Phishing Attack Hits Oklahoma Municipal Association
OMA confirmed a July phishing attack affecting 250,000 victims. Here is how phishing spreads from one click to a quarter million people, and what to do about it.
In mid-July 2026, the Oklahoma Municipal Association (OMA) confirmed what many of its members already suspected: a phishing attack had compromised a limited portion of its local network. The attack was traced to two computers and had affected approximately 250,000 victims.
OMA’s statement was brief but telling: “The attack happened July 15 and affected a limited portion of its local network.” The scale — a quarter million people — suggests that “limited” is a relative term.
How phishing attacks grow
A phishing attack starts the same way every time: someone clicks a link or opens an attachment in an email that was not what it claimed to be. That single click gives the attacker a foothold.
From there, the attack can spread laterally — moving from the original victim’s computer to shared drives, to email accounts that send more phishing messages to contacts, to systems that store customer or vendor data. What started as one compromised account can quickly become a network-wide incident.
For OMA, the attack hit on July 15. It was traced to two computers. But the 250,000 figure suggests the phishing emails sent from compromised accounts reached far beyond two machines.
What businesses miss about phishing
Most small business owners think phishing protection is about blocking emails. It is actually about training people.
The technical filters catch the obvious fakes — the ones with misspelled domains and broken grammar. The dangerous ones look real. They come from what appears to be a real vendor, a real colleague, a real customer. They create urgency: “The invoice is attached,” “The package is delayed, click here,” “Your account will be closed.”
The defense is not just better software. It is a team that has been trained to pause before clicking.
What to do next
If you have not run a phishing test with your team in the last six months, you are operating blind. The attack that looks most real is the one that gets through.
Book a free 15-minute consultation and I will walk through your team’s current email habits, identify where a realistic phishing attack would get through, and recommend a simple training routine that pays for itself the first time it prevents a click.
Sources: NewsOn6 coverage, Instagram post