BusinessCybersecurityNewswireTechnology

Suisan City California Responds to Cyber Incident Amid US Wave

Originally published on: August 12, 2026
▼ Summary

– Suisun City, California, declared a state of emergency after a malicious software infection on August 7 disrupted 911 call routing, police and fire dispatch, and city services.
– The city shut down its entire IT network to contain the threat, leaving online services and City Hall operations temporarily unavailable.
– Police and fire services continue to respond to 911 calls via the Solano County dispatch center, and the city states there is no imminent public threat.
– The incident is suspected to be ransomware-related, though unconfirmed, and an emergency meeting on August 11 will address the city’s response to demands from the attackers.
– Other recent attacks include a ransomware attack on Coweta, Oklahoma (August 5) and a cyber incident in Washburn County, Wisconsin (August 6), highlighting a pattern of targeting resource-constrained local governments.

The City of Suisun City, California, remains in the throes of a significant cybersecurity event, joining a growing list of U.S. municipalities hit by digital intrusions in recent weeks. Local officials declared a state of emergency after detecting malicious software on their IT network at approximately 5:45 a.m. on August 7. That declaration unlocks access to critical emergency resources and support from both state and federal agencies.

The fallout has been extensive. The malware disrupted 911 call routing, police and fire dispatch operations, records management, and various City services. In a bid to contain the threat and preserve digital evidence for federal investigators, the City took the drastic step of shutting down its entire IT network. As a result, online services and internal operations remain offline, and City Hall is closed to the public. This suspension has halted in-person meetings across departments handling planning, housing, and water utilities.

In a public update posted on August 10, Suisun City reassured residents that police and fire units are still fully capable of responding to emergencies. 911 calls are being rerouted through the Solano County dispatch center to ensure continuity. The City also emphasized that there is no “imminent” threat to public safety stemming from the incident itself. Located in Northern California, Suisun City is home to roughly 30,000 residents.

Ransomware Suspected in Suisun City Attack

While the City has not officially confirmed the attack’s origin or the identity of the perpetrators, evidence strongly suggests a ransomware-related incident. Late on August 10, Suisun City Council Member Princess Washington took to LinkedIn to announce an emergency meeting scheduled for August 11 to address the ongoing effects of the breach. She noted that the Council would also consider a closed session to discuss “threats to public services and facilities, cybersecurity matters and anticipated litigation.”

Local news outlet SFGATE has reported that the emergency session will focus on the City’s response to demands made by the “person or persons” responsible for the malware. This development points to an active negotiation or strategic planning phase regarding the attackers’ ultimatum.

A Wave of Attacks on U. S. Local Governments

Suisun City is not alone in facing this crisis. A surge of cyber-attacks has targeted local authorities across the country over the past week. On August 5, the City of Coweta in Oklahoma disclosed a “system-wide ransomware attack” and is now working with cybersecurity experts to restore systems and determine if sensitive data was compromised. The following day, Washburn County in Wisconsin issued a press release confirming it was responding to a cyber incident, having taken its technology services offline as a precautionary measure. Officials have not yet clarified whether that incident involves ransomware.

These recent events are part of a broader, troubling trend. U. S. cities and local governments have become prime targets for ransomware gangs, often resulting in severe disruptions to essential services and hefty recovery costs. For instance, in August 2025, officials in St. Paul, Minnesota, confirmed that the Interlock ransomware group had leaked employee data online after the city refused to pay the ransom. Similarly, in 2024, Clay County in Indiana and Jackson County in Missouri both reported ransomware attacks that crippled critical government functions.

Expert Insight: Attackers See Local Governments as Easy Targets

Commenting on the recent spate of incidents, Seemant Sehgal, Founder and CEO of BreachLock, highlighted a sobering reality for municipal cybersecurity. He noted that local government infrastructure has become a reliable target for threat actors, largely due to chronic underfunding. “Municipal IT and security teams, more often than not, operate under resource constraints that most enterprise security organizations would find genuinely difficult to imagine, and when you see three incidents like this in the same news cycle, it’s clear that attackers have figured that out,” Sehgal said. He added, “Suisun City, Coweta, Washburn County, these are not outliers, they are a pattern.”

(Source: Infosecurity Magazine)

Topics

cyber incident response 98% ransomware attacks 95% local government cybersecurity 93% public safety operations 90% emergency declarations 86% government it network shutdown 84% data breach consequences 82% threat actor behavior 79% ransom payment decisions 77% cybersecurity expert commentary 74%