Oklahoma’s New Cybersecurity Breach Law Reveals Gaps in Reporting as Attacks Surge
Oklahoma’s Security Breach Notification Act, enacted in 2025, requires businesses, schools, and state agencies to report cyberattacks exposing the personal data of at least 500 Oklahomans to the Attorney General’s Office. The law also mandates "reasonable safeguards" to protect sensitive information, with civil penalties for non-compliance. As of July 30, only three entities Jenks Public Schools, Gordon Cooper Technology Center, and the University of Phoenix had formally reported breaches under the new statute.
The University of Phoenix disclosed a November 2025 breach, predating the law, in which hackers accessed student data, including bank account numbers, via a third-party software vulnerability. Meanwhile, Jenks Public Schools and Gordon Cooper Technology Center reported an April attack on the Canvas learning platform by the hacking group ShinyHunters, which claimed to have compromised data from over 275 million individuals across nearly 9,000 schools globally, including dozens in Oklahoma.
Despite these reports, cybersecurity experts suspect underreporting. Ron Vaughn of Emsco Solution identified at least 17 cyberattacks in Oklahoma this year based on public records, suggesting many incidents may have gone unreported. The FBI’s 2025 Internet Crime Complaint Center report noted a 26% increase in cybercrime-related losses, totaling nearly $21 billion for U.S. residents, with threats expected to escalate alongside advancements in artificial intelligence.
Recent incidents highlight the law’s challenges. In August, the city of Coweta disclosed a ransomware attack but did not specify the demanded amount. The Oklahoma Tax Commission’s April breach, which exposed personal data through the OKTAP tax portal, was also not reported to the Attorney General. Similarly, the Oklahoma Manufacturing Alliance (OMA) suffered a July ransomware attack by the Booba Project group, which threatened to publish or auction stolen data. OMA did not report the incident, citing no exposure of personal client information, though it acknowledged the attack as a reminder of cybersecurity’s critical role.
The law, backed by bipartisan support, aims to centralize breach reporting for better threat tracking. However, critics like Sen. David Bullard (R-Durant) argued it could unfairly penalize businesses for security lapses. Co-author Sen. Brent Howard (R-Altus) countered that the goal was not punishment but establishing a system to identify industry-wide vulnerabilities. Oklahoma joins over half of U.S. states with similar "reasonable security" requirements, reflecting a growing national effort to address escalating cyber threats.
Jenks Public Schools cybersecurity rating report: https://www.rankiteo.com/company/jenks-public-schools
Oklahoma Attorney General's Office cybersecurity rating report: https://www.rankiteo.com/company/oklahoma-attorney-general's-office
Gordon Cooper Technology Center cybersecurity rating report: https://www.rankiteo.com/company/gordon-cooper-technology-center
"id": "JENOKLGOR1786445491",
"linkid": "jenks-public-schools, oklahoma-attorney-general's-office, gordon-cooper-technology-center",
"type": "Cyber Attack",
"date": "4/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Unknown (part of 275M globally)',
'industry': 'Education',
'location': 'Oklahoma, USA',
'name': 'Jenks Public Schools',
'type': 'Educational Institution'},
{'customers_affected': 'Unknown (part of 275M globally)',
'industry': 'Education',
'location': 'Oklahoma, USA',
'name': 'Gordon Cooper Technology Center',
'type': 'Educational Institution'},
{'customers_affected': 'Students (bank account numbers '
'exposed)',
'industry': 'Higher Education',
'location': 'Oklahoma, USA',
'name': 'University of Phoenix',
'type': 'Educational Institution'},
{'industry': 'Public Sector',
'location': 'Oklahoma, USA',
'name': 'City of Coweta',
'type': 'Government'},
{'customers_affected': 'Taxpayers (personal data '
'exposed)',
'industry': 'Public Sector',
'location': 'Oklahoma, USA',
'name': 'Oklahoma Tax Commission',
'type': 'Government Agency'},
{'customers_affected': 'Clients (data potentially '
'exposed)',
'industry': 'Manufacturing',
'location': 'Oklahoma, USA',
'name': 'Oklahoma Manufacturing Alliance (OMA)',
'type': 'Non-Profit/Industry Association'}],
'attack_vector': ['Third-party software vulnerability',
'Exploited learning platform vulnerability'],
'data_breach': {'data_exfiltration': ['Yes (ShinyHunters, Booba Project)'],
'number_of_records_exposed': '275M globally (including '
'Oklahoma entities)',
'personally_identifiable_information': ['Yes (student and '
'taxpayer data)'],
'sensitivity_of_data': 'High (PII, financial data)',
'type_of_data_compromised': ['Student data',
'Bank account numbers',
'Taxpayer data',
'Client data']},
'date_publicly_disclosed': '2025-07-30',
'description': 'Oklahoma’s Security Breach Notification Act, enacted in 2025, '
'requires entities to report cyberattacks exposing personal '
'data of at least 500 Oklahomans. Multiple breaches have been '
'reported, but underreporting is suspected. Key incidents '
'include attacks on Jenks Public Schools, Gordon Cooper '
'Technology Center, University of Phoenix, the city of Coweta, '
'Oklahoma Tax Commission, and Oklahoma Manufacturing Alliance.',
'impact': {'brand_reputation_impact': ['University of Phoenix',
'Jenks Public Schools',
'Gordon Cooper Technology Center',
'Oklahoma Tax Commission',
'Oklahoma Manufacturing Alliance'],
'data_compromised': ['Student data (bank account numbers, personal '
'information)',
'Taxpayer data (Oklahoma Tax Commission)',
'Client data (Oklahoma Manufacturing '
'Alliance)'],
'identity_theft_risk': ['High (student and taxpayer data exposed)'],
'operational_impact': ['Disruption to educational services (Jenks '
'Public Schools, Gordon Cooper Technology '
'Center)',
'Tax portal downtime (Oklahoma Tax '
'Commission)',
'Manufacturing alliance operations '
'disrupted'],
'payment_information_risk': ['High (bank account numbers exposed)'],
'systems_affected': ['Canvas learning platform',
'OKTAP tax portal',
'Oklahoma Manufacturing Alliance systems']},
'initial_access_broker': {'data_sold_on_dark_web': ['ShinyHunters claimed to '
'have compromised data '
'from 275M individuals']},
'investigation_status': 'Ongoing (underreporting suspected)',
'lessons_learned': 'Underreporting of cyber incidents remains a challenge '
'despite new legislation. Third-party vulnerabilities and '
'ransomware threats are escalating, requiring stronger '
'safeguards and centralized reporting mechanisms.',
'motivation': ['Data exfiltration', 'Financial gain', 'Extortion'],
'post_incident_analysis': {'corrective_actions': ['Strengthen vendor risk '
'management',
'Implement mandatory breach '
'reporting',
'Enhance ransomware '
'preparedness'],
'root_causes': ['Third-party software '
'vulnerabilities',
'Inadequate security safeguards',
'Lack of centralized reporting '
'enforcement']},
'ransomware': {'data_encryption': ['Yes (Oklahoma Manufacturing Alliance)'],
'data_exfiltration': ['Yes (Booba Project threatened to '
'publish/auction data)']},
'recommendations': ['Enhance third-party vendor security assessments',
'Improve incident reporting compliance across all sectors',
'Strengthen ransomware defenses and data encryption',
'Increase public-private collaboration for threat '
'intelligence sharing'],
'references': [{'source': 'Oklahoma Security Breach Notification Act'},
{'source': 'FBI Internet Crime Complaint Center (IC3) 2025 '
'Report'},
{'source': 'Emsco Solution (Ron Vaughn)'}],
'regulatory_compliance': {'regulations_violated': ['Oklahoma Security Breach '
'Notification Act '
'(potential non-compliance '
'by Coweta, Oklahoma Tax '
'Commission, OMA)'],
'regulatory_notifications': ['Three entities '
'reported (Jenks '
'Public Schools, '
'Gordon Cooper '
'Technology Center, '
'University of '
'Phoenix)']},
'response': {'communication_strategy': ['Public disclosures by Jenks Public '
'Schools, Gordon Cooper Technology '
'Center, and University of Phoenix',
'Limited transparency from Oklahoma '
'Tax Commission and OMA']},
'stakeholder_advisories': 'State agencies and businesses urged to comply with '
'reporting requirements to improve cybersecurity '
'resilience.',
'threat_actor': ['ShinyHunters', 'Booba Project'],
'title': 'Oklahoma Cybersecurity Breaches Under New Reporting Law',
'type': ['Data Breach', 'Ransomware'],
'vulnerability_exploited': ['Third-party software flaw (University of '
'Phoenix)',
'Canvas learning platform vulnerability (Jenks '
'Public Schools, Gordon Cooper Technology '
'Center)']}