The Containment Era is here. →Explore

Executive Summary

In early June 2024, Crisis24 permanently shut down its OnSolve CodeRED emergency notification system after a ransomware attack severely damaged the platform's environment. The incident, attributed to the INC ransomware group, involved unauthorized access to and exfiltration of user data, including names, addresses, email addresses, phone numbers, and passwords. Forensic analysis indicated the attack was contained within the legacy CodeRED environment. The shutdown left dozens of municipalities and law enforcement agencies temporarily without emergency notification services, though the U.S. government's Emergency Alert System was unaffected. Crisis24 accelerated rollout of its new platform, conducted a security audit, and notified law enforcement.

This breach underscores the increasing risk posed by ransomware groups targeting public safety infrastructure. With attackers leaking sensitive personal data and causing operational disruptions, organizations face mounting pressure to modernize legacy systems and enhance both incident response and segmentation controls in light of sophisticated, persistent threats.

Why This Matters Now

Public safety platforms are now prime targets for ransomware, amplifying risks to critical infrastructure and personal data. The incident highlights the urgent need to secure legacy environments, implement rapid segmentation, and proactively address vulnerabilities before attackers exploit them—especially as threat groups intensify campaigns on essential service providers.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Names, addresses, email addresses, phone numbers, and passwords of OnSolve CodeRED users were accessed and leaked by the attackers.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Comprehensive Zero Trust controls—including segmentation, lateral movement prevention, encrypted traffic enforcement, robust egress policies, and threat detection—would have isolated environments, reduced attack surface, and quickly detected malicious activity, greatly containing or preventing this attack.

Initial Compromise

Control: Multicloud Visibility & Control

Mitigation: Anomalous access would be rapidly detected and investigated.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Prevents attackers from gaining unnecessary access by enforcing least privilege.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement is contained via workload-to-workload segmentation.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Blocks or detects suspicious outbound C2 traffic.

Exfiltration

Control: Cloud Firewall (ACF)

Mitigation: Prevents unauthorized data exfiltration via policy controls.

Impact (Mitigations)

Enables rapid detection of ransomware activity and abnormal file/system behavior.

Impact at a Glance

Affected Business Functions

  • Emergency Notification Services
  • Public Safety Communications
Operational Disruption

Estimated downtime: 14 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Personal information including names, addresses, email addresses, phone numbers, and passwords of CodeRED users were compromised and leaked online.

Recommended Actions

  • Deploy identity-based Zero Trust segmentation to isolate legacy platforms and enforce least-privilege access.
  • Implement comprehensive east-west and egress traffic inspection to contain movement and block C2 and data exfiltration.
  • Enforce robust encryption policies for data in transit and at rest to protect sensitive information.
  • Leverage continuous monitoring, threat detection, and anomaly response to detect and contain breaches early.
  • Regularly review and update cloud firewall, segmentation, and visibility controls in line with evolving threat tactics.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image