Menu
Browse

Cyber Incident Victim: Crisis24

Date:

Nov 2025

Location:

United States of America

Summary

A cyberattack on Crisis24's legacy CodeRED platform disrupted emergency alert systems used by local governments, police, and fire agencies across the United States, impairing the ability to send timely warnings and notifications. The disruption affected multiple jurisdictions, forcing agencies to rely on alternative communication methods while the platform was restored.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On November 26, 2025, a cyberattack was reported that targeted Crisis24's legacy CodeRED platform. The attack was described as widespread and specifically aimed at the emergency communication infrastructure. The disruption affected emergency alert systems used by local governments across the United States. Police and fire agencies also experienced interruptions in their notification capabilities. The incident was documented in an article from the BSafes Library titled “OnSolve CodeRED cyberattack disrupts emergency alert systems nationwide.” The article did not disclose the identity of the attackers or the specific methods used. It also did not provide details on how the breach was detected or contained. No information was given about any data loss or theft resulting from the incident. The report focused on the operational impact to public safety communications. The scope of the disruption was characterized as nationwide.

Cyber Incident Image

Because the attack struck a legacy platform, the affected systems were those that local jurisdictions relied upon for issuing urgent alerts to the public. The interruption hindered the ability of government entities to disseminate time‑critical information during emergencies. First responders faced challenges in receiving coordinated alerts through the compromised channels. The article noted that the disruption persisted across multiple states, though it did not list the exact jurisdictions impacted. No statements were made regarding restoration timelines or remedial actions taken by Crisis24 or its partners. The source material offered no further technical details about the vulnerability exploited. Consequently, the narrative is limited to the confirmed facts of the target, the date, and the described effects on emergency communication services. The incident remains recorded as a significant event affecting public safety alerting infrastructure in the United States.

Sources
Sources available to members
1 source