Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
City of Oakland

City of Oakland Vendor Cyber Rating & Cyber Score

oaklandca.gov

Incorporated in 1852, Oakland is the eighth largest city in California, with an estimated population of 450,000 and a wealth of resources and opportunities. Located on the east side of the San Francisco Bay, Oakland is bordered by 19 miles of coastline to the west and rolling hills to the east, which provide unparalleled vistas of the Bay and the Pacific Ocean.


CO A.I CyberSecurity Scoring

CO
Company Information
Website:http://oaklandca.gov
Employees number:2,493
Number of followers:22,311
NAICS:92
Industry Type:Government Administration
Homepage:oaklandca.gov
CO Risk Score (AI oriented)
Between 0 and 549
logo
COGovernment Administration
Updated:
04/04/2026
291/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
CO Global Score (TPRM)
xxxx
logo
COGovernment Administration
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

CO
COCritical
Current Score
291C (CRITICAL)
01000
5 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
323Before Incident
MAY 2026
302Before Incident
APRIL 2026
302Before Incident
MARCH 2026
289Before Incident
FEBRUARY 2026
275Before Incident
JANUARY 2026
262Before Incident
DECEMBER 2025
236Before Incident
NOVEMBER 2025
232Before Incident
OCTOBER 2025
217Before Incident
SEPTEMBER 2025
203Before Incident
AUGUST 2025
192Before Incident
JULY 2025
181Before Incident
MAY 2025
373Before Incident
Ransomware
01 May 2025CO
City of Oakland

Play Ransomware Group Targets 900 Organizations Since 2022

147After Incident
CRITICAL-226
OAK825090225
The City of Oakland was targeted by the Play ransomware group, a threat actor known for its double extortion model, where stolen data is encrypted and threatened for public release if ransom demands are unmet. The attack likely involved exploiting vulnerabilities in external-facing services (e.g., RDP, VPNs, FortiOS, or Microsoft Exchange) or stolen credentials to gain initial access. Once inside, the attackers used tools like AdFind, Grixba, Cobalt Strike, and Mimikatz to escalate privileges, disable security software (e.g., Microsoft Defender via PowerShell scripts), and move laterally across the network. The ransomware variant deployed may have included ESXi-targeting malware, capable of shutting down virtual machines and encrypting files with unique keys per file, severely disrupting municipal operations. Given the city’s reliance on digital infrastructure for public services, emergency response, and administrative functions, the attack likely caused operational outages, financial losses from recovery efforts, and potential leaks of sensitive citizen or employee data. The Play group’s history of data exfiltration and public leak threats further amplifies reputational and legal risks for the city. Recovery efforts would involve rebuilding encrypted systems, forensic investigations, and potential ransom negotiations, with long-term impacts on trust in municipal cybersecurity.
INCIDENT DETAILS -
TYPE
ransomwaredata breachdouble extortion
MOTIVATION
financial gaindata theft for extortion
APRIL 2023
251Before Incident
Ransomware
01 Apr 2023CO
City of Oakland

Oakland Ransomware Attack

100After Incident
CRITICAL-151
CIT34928823
The Oakland ransomware attack on April 2023, which seriously disrupted city operations for weeks, was carried out by the LockBit ransomware gang. At first, the Play ransomware gang claimed responsibility for the attack, but LockBit later added the city to its list of leak locations.
INCIDENT DETAILS -
TYPE
Ransomware
IMPACT
Downtime: weeksOperational Impact: seriously disrupted city operations
MARCH 2023
470Before Incident
Ransomware
01 Mar 2023CO
City of Oakland

Ransomware Attack on the City of Oakland

236After Incident
HIGH-234
CIT183681023
The City of Oakland reported a ransomware attack. The City of Oakland, out of an abundance of caution, took the affected systems offline while they worked to secure the affected infrastructure. In order to ascertain the extent and gravity of the problem, the information technology department alerted the relevant authorities and started an inquiry into the occurrence. Even while the City's primary operations—including 911, financial information, and fire and rescue resources—were unaffected, the notice it published cautions the public about potential delays from the City as a result of the attack. The City has verified that an unauthorized entity has obtained a number of files from its network and has threatened to make the information publicly available.
INCIDENT DETAILS -
TYPE
Ransomware
IMPACT
Data Compromised: Files obtained from the networkOperational Impact: Potential delays in city services
DATA BREACH
Data Exfiltration: Files obtained from the network
FEBRUARY 2023
635Before Incident
Ransomware
01 Feb 2023CO
City of Oakland

Ransomware Attack on the City of Oakland

463After Incident
HIGH-172
CIT6316223
The City of Oakland was targeted by Ransomware Attack after that Oakland continues to experience a network outage that has left several non-emergency systems including phone lines within the City of Oakland impacted or offline. The City appreciates the community's patience while workers from several departments collaborate to reduce interruptions and put in place workarounds to typical business procedures that enable the City to keep providing services. In addition to engaging with additional cybersecurity and technology companies on recovery and remediation efforts, the City's IT Department is collaborating with a top forensics firm to conduct a thorough incident response and investigation. With numerous local, state, and federal authorities participating, this inquiry is still ongoing. In order to address the problem, the City is creating a response strategy while adhering to industry best practises. ITD has taken affected systems offline out of an abundance of caution as they seek to secure and safely restore services. The public should anticipate delays from the City in the interim.
INCIDENT DETAILS -
TYPE
Ransomware
IMPACT
Non-emergency systemsPhone linesDowntime: OngoingOperational Impact: Delays in city services
JUNE 2022
768Before Incident
Ransomware
16 Jun 2022CO
City of Oakland

City of Oakland Ransomware Attack (2023)

615After Incident
CRITICAL-153
OAK3702437100825
In 2023, the City of Oakland suffered a severe ransomware attack executed by the Play ransomware group, exposing the personal data of thousands of current and former police officers and city employees. Compromised information included home addresses, medical records, and Social Security numbers, which were leaked on the dark web. The attack crippled the city’s IT systems for weeks, disrupting essential government services and delaying critical operations, including police misconduct investigations. The breach led to a class-action lawsuit with over 10,000 plaintiffs, resulting in settlements of $175 per affected officer and up to $350 for other employees who proved financial harm. The city also offered three years of free credit monitoring. An earlier 2022 audit had warned of cybersecurity vulnerabilities due to understaffing and resource shortages, but no action was taken. The incident exposed systemic neglect in Oakland’s digital defenses, raising concerns about identity theft risks—especially for police in a high-crime city—and prolonged operational disruptions across municipal services.
INCIDENT DETAILS -
TYPE
ransomwaredata breach
MOTIVATION
financial gaindata theft
IMPACT
home addressesmedical informationSocial Security numberspersonally identifiable information (PII)city government technological systemspolice department investigationsDowntime: weeks to monthsdisruption of basic city servicesdelays in officer misconduct investigationsextended federal oversight of Oakland Police Departmentloss of trust in city governmentpublic scrutiny over cybersecurity neglectclass-action lawsuit with over 10,000 plaintiffssettlements for affected employeesIdentity Theft Risk: high (data sold on dark web)
DATA BREACH
PIIhome addressesmedical informationSocial Security numbersNumber Of Records Exposed: 10,000+Sensitivity Of Data: highData Exfiltration: yes (data sold on dark web)Personally Identifiable Information: yes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for CO ?
?
What was CO's A.I Rankiteo Cyber Score in May 2026 ?
?
What was CO's A.I Rankiteo Cyber Score in April 2026 ?
?
What was CO's A.I Rankiteo Cyber Score in March 2026 ?
?
What was CO's A.I Rankiteo Cyber Score in February 2026 ?
?
What was CO's A.I Rankiteo Cyber Score in January 2026 ?
?
What was CO's A.I Rankiteo Cyber Score in December 2025 ?
?
What was CO's A.I Rankiteo Cyber Score in November 2025 ?
?
What was CO's A.I Rankiteo Cyber Score in October 2025 ?
?
What was CO's A.I Rankiteo Cyber Score in September 2025 ?
?
What was CO's A.I Rankiteo Cyber Score in August 2025 ?
?
What was CO's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on CO's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with CO ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view CO's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?