Craven County CodeRED system hacked, shut down

(MGN | MGN Image)
Published: Nov. 25, 2025 at 1:32 PM EST|Updated: Nov. 25, 2025 at 1:43 PM EST

CRAVEN COUNTY, N.C. (WITN) - Craven County’s emergency alert platform is offline after it was part of a nationwide cybersecurity attack earlier this month.

The county was using OnSolve CodeRED to alert citizens of emergencies.

When the platform was hacked, the county says cybercriminals got user information that includes names, addresses, email addresses, phone numbers, and passwords used to create people’s CodeRED accounts.

Craven County says anyone who registered for an OnSolve CodeRED account who uses the same password for any other account, is encouraged to immediately change those passwords.

The county is now working with CodeRED by Crisis 24 to replace the hacked platform with a new system. That new platform is supposed to be available by Friday.

Onslow County said it previously used OnSolve CodeRED, but switched to a different system last December. Onslow County said it is checking with the company to learn if any of its citizens’ information was included in a recent data breach.

FAQs provided by CodeRED By Crisis 24

Is user data affected?

Our provider informed us that data potentially associated with the OnSolve CodeRED platform may be published. Our provider’s investigation suggests that the affected personal information is limited to contact information: name, address, email address, phone numbers and/or associated passwords used to create user profiles for alerts. If users have the same password for any other personal or business accounts, those passwords should be changed immediately.

What happened?

Our provider notified us that the OnSolve CodeRED environment was the victim of a targeted cyber-attack by an organized cybercriminal group. The attack damaged the OnSolve CodeRED environment. Our provider’s investigation indicates that this is an incident strictly contained within the OnSolve CodeRED environment with no contagion beyond. This does not impact any of our systems outside of emergency alerts.

Did this impact other systems for the municipality?

No. Our provider’s forensic analysis indicates that this is an incident strictly contained within the OnSolve CodeRED environment with no contagion beyond. This does not impact any of our systems outside of emergency alerts.

What is the new CodeRed system?

Our provider launched a new CodeRed System, which had been in the works. Our provider assures us that the new CodeRED platform resides on a non-compromised, separate environment and that they completed a comprehensive security audit and engaged external experts for additional penetration testing and hardening.

Does this incident impact the new CodeRed system?

No. Our provider informs that it resides in a non-compromised, separate environment. It also informed that they completed a comprehensive security audit and as engaged external experts for additional penetration testing and hardening.

When did this event occur?

Our provider notified us of the cybersecurity incident in November.

What is the Provider doing to respond to this issue?

The provider informed us that it promptly took steps to secure its systems, launched an investigation, and engaged external cybersecurity experts to assist. The provider decommissioned the OnSolve CodeRED platform and is the process of moving all customers to its new CodeRED platform.

What information of users was involved?

The provider is still investigating this matter, however, the provider informs that the affected personal information appears to be limited to contact information: name, address, email address, phone numbers and/or associated passwords used to create user profiles for alerts. If users have the same password for any other personal or business accounts, those passwords should be changed immediately.

Does this mean that users are victims of identity theft?

We have no evidence that any user information has been used to carry out identity theft and/or fraud.

Why did this happen?

Unfortunately, there have been rising cybersecurity risks and penetrations across many organizations as of late.