Full Breakdown
Cyberattack Disrupts OnSolve CodeRED Emergency Notification System
11/27/2025, 7:24:26 AM
Overview of the Cyberattack
In November 2025, the OnSolve CodeRED emergency notification system, widely used by local governments and public safety agencies across the United States, suffered a significant cyberattack attributed to the INC Ransomware group. This incident compromised the personal data of users and disrupted emergency alert services, leaving many jurisdictions unable to communicate critical information to their communities.
Impact on Emergency Services
The cyberattack led to the decommissioning of the legacy CodeRED platform, which was essential for sending alerts regarding severe weather, public safety threats, and other emergencies. Affected areas included counties in California, Colorado, North Carolina, and many others across the nation. The attack resulted in the exposure of sensitive user data, including names, addresses, email addresses, phone numbers, and passwords. Users were advised to change their passwords immediately, especially if they reused them across multiple accounts.
Key Responses from Affected Agencies
Numerous law enforcement agencies, including the Douglas County Sheriff's Office in Colorado, have terminated their contracts with CodeRED, citing concerns over user privacy and the reliability of the service. Douglas County officials expressed frustration over the lack of timely communication from Crisis24, the parent company of CodeRED, regarding the system's outages. Sheriff Darren Weekly emphasized the critical nature of the service, stating, "Had we had a major event, we would not have had the ability to reach out to our citizens."
Official Statements from Crisis24
Crisis24 confirmed the breach, stating, "We detected security vulnerabilities on November 10 and immediately suspended access to the OnSolve CodeRED platform." The company assured customers that the incident was contained within the CodeRED environment and that no other systems were affected. They are currently in the process of transitioning to a new CodeRED platform, which has undergone a comprehensive security audit to enhance its defenses.
Criticism & Opposition
The response from Crisis24 has faced scrutiny, with many agencies criticizing the company's communication and handling of the incident. The lack of immediate notification about the system's failure raised concerns about the preparedness of local governments to respond to emergencies. Critics argue that the incident highlights vulnerabilities in third-party services that support critical infrastructure.
Conflicting Reports & Gaps
While Crisis24 has stated that there is no evidence that the stolen data has been published online, some reports indicate that the INC Ransomware group has begun selling parts of the compromised data. This discrepancy raises concerns about the potential for identity theft and further exploitation of the exposed information.
What's Next for Emergency Notification Systems
In the wake of the attack, many jurisdictions are actively seeking alternative emergency notification systems. The City of University Park, Texas, and other municipalities have begun transitioning to new platforms that promise enhanced security features. Meanwhile, agencies are relying on traditional methods, such as door-to-door notifications and social media, to keep their communities informed during the outage.
Verbatim Quotes
- “In an emailed statement received Tuesday from "Communications" at Crisis24, the company said: "We detected security vulnerabilities on November 10 and immediately suspended access to the OnSolve CodeRED platform.” — Crisis24 Statement
- “immediate action to terminate our contract with CodeRED for cause. Our top priority is the privacy and protection of our citizens, which led to the decision to end our agreement with CodeRED.” — Douglas County Sheriff's Office
This cyberattack underscores the growing threat of ransomware to critical infrastructure and the urgent need for robust cybersecurity measures in emergency services.
