Coweta Ransomware Attack Locks City Computers As Officials Refuse To Pay Hackers
- mike33692

- 1 day ago
- 3 min read

Coweta Ransomware Attack Locks City Computers As Officials Refuse To Pay Hackers
A Coweta ransomware attack continues to disrupt city operations after hackers encrypted municipal computer systems earlier this week, but city leaders say they will not negotiate with the cybercriminals or pay the ransom being demanded.
The attack targeted the City of Coweta on Wednesday using a ransomware strain known as Anubis, locking files across city hall, including Word documents, Excel spreadsheets and municipal financial systems. While city employees continue working to restore operations, officials say emergency services remain fully operational and no resident payment information was compromised.
Coweta Ransomware Attack Encrypts City Hall Systems
According to the City of Coweta, the Coweta ransomware attack affected multiple internal computer systems used for daily city operations after hackers deployed the Anubis ransomware.
City Manager Julie Casteen confirmed the attackers demanded a ransom but said the city has intentionally refused to communicate with those responsible.
"They've demanded a ransom," Casteen said. "We don't know what the amount is because we're not communicating with them. We just refuse to do that."
Casteen said her decision is based on previous experience working for another municipality that paid a ransomware demand only to become the victim of another cyberattack weeks later.
"I've been through that process before with another city and we actually got reinfected two weeks after we paid the ransom," she said. "If you pay the ransom, it makes the attackers realize they can come back."
The attack encrypted local files, spreadsheets and financial records, forcing city staff to temporarily rely on backup procedures while technology specialists assess the damage.
Coweta Ransomware Attack Did Not Compromise Payment Information
Despite the disruption, city leaders stressed that resident payment information was not accessed during the Coweta ransomware attack.
Officials said utility payment processing operates on a separate cloud-based platform that was isolated from the affected municipal network.
According to guidance from the Cybersecurity and Infrastructure Security Agency (CISA), organizations hit by ransomware should immediately isolate infected systems, preserve evidence and avoid paying ransom demands whenever possible because payment does not guarantee stolen data will be recovered or future attacks prevented.
Coweta officials also confirmed that 911 dispatch, police and fire services operate on independent off-site networks and were never affected by the cyberattack.
As a result, emergency services have continued operating normally throughout the incident.
While some city computer functions remain unavailable, residents may continue paying utility bills online through Xpress Bill Pay, by check at City Hall or with assistance from city employees working onsite.
Late payment penalties and water shutoffs for nonpayment have also been temporarily suspended while systems are restored.
FBI Assisting With Cyberattack Investigation
The Coweta ransomware attack is now under investigation by contracted cybersecurity specialists, the city's cyber insurance provider, local law enforcement and the Federal Bureau of Investigation.
Investigators are reviewing server logs to determine how hackers gained access to municipal systems and whether additional security improvements are needed before the network returns to normal operations.
City officials expect to restore computer systems using an off-site backup and hope to have most municipal operations functioning again by Monday.
As part of that recovery effort, Coweta also plans to strengthen its cybersecurity by replacing traditional multi-factor authentication with passkey technology, which cybersecurity experts—including the National Institute of Standards and Technology (NIST)—have identified as a more secure method of protecting user accounts against phishing and credential theft.





Comments