Crisis24 CodeRED Cyberattack Rocks US Emergency Alert Systems

Listen to this Post

Featured Image

Introduction

When an emergency alert system fails, entire communities are left exposed. That is exactly what happened when Crisis24 confirmed that its OnSolve CodeRED platform, a critical lifeline for state and local governments, police departments, and fire agencies across the United States, was hit by a damaging cyberattack. The breach forced the shutdown of legacy systems, disrupted emergency alerts nationwide, and exposed sensitive customer data. What unfolded next revealed just how vulnerable the nation’s emergency communication infrastructure has become.

Summary of the Original

The cyberattack against Crisis24’s CodeRED platform triggered a nationwide disruption, affecting emergency notification systems used for weather alerts, public warnings, and police and fire department communications. CodeRED is a vital service that enables government entities to send urgent alerts to residents, ranging from severe weather warnings to public safety notices.

Crisis24 confirmed that the attack targeted only the CodeRED environment. Their internal investigation found no evidence that other Crisis24 systems were compromised. However, they acknowledged that data was stolen during the incident. The exposed information includes names, physical addresses, email addresses, phone numbers, and passwords associated with CodeRED user accounts. Despite the severity of the breach, Crisis24 stated there is currently no indication that the stolen data has been publicly posted online.

Cities such as University Park, Texas, notified residents that data theft was confirmed, even if it has not surfaced publicly. Because the cyberattack damaged the platform, Crisis24 began rebuilding CodeRED from backups. The available backup dates back to March 31, 2025, which means many accounts created after that date will be missing from the restored system.

Across the country, counties and public safety agencies reported service disruptions and urged residents to remain aware while systems were being rebuilt.

Behind the scenes, the INC Ransom gang claimed responsibility. Although Crisis24 described the attackers as an organized cybercriminal group, BleepingComputer discovered that INC Ransom added OnSolve to its data leak site. They published screenshots showing stolen customer data, including clear text passwords, and claimed to have breached the system on November 1, 2025. The gang alleges that it encrypted files on November 10, but after receiving no ransom payment, it began selling the stolen data.

Customers are strongly advised to reset any passwords used on CodeRED, especially if the same credentials were used elsewhere.

INC Ransom, a ransomware-as-a-service operation launched in July 2023, has targeted high-profile organizations worldwide. Its victim list includes healthcare providers, educational institutions, government agencies, and major corporations like Yamaha Motor Philippines, Scotland’s National Health Service, Ahold Delhaize, and Xerox Business Solutions in the United States.

The cyberattack highlights the growing threat against critical infrastructure and the devastating consequences of credential leaks, data theft, and system outages in emergency services.

What Undercode Say:

The attack on Crisis24’s CodeRED platform underscores a critical truth about modern infrastructure. Emergency communications are no longer just phone trees and radio systems. They rely on interconnected digital platforms that must balance speed, reliability, and security. When that balance fails, public safety is at risk.

The stolen dataset is especially concerning because it contains clear text passwords. Modern systems should never store credentials without hashing and salting them. If these passwords were reused across multiple services, attackers could pivot to private accounts, government portals, or even enterprise systems.

The restoration from a March 31 backup reveals a deeper operational issue. A nearly eight-month backup gap suggests serious weaknesses in disaster recovery planning. Emergency alert systems should have redundant, real-time recovery mechanisms. The fact that entire user accounts will be missing shows how unprepared the platform was for a complete environment failure.

INC Ransom’s involvement is a red flag for organizations that rely on legacy systems. This group has escalated its attacks consistently since 2023, and its choice of targets shows a preference for entities with widespread operational dependence. CodeRED fits that criteria perfectly. A single outage impacts hundreds of governments and millions of citizens.

Another disturbing element is the use of screenshots containing clear text passwords. That indicates a possible breach of a database that stored unencrypted credentials or logs where passwords were captured improperly. For a platform trusted with emergency communications, this is an unacceptable security posture.

Rebuilding CodeRED in a new environment is the correct decision, but the process will likely take time. Agencies relying on the platform must revalidate their user lists, rebuild notification groups, and ensure new credentials are securely generated. Until then, their alerting capabilities remain weaker than before the attack.

The broader implication is clear. Cybercriminals are shifting toward high-impact targets where downtime has real-world consequences. The CodeRED incident should serve as a national wake-up call. Emergency systems need continuous monitoring, encrypted credential storage, zero-trust design, and rapid failover capabilities. Without these, a single breach can silence the very alerts meant to protect the public.

🔍 Fact Checker Results

INC Ransom gang has publicly claimed responsibility for the attack. ✅

Clear text passwords were shown in leaked screenshots from attackers. ✅

Crisis24 confirmed data theft but found no evidence of public data posting so far. ❌

📊 Prediction

Emergency alert systems will face increased targeting from ransomware groups in the next 12 months. 🔥
Governments will accelerate modernization of notification platforms, prioritizing encryption, redundancy, and zero-trust frameworks. 🔐
INC Ransom’s success here will encourage other RaaS groups to pursue more critical infrastructure operators. ⚠️

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: www.bleepingcomputer.com
Extra Source Hub (Possible Sources for article):
https://www.quora.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon