Blog

Ransomware Gang Rivalry and Why It Matters to Oklahoma Small Businesses

Two rival ransomware gangs are fighting for volume, and Oklahoma small businesses are taking the hits. Here is how the Booba Project attack on OMA connects to a bigger pattern.

Dark moody illustration of a small office with ransom lock symbols and two rival gang silhouettes

A ransomware gang you have never heard of just hit an Oklahoma business you probably do. The Booba Project is a relatively new ransomware outfit and does not have the brand recognition of LockBit or Cl0p. That is exactly why it is a problem.

When big ransomware gangs compete for volume, they stop being picky about who they target. They lower the bar. They cast a wider net. And small businesses that would have been invisible to them a year ago are now sitting in their crosshairs.

The Oklahoma Manufacturing Alliance in Tulsa found out the hard way.

What happened to OMA

On July 15, 2026, the Oklahoma Manufacturing Alliance, a Tulsa-based organization that connects manufacturers across the state, detected ransomware activity on two employee computers. Their IT team identified the threat, isolated the affected systems, and restored access through a separate, secure network later that same morning.

On August 8, News 9 reported that the Booba Project claimed to have breached OMA and exfiltrated 10 gigabytes of data. Cybersecurity consultant Ron Vaughn of EMSCO Solutions, who spotted the claim on Booba’s leak site, told reporters that 10 gigabytes is not a small amount for a mid-sized organization and that the threat to publish should be taken seriously.

OMA says client records were not compromised. Their client data lives on a separate system that was not part of the incident. But the attack still hit close to home for thousands of Oklahoma businesses.

Why a brand-new gang matters

Booba Project started attacking people about a month before they hit OMA, according to Vaughn. They are not a seasoned outfit with a proven track record. They are a new gang trying to build their reputation.

Ransomware operates on volume. A group like Booba Project needs to prove they can breach organizations, extract data, and get paid. They do that by casting a wide net and hitting as many targets as they can while they are still figuring out their process. Small businesses are the easiest targets because they tend to have smaller security budgets, thinner IT teams, and less awareness of what ransomware groups actually look like when they are picking a victim.

But there is a twist. Ransomware gangs are not just hunting for the biggest payouts anymore. They are competing with each other. Qilin and The Gentlemen — two of the top groups in 2026 — are going after each other’s victims. When two gangs are fighting for dominance, the result is more attacks, more leaks, and a wider range of targets.

The numbers are not good

The latest quarterly ransomware data shows that businesses with fewer than 200 employees absorbed 63% of all ransomware attacks in Q2 2026. Qilin led with 356 incidents, followed by The Gentlemen with 207. Small and mid-sized businesses with revenues under $25 million took the most hits.

In 2026, 96% of ransomware victims were not Fortune 500 companies. They were small businesses — the kind of organizations that assumed they were too small to bother with.

That assumption is now costing them.

AI is making it worse

In July 2026, the first fully AI-automated ransomware attack was recorded. A criminal AI agent broke into a network, stole data, and encrypted files without any human attacker involved. This is an emerging threat for small businesses that cannot afford 24/7 monitoring or a dedicated security team.

The Booba Project attack on OMA did not involve AI automation — Vaughn said the attackers likely got in through a phishing email, which remains the single most common way ransomware gets inside a network. But the trend is clear: ransomware is getting cheaper to deploy and easier for a new gang to execute with minimal human oversight.

What you can do about it

You cannot control what ransomware groups are fighting each other. But you can control how vulnerable you are when they show up.

Ron Vaughn’s advice is practical and not expensive:

  • Multi-factor authentication. This is the single most effective control. If someone steals a password, MFA stops them. Period.
  • Encryption. Encrypt data at rest and in transit. If attackers get in, encrypted data is much less useful to them.
  • Employee training. Most breaches start with a phishing email. Train your team to recognize one. Run a phishing simulation if you can.
  • Strong password management. Passwords matter. Not all of them need to be 32 characters, but they should all be different and hard to guess.

Vaughn also noted something that should worry every small business owner: OMA was an organization, not a manufacturing plant. They were the people who help manufacturers. The same logic applies to your accounting firm, your law practice, your medical office. You are not the target because of what you make. You are the target because you have data.

The bottom line

The Booba Project is a new gang. They are trying to make a name for themselves. They picked OMA in Tulsa. They could just as easily pick your business in Norman, Moore, or Stillwater.

Ransomware gangs are competing for volume. That means more attacks, lower targets, and a wider net. AI is making attacks cheaper and faster. Cyber insurance is getting stricter and more expensive.

The question is not whether a ransomware attack will happen to a business like yours. The question is whether you will be the one who was not ready.

Questions about any of this?

Craig answers the phone. Book an hour of support or send a note — no contract required to get help.