Coweta Refused to Pay: How Offsite Backups Saved a City From Ransomware
Coweta, Oklahoma was hit by Anubis ransomware in August 2026. They refused to pay and recovered from offsite backups. Here is what small businesses should learn.
On August 5, 2026, the City of Coweta, Oklahoma, woke up to a message on every city computer: their files were locked, and the attackers — using a strain called Anubis — wanted money to unlock them.
The city’s response is instructive, especially for any small business that has ever wondered whether backups matter enough to pay for.
What happened
The ransomware encrypted files across city hall — financial records, Word documents, spreadsheets, internal systems. Everything local was locked. City computers stopped working.
But the payment system was not affected. Emergency services — 911, police, fire — run on separate off-site servers and stayed fully operational. Utility payments continued through the cloud-based billing portal.
And critically, the city had offsite backups. When they refused to pay the ransom and instead restored from those backups, the systems came back.
The lesson every small business owner should take
Most small business owners think ransomware is a “big city problem.” Coweta’s experience shows it happens to organizations of every size — and the recovery path is the same.
You do not need to be a city to learn from this. The same principles apply whether you run a two-person office or a twenty-person shop:
- Keep backups off the network. The Coweta attack encrypted everything local. If their backup drive sat permanently connected to the infected machine, it would have been encrypted too. Their backup survived because it was stored separately.
- Isolate your critical systems. Coweta’s emergency services and payment processing ran on separate infrastructure. When one path went down, the others stayed up.
- Do not pay the ransom. Coweta’s city manager said: “I’ve been through that process before with another city and we actually got reinfected two weeks after we paid the ransom.” Paying does not guarantee recovery, and it tells criminals your business is one that pays.
What to do before it happens to you
The most important line in any small business disaster plan is the one you write when nothing is wrong:
- Test your restore. Coweta had backups, but they also tested them. You should too — at least quarterly, recover a few files and confirm they open.
- Separate what you can’t afford to lose. Your customer database, financial records, and recent work should not live in the same place as your daily working files.
- Document the recovery path. Write down who calls whom, what system restores first, and what you tell customers while you are offline. When an attack happens, panic is expensive.
What’s next
If you are not sure whether your backup would hold up against ransomware — whether it is truly offline, whether you can restore from it, whether someone on your team knows how — that uncertainty is the one thing you can fix right now.
Book a free 15-minute consultation and I will walk through your current backup setup, identify where a real attack would break through, and recommend the minimum protection that keeps your business running.
Sources: City of Coweta press release, KTUL coverage, DysruptionHub report