Drooid Logo
Back to story perspectives

Full Breakdown

Nationwide Cyberattack on CodeRED Emergency Notification System

11/28/2025, 3:33:22 AM

Overview of the Cyberattack

A significant cybersecurity incident has targeted the OnSolve CodeRED emergency notification system, affecting municipalities across the United States. The attack, attributed to the INC Ransom group, has compromised personal data and disrupted the ability of local governments to send critical alerts regarding severe weather, public safety threats, and other emergencies. The CodeRED platform, which is utilized by various cities and counties to deliver timely notifications, has been rendered inoperable, prompting officials to advise users to change their passwords immediately.

Impact on Emergency Notification Systems

The breach has led to the exposure of sensitive user information, including names, addresses, email addresses, phone numbers, and passwords. Cities such as Sumner, Harrisburg, and Cambridge have reported the incident, emphasizing that while their internal systems remain secure, the CodeRED platform's vulnerability has raised concerns about potential identity theft. Crisis24, the company managing CodeRED, confirmed that the data was published online following the attack, although they stated there was no evidence that the information had been leaked publicly.

Official Responses and Recommendations

Local authorities have issued urgent advisories for residents to change their passwords, particularly if they have reused them across different accounts. The City of Cambridge noted that users cannot manually change their passwords until access to the new platform is restored. The Rhode Island Emergency Management Agency reassured the public that their additional alert systems remain operational and that no healthcare or financial information was compromised.

Criticism and Concerns

Critics have pointed out the apparent negligence in how CodeRED stored user data, particularly the use of clear-text passwords, which poses a significant risk when such systems are breached. Ed Carroll, Director of the Carolina Cyber Center, remarked on the predictable nature of cybercriminals targeting large companies like OnSolve, which are under pressure to pay ransoms to regain control of their platforms. This incident has led to some municipalities, including Douglas County, Colorado, terminating their contracts with CodeRED.

Conflicting Reports and Gaps

While Crisis24 has acknowledged the breach and the potential exposure of user data, there are discrepancies regarding the extent of the data compromised. Some reports suggest that the breach was contained within the CodeRED environment, while others indicate that the stolen data may have been posted online. The full scope of the attack and its long-term implications for affected municipalities remain unclear.

What's Next for Affected Communities

In response to the breach, many municipalities are exploring alternative notification systems to ensure continued communication with residents during emergencies. Buncombe County, for instance, is actively seeking to contract with another company while working with OnSolve to restore their alert capabilities. As the situation develops, local governments are expected to provide further updates and guidance to their communities.

Verbatim Quotes

  • “We confirm that data potentially associated with the legacy OnSolve CodeRED platform has been published online following a targeted attack by an organized cybercriminal group. The attack also resulted in damage to the OnSolve CodeRED environment,” — Crisis24
  • “Unfortunately, I think going forward in the future, this is something that we’re just going to have to learn to live with,” — Derick Wenck, Mayor of Harrisburg
  • “Just recently, we sent an alert on the fires that were on the Blue Ridge Parkway,” — Lillian Govus, Buncombe County Spokeswoman
  • “The only information stored in the CodeRED alert system is potentially the name, address, email addresses, phone numbers, and passwords of users who signed up to receive these alerts,” — Rhode Island Emergency Management Agency

This incident underscores the vulnerabilities inherent in digital communication systems and the critical need for robust cybersecurity measures to protect sensitive information.