CO A.I CyberSecurity Scoring
CO
Company Information
Website:http://oaklandca.gov
Employees number:2,493
Number of followers:22,311
NAICS:92
Industry Type:Government Administration
Homepage:oaklandca.gov
CO Risk Score (AI oriented)
Between 0 and 549
COGovernment Administration
Updated:
04/04/2026
04/04/2026
291/1000
Critical
C
CO Global Score (TPRM)
xxxx
COGovernment Administration
Score locked

COCritical
Current Score
291C (CRITICAL)
01000
5 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
323
MAY 2026
302
APRIL 2026
302
MARCH 2026
289
FEBRUARY 2026
275
JANUARY 2026
262
DECEMBER 2025
236
NOVEMBER 2025
232
OCTOBER 2025
217
SEPTEMBER 2025
203
AUGUST 2025
192
JULY 2025
181
MAY 2025
373
Ransomware
01 May 2025 • CO
City of Oakland
Play Ransomware Group Targets 900 Organizations Since 2022
147
CRITICAL-226
OAK825090225
The City of Oakland was targeted by the Play ransomware group, a threat actor known for its double extortion model, where stolen data is encrypted and threatened for public release if ransom demands are unmet. The attack likely involved exploiting vulnerabilities in external-facing services (e.g., RDP, VPNs, FortiOS, or Microsoft Exchange) or stolen credentials to gain initial access. Once inside, the attackers used tools like AdFind, Grixba, Cobalt Strike, and Mimikatz to escalate privileges, disable security software (e.g., Microsoft Defender via PowerShell scripts), and move laterally across the network. The ransomware variant deployed may have included ESXi-targeting malware, capable of shutting down virtual machines and encrypting files with unique keys per file, severely disrupting municipal operations. Given the city’s reliance on digital infrastructure for public services, emergency response, and administrative functions, the attack likely caused operational outages, financial losses from recovery efforts, and potential leaks of sensitive citizen or employee data. The Play group’s history of data exfiltration and public leak threats further amplifies reputational and legal risks for the city. Recovery efforts would involve rebuilding encrypted systems, forensic investigations, and potential ransom negotiations, with long-term impacts on trust in municipal cybersecurity.
INCIDENT DETAILS -
TYPE
MOTIVATION
REFERENCES
APRIL 2023
251
Ransomware
01 Apr 2023 • CO
City of Oakland
Oakland Ransomware Attack
100
CRITICAL-151
CIT34928823
The Oakland ransomware attack on April 2023, which seriously disrupted city operations for weeks, was carried out by the LockBit ransomware gang.
At first, the Play ransomware gang claimed responsibility for the attack, but LockBit later added the city to its list of leak locations.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
MARCH 2023
470
Ransomware
01 Mar 2023 • CO
City of Oakland
Ransomware Attack on the City of Oakland
236
HIGH-234
CIT183681023
The City of Oakland reported a ransomware attack. The City of Oakland, out of an abundance of caution, took the affected systems offline while they worked to secure the affected infrastructure.
In order to ascertain the extent and gravity of the problem, the information technology department alerted the relevant authorities and started an inquiry into the occurrence.
Even while the City's primary operations—including 911, financial information, and fire and rescue resources—were unaffected, the notice it published cautions the public about potential delays from the City as a result of the attack.
The City has verified that an unauthorized entity has obtained a number of files from its network and has threatened to make the information publicly available.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2023
635
Ransomware
01 Feb 2023 • CO
City of Oakland
Ransomware Attack on the City of Oakland
463
HIGH-172
CIT6316223
The City of Oakland was targeted by Ransomware Attack after that Oakland continues to experience a network outage that has left several non-emergency systems including phone lines within the City of Oakland impacted or offline.
The City appreciates the community's patience while workers from several departments collaborate to reduce interruptions and put in place workarounds to typical business procedures that enable the City to keep providing services.
In addition to engaging with additional cybersecurity and technology companies on recovery and remediation efforts, the City's IT Department is collaborating with a top forensics firm to conduct a thorough incident response and investigation.
With numerous local, state, and federal authorities participating, this inquiry is still ongoing.
In order to address the problem, the City is creating a response strategy while adhering to industry best practises.
ITD has taken affected systems offline out of an abundance of caution as they seek to secure and safely restore services.
The public should anticipate delays from the City in the interim.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
JUNE 2022
768
Ransomware
16 Jun 2022 • CO
City of Oakland
City of Oakland Ransomware Attack (2023)
615
CRITICAL-153
OAK3702437100825
In 2023, the City of Oakland suffered a severe ransomware attack executed by the Play ransomware group, exposing the personal data of thousands of current and former police officers and city employees. Compromised information included home addresses, medical records, and Social Security numbers, which were leaked on the dark web. The attack crippled the city’s IT systems for weeks, disrupting essential government services and delaying critical operations, including police misconduct investigations. The breach led to a class-action lawsuit with over 10,000 plaintiffs, resulting in settlements of $175 per affected officer and up to $350 for other employees who proved financial harm. The city also offered three years of free credit monitoring. An earlier 2022 audit had warned of cybersecurity vulnerabilities due to understaffing and resource shortages, but no action was taken. The incident exposed systemic neglect in Oakland’s digital defenses, raising concerns about identity theft risks—especially for police in a high-crime city—and prolonged operational disruptions across municipal services.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for CO ??
What was CO's A.I Rankiteo Cyber Score in May 2026 ??
What was CO's A.I Rankiteo Cyber Score in April 2026 ??
What was CO's A.I Rankiteo Cyber Score in March 2026 ??
What was CO's A.I Rankiteo Cyber Score in February 2026 ??
What was CO's A.I Rankiteo Cyber Score in January 2026 ??
What was CO's A.I Rankiteo Cyber Score in December 2025 ??
What was CO's A.I Rankiteo Cyber Score in November 2025 ??
What was CO's A.I Rankiteo Cyber Score in October 2025 ??
What was CO's A.I Rankiteo Cyber Score in September 2025 ??
What was CO's A.I Rankiteo Cyber Score in August 2025 ??
What was CO's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on CO's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with CO ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view CO's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?