When Ransomware Hits Public Safety The OnSolve CodeRED Attack

In November 2025, the OnSolve CodeRED emergency-alert platform — used by hundreds of U.S. counties, cities, and law-enforcement agencies — was hit by a ransomware attack perpetrated by the INC Ransom group.

The attack disabled emergency-alert capabilities for many jurisdictions and resulted in a data breach: personal data and passwords for CodeRED users were stolen.

The vendor, parent company Crisis24 (owner of OnSolve CodeRED), decommissioned the “legacy” platform and commenced migrating customers to a newly launched “CodeRED by Crisis24” — but the forensic impact and fallout remain substantial.

For businesses, municipalities, and public-safety agencies: this is a wake-up call about vendor risk, third-party dependencies, and the need for resilient infrastructure, layered security, and incident response preparedness.

What Happened — The OnSolve CodeRED Attack Details and Timeline

Attack Overview

The OnSolve CodeRED platform was targeted by the INC Ransom ransomware group, which claims to have gained unauthorized access on November 1, 2025.

By November 10, 2025, the attackers deployed file-encrypting ransomware within the legacy CodeRED environment.

The attack resulted not only in system downtime but also in a data breach — affecting user data such as names, physical addresses, email addresses, phone numbers, and account passwords associated with legacy CodeRED user profiles.

Scope of Impact — Who and Where

The disruption affected a broad range of U.S. states including Massachusetts, Colorado, Texas, Florida, North Carolina, Ohio, Kansas, Georgia, California, Utah, Missouri, Montana, New Mexico, and many additional jurisdictions.

Several local governments, counties, and law-enforcement agencies publicly announced that their CodeRED-based alerting systems were down.

Because the attack disrupted alerting for routine AND emergency messages (floods, hazardous spills, evacuations, missing-person alerts), impacted communities were left without critical communication capabilities.

Vendor Response & Aftermath

In response, Crisis24 permanently decommissioned the legacy CodeRED platform that was under attack.

The company accelerated rollout of a new version: CodeRED by Crisis24, and began migrating all customers to the new platform.

However, since migration is based on backups dated March 31, 2025, any user registrations or profile updates made after that date may be lost or require re-registration.

The attackers publicly leaked parts of the compromised data and offered it for sale, increasing the risk of identity theft, phishing, and exploitation of personal information.

Why This Matters — Risks for Businesses, Municipalities & Citizens

1. Critical Infrastructure Dependencies Are Risky

Many municipalities treat SaaS alerting platforms as mission-critical systems. This incident demonstrates how vendor compromise creates cascading risk — where a single breach impacts entire communities.

2. People’s Safety Was at Stake — Not Just Data

This was not a typical breach of a retail or marketing platform. Public-safety systems responsible for life-saving alerts were taken offline. In a real-time emergency, this could have resulted in serious harm or fatalities.

3. Personal Data Exposure — Identity & Privacy Risk

The stolen data includes names, addresses, emails, phone numbers, and passwords. For users who reuse passwords, this poses significant risk of identity theft and further account compromise.

4. Trust & Reputation Damage

The breach has severely affected trust in the vendor and forced municipalities to reconsider partnerships or seek alternative platforms.

5. Regulatory, Compliance & Legal Risk

Failure to protect citizen data may result in investigations, legal action, fines, and liability exposure for both vendors and municipalities.

Key Lessons for Businesses

Vendor Due Diligence Is Non-Negotiable
  • Conduct thorough security assessments before using third-party vendors.

  • Demand transparency about encryption, backups, and incident response processes.

Redundancy & Backup Channels Are Essential
  • Maintain fallback alert channels such as SMS, broadcast media, manual call trees, or alternative platforms.

  • Disaster-recovery strategies must include cyber-induced outages.

Strong Identity & Access Management
  • Enforce multi-factor authentication (MFA).

  • Prevent password reuse across platforms.

  • Regularly audit and remove stale accounts.

Contractual & SLA Protections
Transitional & Hybrid Alternatives
  • Implement hybrid systems combining cloud-based and on-premise fallback solutions.

  • Maintain clean, offline backups to restore operations if vendor systems fail.

Incident Response & Communication Planning
  • Regularly test incident-response playbooks.

  • Create communication strategies to inform citizens and stakeholders during outages.

What Should Affected Organizations & Citizens Do Now?

In the aftermath of the CodeRED ransomware incident, immediate action is critical to minimize ongoing risk and prevent further exploitation of exposed data and compromised systems. Both organizations and residents who relied on the affected platform must treat this as an active security event, not a resolved issue. Proactive steps taken now — from credential resets to system audits and backup communication planning — can significantly reduce the likelihood of identity misuse, service disruption, and future cyber incidents.

  • Immediately reset any passwords used on CodeRED, especially reused ones.

  • Enable multi-factor authentication where possible.

  • Re-register on the new CodeRED by Crisis24 platform.

  • Subscribe to alternative communication channels for emergency notifications.

  • Conduct vendor-risk reviews and security audits.

Wider Implications for All U.S. Businesses

This incident reinforces a critical truth: vendor supply-chain risk can disrupt even the most vital systems. Businesses relying on third-party services for operations, data processing, and compliance must proactively manage these risks to protect continuity and reputation.

Frequently Asked Questions

Q: What is CodeRED?
A mass-notification system used by municipalities to send emergency alerts via SMS, phone, and email.

Q: Was the national emergency system affected?
No. This incident impacted CodeRED only, not national systems like FEMA’s Emergency Alert System (EAS).

Q: What data was compromised?
Names, addresses, emails, phone numbers, and passwords linked to CodeRED profiles.

Q: Has the data been leaked?
Attackers claim portions have been released or sold, though full exposure remains unclear.

Q: What actions did the vendor take?
The legacy platform was decommissioned and replaced with CodeRED by Crisis24. Users were advised to reset passwords.

Strategic Takeaways for Leaders

For leaders, this event provides a clear blueprint of what must change in how organizations approach cybersecurity and third-party risk.

Below is a detailed breakdown of the most critical strategic lessons.

1. Vendor Risk Must Be Treated as Enterprise Risk — Not an IT Issue

Most organizations still view vendor selection as primarily a procurement or operational decision. This incident proves that vendor risk is business risk.

What leaders must understand:
  • When a third-party SaaS platform fails, the organization that depends on it bears the consequences — financially, legally, and reputationally.

  • Dependency on external vendors creates single points of failure that can paralyze operations.

Strategic Actions:
Leadership Question to Ask:

“If this vendor is compromised tomorrow, what happens to our operations within 24 hours?”

2. Critical Systems Require Redundant & Fail-Safe Architecture

One of the most dangerous failures exposed by the CodeRED incident was over-reliance on a single platform for emergency communication.

What This Means for Leaders:

Mission-critical systems should never rely on a single channel or provider.

Strategic Actions:
Leadership Principle:

“Two is one. One is none.”

3. Cybersecurity Must Move Into the Boardroom

Cybersecurity should no longer be discussed only at the IT level. It affects:

  • Public safety

  • Legal exposure

  • Financial risk

  • Brand trust

  • Community confidence

Strategic Actions:
What Leaders Should Demand:

4. Design for Operational Continuity, Not Just Protection

Most cybersecurity strategy focuses on preventing breach. But modern strategy must focus on survivability during breach.

Strategic Shift:

From → “How do we stop all attacks?”
To → “How do we keep operating when attacks succeed?”

Strategic Actions:

5. Data Breach Impact Is Now Multi-Dimensional

A breach today impacts:

  • Compliance exposure

  • Citizen/customer trust

  • Litigation risk

  • Service continuity

  • Political & media fallout (for municipalities)

Strategic Actions:

6. Cyber Insurance Is Strategy — Not Backup

Cyber insurance is no longer optional.

Leadership Responsibilities:

7. Human Risk Remains the Weakest Link

Most breaches involve credential misuse, phishing, or poor password hygiene.

Leaders Must:

8. Public Trust Is a Strategic Asset

For government and public agencies, trust is everything. A failure in emergency communication erodes citizen confidence.

Strategic Actions:

9. Proactive Risk Culture Beats Reactive Recovery

Organizations that thrive aren’t those that never face attacks — they are those that are prepared.

What Leaders Should Champion:

10. Turn Crisis into Strategic Advantage

Leaders who respond proactively can turn cybersecurity into competitive and governance strength.

Strategic Opportunities:
    • Position organization as “resilient & prepared.”

    • Improve stakeholder confidence post-breach.

    • Strengthen procurement standards.

Conclusion

The CodeRED ransomware attack proves cybersecurity failures are no longer just technical issues — they endanger lives and public trust.

This event should trigger urgent action for municipalities and businesses to reassess vendor relationships, strengthen contingency plans, and adopt resilience-first security strategies.

For organizations like Synergy IT Solutions Group, this is a powerful opportunity to lead with proactive security, vendor-risk mitigation, and disaster-readiness advisory services.

Source :https://www.securityweek.com/ransomware-attack-disrupts-local-emergency-alert-system-across-us/

Leave A Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.