CO A.I CyberSecurity Scoring
CO
Company Information
Website:http://oaklandca.gov
Employees number:2,559
Number of followers:24,615
NAICS:92
Industry Type:Government Administration
Homepage:oaklandca.gov
CO Risk Score (AI oriented)
Between 0 and 549
COGovernment Administration
Updated:
25/08/2026
25/08/2026
191/1000
Critical
C
CO Global Score (TPRM)
xxxx
COGovernment Administration
Score locked

COCritical
Current Score
191C (CRITICAL)
01000
6 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
194
AUGUST 2026
191
JULY 2026
180
JUNE 2026
166
MAY 2026
147
APRIL 2026
147
MARCH 2026
135
FEBRUARY 2026
122
JANUARY 2026
111
DECEMBER 2025
100
NOVEMBER 2025
100
OCTOBER 2025
100
MAY 2025
165
Ransomware
01 May 2025 • CO
City of Oakland
Play Ransomware Group Targets 900 Organizations Since 2022
100
CRITICAL-65
OAK825090225
The City of Oakland was targeted by the Play ransomware group, a threat actor known for its double extortion model, where stolen data is encrypted and threatened for public release if ransom demands are unmet. The attack likely involved exploiting vulnerabilities in external-facing services (e.g., RDP, VPNs, FortiOS, or Microsoft Exchange) or stolen credentials to gain initial access. Once inside, the attackers used tools like AdFind, Grixba, Cobalt Strike, and Mimikatz to escalate privileges, disable security software (e.g., Microsoft Defender via PowerShell scripts), and move laterally across the network. The ransomware variant deployed may have included ESXi-targeting malware, capable of shutting down virtual machines and encrypting files with unique keys per file, severely disrupting municipal operations. Given the city’s reliance on digital infrastructure for public services, emergency response, and administrative functions, the attack likely caused operational outages, financial losses from recovery efforts, and potential leaks of sensitive citizen or employee data. The Play group’s history of data exfiltration and public leak threats further amplifies reputational and legal risks for the city. Recovery efforts would involve rebuilding encrypted systems, forensic investigations, and potential ransom negotiations, with long-term impacts on trust in municipal cybersecurity.
INCIDENT DETAILS -
TYPE
MOTIVATION
REFERENCES
NOVEMBER 2024
309
Ransomware
16 Nov 2024 • CO
City of Oakland: City of Oakland Hit by Ransomware
Oakland Hit by Ransomware Attack, City Systems Taken Offline
100
CRITICAL-209
OAK1787639165
Oakland Hit by Ransomware Attack, City Systems Taken Offline
The City of Oakland has fallen victim to a ransomware attack, forcing officials to take critical IT systems offline as they work to contain the breach and restore services. The incident, which began on the night of February 8, has disrupted non-emergency systems, including voicemail and other municipal services, though core functions such as 911, fire, and emergency response remain operational.
Oakland’s government confirmed the attack in a notice posted late last week, stating that the Information Technology Department (ITD) is coordinating with law enforcement to assess the scope and severity of the intrusion. As a precaution, affected systems were taken offline to prevent further damage, though the city has warned residents to expect delays in services.
Five days into the incident, officials are still developing a response plan. While the city has not disclosed which hacking group is responsible or whether a ransom demand was made, the standard tactic of taking systems offline suggests attackers may have already exfiltrated sensitive data. If negotiations fail, such data is often leaked or sold on dark web forums.
The attack highlights the ongoing vulnerability of municipal networks to ransomware, with local governments increasingly targeted by cybercriminals. Oakland’s response remains under close monitoring as recovery efforts continue.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
APRIL 2023
251
Ransomware
01 Apr 2023 • CO
City of Oakland
Oakland Ransomware Attack
100
CRITICAL-151
CIT34928823
The Oakland ransomware attack on April 2023, which seriously disrupted city operations for weeks, was carried out by the LockBit ransomware gang.
At first, the Play ransomware gang claimed responsibility for the attack, but LockBit later added the city to its list of leak locations.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
MARCH 2023
470
Ransomware
01 Mar 2023 • CO
City of Oakland
Ransomware Attack on the City of Oakland
236
HIGH-234
CIT183681023
The City of Oakland reported a ransomware attack. The City of Oakland, out of an abundance of caution, took the affected systems offline while they worked to secure the affected infrastructure.
In order to ascertain the extent and gravity of the problem, the information technology department alerted the relevant authorities and started an inquiry into the occurrence.
Even while the City's primary operations—including 911, financial information, and fire and rescue resources—were unaffected, the notice it published cautions the public about potential delays from the City as a result of the attack.
The City has verified that an unauthorized entity has obtained a number of files from its network and has threatened to make the information publicly available.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2023
635
Ransomware
01 Feb 2023 • CO
City of Oakland
Ransomware Attack on the City of Oakland
463
HIGH-172
CIT6316223
The City of Oakland was targeted by Ransomware Attack after that Oakland continues to experience a network outage that has left several non-emergency systems including phone lines within the City of Oakland impacted or offline.
The City appreciates the community's patience while workers from several departments collaborate to reduce interruptions and put in place workarounds to typical business procedures that enable the City to keep providing services.
In addition to engaging with additional cybersecurity and technology companies on recovery and remediation efforts, the City's IT Department is collaborating with a top forensics firm to conduct a thorough incident response and investigation.
With numerous local, state, and federal authorities participating, this inquiry is still ongoing.
In order to address the problem, the City is creating a response strategy while adhering to industry best practises.
ITD has taken affected systems offline out of an abundance of caution as they seek to secure and safely restore services.
The public should anticipate delays from the City in the interim.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
JUNE 2022
768
Ransomware
16 Jun 2022 • CO
City of Oakland
City of Oakland Ransomware Attack (2023)
615
CRITICAL-153
OAK3702437100825
In 2023, the City of Oakland suffered a severe ransomware attack executed by the Play ransomware group, exposing the personal data of thousands of current and former police officers and city employees. Compromised information included home addresses, medical records, and Social Security numbers, which were leaked on the dark web. The attack crippled the city’s IT systems for weeks, disrupting essential government services and delaying critical operations, including police misconduct investigations. The breach led to a class-action lawsuit with over 10,000 plaintiffs, resulting in settlements of $175 per affected officer and up to $350 for other employees who proved financial harm. The city also offered three years of free credit monitoring. An earlier 2022 audit had warned of cybersecurity vulnerabilities due to understaffing and resource shortages, but no action was taken. The incident exposed systemic neglect in Oakland’s digital defenses, raising concerns about identity theft risks—especially for police in a high-crime city—and prolonged operational disruptions across municipal services.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for CO ??
What was CO's A.I Rankiteo Cyber Score in August 2026 ??
What was CO's A.I Rankiteo Cyber Score in July 2026 ??
What was CO's A.I Rankiteo Cyber Score in June 2026 ??
What was CO's A.I Rankiteo Cyber Score in May 2026 ??
What was CO's A.I Rankiteo Cyber Score in April 2026 ??
What was CO's A.I Rankiteo Cyber Score in March 2026 ??
What was CO's A.I Rankiteo Cyber Score in February 2026 ??
What was CO's A.I Rankiteo Cyber Score in January 2026 ??
What was CO's A.I Rankiteo Cyber Score in December 2025 ??
What was CO's A.I Rankiteo Cyber Score in November 2025 ??
What was CO's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on CO's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with CO ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view CO's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?