Spokane County
Incident posture
Linked entities
- Victim
- Spokane County
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
Spokane County experienced a disruption of its emergency alert notifications after hackers compromised the Crisis24‑owned OnSolve CodeRED platform used for the ALERT Spokane program. The breach prevented county officials from logging into the system, forcing reliance on state and federal alert services for about a week while the platform was effectively destroyed and later decommissioned by the provider. Although the provider said county user data was not affected, the attackers accessed usernames, phone numbers and outdated passwords from other subscribers and posted screenshots of stolen credentials, an act linked to the INC Ransomware group. Crisis24’s initial ransom offer of one hundred thousand dollars, later increased to one hundred fifty thousand, was rejected. The county has since turned to alternative backup systems and decided to end its relationship with the provider, seeking a new vendor to restore and improve its alerting capabilities.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Last November, hackers gained access to the company that provides Spokane County's emergency alert notifications system as part of a larger cyberattack that affected local governments and first responders nationwide. Spokane County had used Crisis24's OnSolve CodeRED platform since 2017 to host its ALERT Spokane program. After the attack, county officials could not log into the CodeRED system at all. It was approximately one week before they received confirmation from OnSolve that the outage resulted from a cyberattack. The cyberattack effectively disabled the CodeRED system, leaving the Spokane area without a local option for agencies to issue emergency alerts. To maintain public messaging, Spokane County relied on the Washington State Alert and Warning Center and the Federal Integrated Public Alert and Warning System, requiring staff to call the state to send alerts on behalf of the county or responding agencies. Despite the system outage, the county reported that its ability to send emergency notifications to residents was not impacted because a backup capability was in place. Similar access problems were reported by agencies in multiple California, Colorado and Florida counties, as well as King County in Washington and Ada County in Idaho.
Crisis24 attorneys informed Deputy Director Chandra Fox that Spokane County users were not affected by the data breach. Elsewhere, the attackers accessed a small number of subscribers' usernames, phone numbers and inactive, outdated passwords that had been deactivated and changed during a 2015 platform migration. The hackers also obtained usernames linked to encrypted passwords, although the passwords themselves remained unreadable. Crisis24 subsequently released a newer iteration of the CodeRED platform described as more secure and has been working to migrate government and law enforcement partners from the legacy system. Spokane County decided not to continue its relationship with Crisis24, citing the company's unsatisfactory response to the incident. After briefing the Spokane County commissioners on the search for a new provider, the county plans to present a new contract for approval by the end of February. The attack has been linked to the INC Ransomware group, which has claimed responsibility for other high‑profile breaches such as Scotland's National Health Service, Xerox Business Solutions' U.S. offices and Yamaha Motors Philippines. INC Ransomware posted online screenshots of alleged stolen customer data, including email addresses and associated clear‑text passwords, and also shared details of the purported ransom negotiation. Crisis24 initially offered $100,000 to the attackers, later increased the offer to $150,000, and both offers were rejected.
Sources
Sources available to members: 1 source.