OnSolve (CodeRED by Crisis24)

OnSolve (CodeRED by Crisis24)

OnSolve’s **CodeRED** platform, used by **Craven County** for public emergency alerts, suffered a **targeted cyberattack** in November by an organized cybercriminal group. The attack resulted in the **removal of user data** from the system, including **names, addresses, email addresses, phone numbers, and passwords** associated with OnSolve CodeRED profiles. While there is **no current evidence** of the data being published online, the **risk of future leaks persists**, exposing users to potential credential stuffing or identity theft if passwords were reused across accounts. The **entire OnSolve CodeRED system was decommissioned nationwide**, disrupting emergency alert services for Craven County and other municipalities relying on the platform. A **new CodeRED system** was deployed after a security audit and penetration testing, but the incident forced the county to temporarily rely on **alternative alert methods** (local media, county website, and social media). The breach was **isolated to the third-party vendor’s environment**, with no impact on Craven County’s internal systems. Users were advised to **change passwords** for any accounts sharing credentials with CodeRED profiles.

Source: https://wcti12.com/news/local/codered-platform-used-by-craven-county-alert-hit-by-cyber-attack

Emergency Communications Network cybersecurity rating report: https://www.rankiteo.com/company/emergency-communications-network-llc

"id": "EME2592825112525",
"linkid": "emergency-communications-network-llc",
"type": "Cyber Attack",
"date": "11/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Users registered for OnSolve '
                                              'CodeRED accounts (exact number '
                                              'unspecified)',
                        'industry': 'Public Administration',
                        'location': 'North Carolina, USA',
                        'name': 'Craven County',
                        'type': 'Local Government'},
                       {'customers_affected': 'Nationwide users of OnSolve '
                                              'CodeRED platform',
                        'industry': 'Emergency Notification Services',
                        'name': 'OnSolve (CodeRED by Crisis24)',
                        'type': 'Private Company (Third-Party Vendor)'}],
 'customer_advisories': ['Change passwords immediately if reused across other '
                         'accounts',
                         'Monitor for suspicious activity related to exposed '
                         'data',
                         'Use alternative communication channels (local media, '
                         'county website, social media) for emergency alerts '
                         'during transition'],
 'data_breach': {'data_exfiltration': 'Data removed from the system; no '
                                      'evidence of online publication but risk '
                                      'of future leak remains',
                 'personally_identifiable_information': ['Names',
                                                         'Addresses',
                                                         'Email addresses',
                                                         'Phone numbers',
                                                         'Passwords'],
                 'sensitivity_of_data': 'Moderate (contact information and '
                                        'passwords, but no financial or highly '
                                        'sensitive data confirmed)',
                 'type_of_data_compromised': ['Personal Identifiable '
                                              'Information (PII)']},
 'date_detected': 'November 2023',
 'date_publicly_disclosed': 'November 2023',
 'description': 'OnSolve CodeRED, a platform used by Craven County to send '
                'public emergency notifications and alerts, was targeted in a '
                'cybersecurity attack in November. User data, including names, '
                'addresses, email addresses, phone numbers, and passwords, was '
                'removed from the system. While there is no current indication '
                'that the data has been published online, the threat of a '
                'future leak remains. The OnSolve CodeRED system was '
                'decommissioned nationwide following the incident, which was '
                "isolated to the third-party vendor's system and did not "
                "affect Craven County's systems. A new platform, which has "
                'undergone a comprehensive security audit, is expected to be '
                'operational by November 28.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
                                       'data breach and system decommissioning',
            'data_compromised': ['Names',
                                 'Addresses',
                                 'Email addresses',
                                 'Phone numbers',
                                 'Passwords'],
            'downtime': 'System decommissioned; new platform expected by '
                        'November 28, 2023',
            'identity_theft_risk': 'Low (no evidence of identity theft or '
                                   'fraud, but risk remains due to exposed '
                                   'data)',
            'operational_impact': 'Emergency alert system temporarily '
                                  'unavailable; county using alternative '
                                  'communication methods (local media, county '
                                  'website, social media)',
            'systems_affected': ['OnSolve CodeRED platform']},
 'initial_access_broker': {'high_value_targets': ['OnSolve CodeRED user '
                                                  'database']},
 'investigation_status': 'Ongoing (provider investigation suggests data '
                         'limited to contact information and passwords; no '
                         'evidence of identity theft or fraud)',
 'post_incident_analysis': {'corrective_actions': ['Decommissioning of '
                                                   'compromised OnSolve '
                                                   'CodeRED platform',
                                                   'Launch of new CodeRED '
                                                   'platform with enhanced '
                                                   'security measures',
                                                   'Comprehensive security '
                                                   'audit and penetration '
                                                   'testing by external '
                                                   'experts',
                                                   'Public education on '
                                                   'password hygiene and '
                                                   'cybersecurity best '
                                                   'practices']},
 'ransomware': {'data_exfiltration': 'Data removed from the system'},
 'recommendations': ['Use unique, long, and random passwords for each account',
                     'Avoid password reuse across multiple platforms',
                     'Monitor for potential identity theft or fraud',
                     'Follow cybersecurity best practices for personal and '
                     'organizational security'],
 'references': [{'source': 'Craven County Official Statement'},
                {'source': 'CodeRED by Crisis24 FAQs'}],
 'response': {'communication_strategy': ['Public disclosure of the incident',
                                         'FAQs provided by CodeRED by Crisis24',
                                         'Advisories for users to change '
                                         'passwords',
                                         'Collaboration with Craven County '
                                         'Emergency Services for transparency'],
              'containment_measures': ['Decommissioning of OnSolve CodeRED '
                                       'platform',
                                       'Isolation of the incident to the '
                                       "third-party vendor's system"],
              'incident_response_plan_activated': True,
              'recovery_measures': ['Transition to new CodeRED platform by '
                                    'November 28, 2023',
                                    'Use of alternative communication channels '
                                    '(local media, county website, social '
                                    'media) in the interim'],
              'remediation_measures': ['Launch of new CodeRED platform on a '
                                       'non-compromised, separate environment',
                                       'Comprehensive security audit',
                                       'Penetration testing and hardening by '
                                       'external experts'],
              'third_party_assistance': ['External cybersecurity experts']},
 'stakeholder_advisories': ['Craven County Emergency Services collaboration '
                            'with CodeRED by Crisis24 for new platform',
                            'Public advisories to change passwords and use '
                            'unique credentials'],
 'threat_actor': 'Organized cybercriminal group',
 'title': 'Cybersecurity Attack on OnSolve CodeRED Emergency Alert System',
 'type': ['Data Breach', 'Cyber Attack']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.