Ransomware victim disclosure
← All victimsCheyenne & Arapaho Tribes
Claimed by Rhysida · listed 3 months ago
Status timeline
- Listed
Feb 17, 2026
- Data leaked
At a glance
- Group
- Rhysida
- Status
- Data leaked
- Country
- United States
- Sector
- Public Sector
- Listed on leak site
- Feb 17, 2026
About the victim
AI dossier — public-source company profileThe Cheyenne and Arapaho Tribes are a federally recognized tribal nation in western Oklahoma, representing the Tsistsistas (Cheyenne) and Hinono'ei (Arapaho) peoples united since the early 19th century. The tribal government administers a range of public services including health, education, housing, and economic development programs for their enrolled membership and surrounding communities.
- Industry
- Tribal Government & Public Administration
- Address
- 100 Red Moon Circle, Concho, Oklahoma 73022, United States
- Employees
- 201-500
Attack summary
Severity: critical — The victim is a federally recognized tribal government. Such entities hold regulated PII at scale including tribal enrollment records, health data, social services records, and financial information for enrolled members — all categories of sensitive data whose exfiltration meets the critical threshold. Data has been confirmed published by the group.Rhysida claims to have compromised the Cheyenne and Arapaho Tribes and has published data (disclosed status: data_published), indicating exfiltration of tribal government records; the specific data categories and volume have not been enumerated in the available post excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Tribal government records
- Enrolled member personal information
- Administrative documents
What the group claims
Cheyenne & Arapaho Tribes The Cheyenne and Arapaho Tribes are a federally recognized united nation of two distinct peoples-the Tsistsistas (Cheyenne) and Hinono'ei (Arapaho)-with a historic alliance formed in the early 19th century.
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
