City of Coweta, Oklahoma Hit by Anubis Ransomware Attack — Threadlinqs Intelligence
As of 2026-08-09, City of Coweta, Oklahoma Hit by Anubis Ransomware Attack is a high-severity ransomware threat attributed to Anubis, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 10 indicators of compromise.
Threat ID: TL-2026-1948 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: Anubis · FINANCIAL
On Wednesday, August 5, 2026, the City of Coweta, Oklahoma suffered a system-wide ransomware attack that encrypted city computer systems and files, taking most municipal services offline. One local
On Wednesday, August 5, 2026, the City of Coweta, Oklahoma suffered a system-wide ransomware attack that encrypted local files, Word documents, Excel spreadsheets, and municipal financial systems across City Hall, taking most computer-based city services offline. The City's own website and its third-party online billing portal (Xpress Bill Pay) were unaffected because they are hosted off-site, and the Coweta Police and Fire Departments continued normal operations, including 911 dispatch, because they run on separate off-site systems (e.g., LexisNexis) that were not touched. Credit card and other payment data were not stored on City servers and were confirmed not accessed. The City immediately engaged its contracted IT provider and additional third-party cybersecurity professionals, placed protective holds on municipal bank accounts, reset usernames and passwords, and reported the incident to local and state authorities with federal (FBI) reporting in process. City Manager Julie Casteen publicly confirmed the attackers demanded a ransom but that the City refused to open any line of communication with them, citing her own past experience at another municipality where paying a ransom failed to resolve the intrusion. The City confirmed it holds an offsite backup and targeted the Monday after disclosure (2026-08-10) to begin restoring systems once they are cleared of the ransomware, and separately announced plans to upgrade authentication from multi-factor authentication (MFA) to passkeys.
Only one of the outlets that broke the story, KTUL, names the ransomware strain as 'Anubis'; the DataBreaches.net, Fox23, KJRH, and NewsOn6 write-ups of the same incident do not disclose a group/strain name, and none of the five articles reviewed publish a ransom note, extension, hash, or other technical artifact tying the intrusion to a specific family. Attribution here is therefore held at MEDIUM confidence, corroborated only by KTUL's single sourcing (echoed verbatim in a Fox23 sister-outlet republish) rather than independent forensic confirmation from the City, FBI, or a named incident-response firm. Notably, open-source reporting on the Anubis operation states its operators have publicly claimed to exclude government, education, and non-profit targets from their program rules — a policy commonly violated by RaaS affiliates in practice (mirroring similar unenforced 'no hospitals/no government' pledges by groups like Conti and LockBit), but a discrepancy worth flagging rather than silently resolving.
Anubis is a Ransomware-as-a-Service (RaaS) operation first observed publicly in December 2024, evolved from an earlier prototype tracked as 'Sphinx.' Affiliates most commonly gain initial access via spear-phishing emails carrying malicious attachments or links impersonating trusted senders, and separately via abuse of exposed internet-facing remote-access services — particularly RDP — using compromised, brute-forced, or previously obtained credentials. As of mid-2026, security researchers (TechTimes, Red Secure Tech, Techzine) documented Anubis affiliates also exploiting CVE-2025-5777 ('CitrixBleed 2', a Citrix NetScaler ADC/Gateway session-token disclosure flaw) to bypass MFA and gain initial footholds at scale, and using RMM tools and the Cloudflare Tunnel client ('cloudflared') for stealthy remote access/tunneling during intrusions. None of the Coweta-specific reporting discloses which of these vectors, if any, was used against the City — the CitrixBleed 2 and cloudflared details below describe the actor's documented 2026 playbook generally, not a confirmed technical finding for this incident. Once deployed, the Anubis binary (Go-language) supports command-line flags (`/KEY=`, `/elevated`, `/PATH=`, `/PFAD=`, `/WIPEMODE`) controlling encryption scope and an optional destructive wipe mode; it checks for administrative privileges via raw disk-handle access to `\\.\PHYSICALDRIVE0` and can clone an elevated token via `CreateProcessWithTokenW`, en
Target sectors: government administration
Target regions: North America
Timeline
- A system-wide ransomware attack encrypts City of Coweta, Oklahoma computer systems and files (local files, Word/Excel documents, financial systems), taking most City Hall computer-based services offline.
- The City immediately engages its contracted IT provider and additional third-party cybersecurity professionals to secure systems and prevent further intrusion.
- The City places protective safeguards on municipal bank accounts and changes usernames and passwords for affected accounts.
- The City and local media (DataBreaches.net, KTUL, Fox23, KJRH) publicly disclose the ransomware attack, confirming an offsite backup exists and that police/fire/911 systems are unaffected.
- The City reports the incident to local and state authorities; federal reporting to the FBI is in process.
- City Manager Julie Casteen confirms attackers demanded a ransom and states the City refuses to open communication with or pay the operators; KTUL attributes the intrusion to the 'Anubis' ransomware strain.
- FBI, local police, and contracted IT professionals investigate server logs to determine the scope and origin of the intrusion.
- The City targets the following Monday (2026-08-10) to begin restoring systems and data from its offsite backup once the environment is confirmed clear of the ransomware.
- The City announces plans to upgrade authentication from multi-factor authentication (MFA) to passkeys as part of its post-incident hardening.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 10 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1566.001, T1190, T1133, T1059, T1134.002, T1078, T1112, T1110, T1005, T1572