM

Overview of the Cyberattack

In November 2025, the OnSolve CodeRED emergency notification system, utilized by various state and local agencies across the United States, suffered a significant cyberattack attributed to an organized cybercriminal group known as the INC Ransomware gang. This incident led to the unauthorized access and potential compromise of sensitive user data, including names, addresses, email addresses, phone numbers, and passwords associated with CodeRED accounts. The attack resulted in widespread disruptions to emergency alert services in multiple counties, including Douglas, Weld, and Park in Colorado, as well as agencies in California and North Carolina.

Impact on Emergency Services

The cyberattack initiated on November 10, 2025, caused immediate outages in the CodeRED system, preventing law enforcement and emergency services from sending critical alerts to residents. For instance, the Douglas County Sheriff's Office reported difficulties accessing the system while attempting to notify citizens about a controlled burn. The failure to communicate effectively during emergencies raised concerns about public safety, prompting several agencies to terminate their contracts with CodeRED and seek alternative notification systems.

Official Responses and Actions Taken

Crisis24, the parent company of OnSolve CodeRED, confirmed the breach and stated that while no evidence suggested the stolen data had been published online, users should change their passwords immediately, especially if reused across other accounts. The company has since decommissioned the legacy CodeRED platform and is migrating customers to a new, more secure system. Douglas County officials emphasized their commitment to protecting residents' privacy, stating, "Our top priority is the privacy and protection of our citizens," as they explored new emergency alert solutions.

Criticism and Opposition

The incident has drawn criticism from various law enforcement agencies, particularly regarding the lack of timely communication from Crisis24 about the system's status. Douglas County Sheriff Darren Weekly expressed frustration, noting that they were not informed of the system's failure until they attempted to use it. This breakdown of trust has led to a reevaluation of contracts with CodeRED among several agencies, including the Thornton Police Department and Weld County.

Conflicting Reports and Gaps

While Crisis24 has assured that the breach was contained within the CodeRED environment and did not affect other systems, some agencies reported that the attack's impact was more extensive than initially communicated. The INC Ransomware gang claimed responsibility for the attack, stating that they had encrypted files and intended to sell the stolen data, raising concerns about the potential for future data exploitation.

What's Next for Affected Agencies

In the aftermath of the cyberattack, affected agencies are actively seeking new emergency alert systems to replace CodeRED. The transition to new platforms is expected to take several weeks, during which agencies will rely on traditional communication methods, such as door-to-door notifications and social media, to keep residents informed. As agencies work to restore their emergency alert capabilities, the incident underscores the growing need for robust cybersecurity measures in public safety systems.

Verbatim Quotes

  • “Our top priority is the privacy and protection of our citizens, which led to the decision to end our agreement with CodeRed," said a statement from Douglas County.” — Douglas County Sheriff's Office
  • “This is a tool that we utilize often.” — Taylor Davis, Douglas County Sheriff Division Chief
  • “We have learned that data associated with the legacy OnSolve CodeRed platform was removed from our systems.” — Crisis24 Statement
  • “In an emailed statement received Tuesday from "Communications" at Crisis24, the company said: "We detected security vulnerabilities on November 10 and immediately suspended access to the OnSolve CodeRED platform.” — Crisis24 Statement

This incident highlights the vulnerabilities in emergency notification systems and the critical importance of maintaining trust and security in public safety communications.