In December 2025, the Cheyenne & Arapaho Tribes experienced a ransomware attack that impacted their IT systems, leading to disruptions in tribal government operations, phone, and email services, as well as higher education programs. The incident was publicly disclosed by tribal leadership on January 7, 2026.
While the Rhysida ransomware group claimed responsibility for the attack and demanded a ransom, the Cheyenne & Arapaho Tribes have explicitly stated that there has been no confirmed data loss. Therefore, no specific data types, estimated number of affected individuals, or sensitive data exposure (such as SSN, medical, or financial data) have been verified. The tribe chose to take systems offline as a precautionary measure. Independent sources have not verified Rhysida's claims of stolen data.
Details regarding the extent of potential data exposure may emerge over time, and official notices to individuals have not been reported beyond the tribe's public disclosure.