Full Report
Risk management company Crisis24 has confirmed its OnSolve CodeRED platform suffered a cyberattack that disrupted emergency notification systems used by state and local governments, police departments, and fire agencies across the United States. [...]
Analysis Summary
# Incident Report: OnSolve CodeRED Emergency Notification System Disruption
## Executive Summary
The OnSolve CodeRED platform, used by numerous U.S. state and local government agencies for emergency notifications, suffered a cyberattack attributed to the INC Ransom gang. The incident caused significant operational disruption, forcing the decommissioning of the legacy environment. Attackers exfiltrated sensitive customer data, including names, addresses, emails, phone numbers, and user passwords, leading to an urgent need for system wide resets. Crisis24 is currently rebuilding the service from older backups, impacting the currency of available data.
## Incident Details
- **Discovery Date:** Not explicitly stated, but subsequent to the data exfiltration/encryption stages (No later than November 25, 2025).
- **Incident Date:** Initial breach allegedly occurred on November 1, 2025; Encryption occurred on November 10, 2025.
- **Affected Organization:** Crisis24 (OnSolve CodeRED platform).
- **Sector:** Government Services/Emergency Management Technology.
- **Geography:** United States (Nationwide impact on customers).
## Timeline of Events
### Initial Access
- **Date/Time:** Allegedly November 1, 2025.
- **Vector:** Unknown, exploited by the INC Ransom gang.
- **Details:** Initial unauthorized access achieved by the threat actors.
### Lateral Movement
- **Date/Time:** Occurred between November 1 and November 10, 2025.
- **Vector:** Internal system reconnaissance/movement within the CodeRED environment.
- **Details:** Not specified, but implied as necessary for data staging and encryption.
### Data Exfiltration/Impact
- **Date/Time:** Prior to November 10, 2025 (Data stolen); November 10, 2025 (Files encrypted).
- **Vector:** Data Exfiltration and Ransomware Encryption.
- **Details:** Attackers stole customer data (names, addresses, emails, phone numbers, passwords). The platform was then encrypted, necessitating decommissioning.
### Detection & Response
- **Date/Time:** Post-November 10, 2025.
- **Details:** Crisis24 detected the attack, contained it to the CodeRED environment (not affecting other systems), and confirmed data exfiltration internally. They subsequently decommissioned the legacy CodeRED environment and began rebuilding using older backups (dated March 31, 2025). INC Ransom began leaking evidence of the breach on their leak site, including clear-text passwords.
## Attack Methodology
- **Initial Access:** Unknown mechanism utilized by INC Ransom to breach the CodeRED environment.
- **Persistence:** Not explicitly detailed.
- **Privilege Escalation:** Not explicitly detailed.
- **Defense Evasion:** Not explicitly detailed, though successful in stealing data and encrypting files.
- **Credential Access:** The gang accessed and stole user profile credentials, allegedly capturing some passwords in **clear text**.
- **Discovery:** Implied internal reconnaissance steps taken to identify valuable data.
- **Lateral Movement:** Implied movement within the CodeRED environment to stage data/execute encryption.
- **Collection:** Names, addresses, email addresses, phone numbers, and passwords were collected.
- **Exfiltration:** Data was exfiltrated before the encryption phase.
- **Impact:** Data theft and denial of service via file encryption, forcing platform decommissioning.
## Impact Assessment
- **Financial:** Not specified, but likely incurred costs associated with incident response, investigation, and the complete rebuilding of the platform.
- **Data Breach:** Confirmed theft of Personal Identifiable Information (PII) and user credentials (names, physical addresses, emails, phone numbers, and passwords) for CodeRED user profiles.
- **Operational:** Widespread disruption to state and local governments, police, and fire agencies nationwide relying on the platform for emergency notifications, weather alerts, and sensitive warnings. Significant operational degradation due to reliance on outdated backups for restoration.
- **Reputational:** Significant impact due to the inability to send urgent alerts during emergencies and the public disclosure of PII theft, including clear-text passwords.
## Indicators of Compromise
- **Network Indicators:** None provided (URLs/IPs are defanged).
- **File Indicators:** None provided.
- **Behavioral Indicators:** Unusual file encryption activity on November 10, 2025; Presence of threat actors on the INC Ransom data leak site referencing OnSolve.
## Response Actions
- **Containment:** The attack was contained specifically to the CodeRED environment, with Crisis24 confirming no impact on other systems.
- **Eradication:** The legacy CodeRED environment was fully decommissioned due to system damage.
- **Recovery:** Rebuilding the service by restoring backups—however, the restorations used an older snapshot from March 31, 2025, leading to missing account data. Customers were advised to reset passwords due to clear-text leak evidence.
## Lessons Learned
- **Security Practices:** The presence of sensitive credentials (passwords) in clear text indicates critical failures in data security and encryption protocols for user profile management within the legacy environment.
- **Business Continuity:** Reliance on a single, critical notification platform created severe service disruption when compromised.
- **Data Freshness:** Restoration from significantly older backups compromises data integrity and requires significant downstream reconciliation (missing accounts).
## Recommendations
- **Immediate Credential Rotation:** Mandate immediate, universal password resets for all CodeRED users, assuming all prior passwords are compromised, especially given reports of clear-text exposure.
- **Enhanced Data Encryption:** Implement full disk/database encryption, especially for stored credentials, ensuring no sensitive data resides in clear text.
- **Platform Redundancy & Segmentation:** Ensure critical, public-safety-facing services are isolated and have highly resilient, preferably immutable, backup and failover systems to minimize outage duration.
- **Proactive Communication:** Improve customer advisory structure to clearly delineate what data was affected and provide precise steps for remediation beyond generalized warnings.