Ktul Ransomware Attack Disrupts City of Coweta Operations
Article Content
- •City of Coweta hit by a ransomware attack on August 5, 2026, affecting most computer systems.
- •Emergency services remain operational; online bill payments via third-party service are safe.
- •City officials are collaborating with cybersecurity experts to recover systems and assess data access.
On August 5, 2026, the City of Coweta experienced a system-wide ransomware attack that took most city computer systems offline. The attack affected all city computers and services, except for the city website and third-party online billing portal. City officials immediately contacted their IT provider and cybersecurity professionals to secure systems and initiate recovery efforts. Emergency services, including 911, remained operational as they utilize off-site servers. The city has an offsite backup of data that will be used for restoration once systems are cleared. Residents can still make payments through Xpress Bill Pay, a third-party service not affected by the attack. In-person credit or debit card payments at City Hall are currently unavailable, but check payments are accepted. City officials are working with cybersecurity attorneys and IT experts to assess the situation and report it to local and federal authorities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Anubis and City Of Coweta in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Ransomware Attack on Hudson MD Group by Metaencryptor On September 21, 2026, Hudson MD Group, a physician-owned medical organization in New Jersey, experienced a ransomware attack attributed to the hacker group Metaencryptor. The attack was reported on dark web monitoring site Ransomware.live, indicating that sensitive data may have been compromised. Hudson MD Group…
Multiple Ransomware Attacks Target Companies in September 2026 On September 15, 2026, the ransomware group ShadowByt3$ claimed to have compromised HandyTrac, a company in Greystar Litchfield Park, AZ, alleging access to sensitive data including employee credentials and financial records. The group demanded negotiation within 72 hours to avoid publishing the data. On the same day…