Suisun City, California, is grappling with a cyber attack that disrupted public services and forced authorities to declare a state of emergency after malware compromised IT systems.
With a population of approximately 30,000, Suisun City is located in Solano County in Northern California, within the broader San Francisco Bay Area.
The attack began at around 5:45 a.m. on Friday, August 7, 2026. It affected various city services, including records, 911 routing, and fire and police dispatch services.
State of emergency in Suisun City after cyber attack disrupts services
On Saturday, August 7, the city disclosed it had experienced a cybersecurity incident affecting various services. It responded by shutting down its entire IT network to contain the incident and transferred police and fire dispatch to the Solano County dispatch center.
“The City of Suisun City is currently experiencing a cybersecurity incident that has impacted services at City Hall and public safety departments,” the city disclosed.
The shutdown affected the Administration, the City Manager’s Office, and the Planning, Building, Housing, Water, Finance, Human Resources, and Public Works departments. It prevented residents from paying water bills and getting building permits or business licenses. Nevertheless, emergency police and fire dispatches continued operating through the new dispatch center.
“Suisun City dispatchers are continuing to take calls through the Solano County dispatch center, and Suisun City PD and Fire continue to respond to calls for service,” the city stated. “Online City services and internal operations remain temporarily unavailable. The cybersecurity incident is currently under investigation.”
The city also activated its Emergency Operations Center and engaged federal, state, and regional agencies to respond to and investigate the cyber attack and restore the impacted systems. Specialized agencies, including the FBI, the Department of Homeland Security (DHS), and the California Office of Emergency Services, were also involved.
On August 8, 2026, the city declared a state of emergency as a result of the cyber attack. On Tuesday, August 11, City officials also held a closed-door consultative meeting and agreed to close City Hall for the rest of the week while responding to the cyber attack. However, internal operations continued, while public services remained closed.
Meanwhile, Suisun City says the cyber attack poses no imminent threat to the residents and all emergency services remain available. Similarly, city officials say there is no evidence that residents’ personal information was stolen. The city expects litigation if personal data was exposed.
Typically, data breaches involving city services leak sensitive information, including government-issued IDs such as Social Security Numbers (SSNs). Consequently, residents were advised to monitor their credit reports and financial statements and report any suspicious activity.
So far, the city has not attributed the cyber attack to any threat actor and no cybercrime gang has taken responsibility. Similarly, Suisun City has not disclosed whether the cyber attack involved ransomware and if any ransom demands have been made. Authorities have also yet to say how the attackers gained access.
“What happened in Suisun City shows why cyber recovery is fundamentally an operational resilience issue,” said Arvind Parthasarathi, CEO and founder, CYGNVS. “Malware affected systems supporting 911 routing, police and fire dispatch, records and other municipal services, forcing the city to shut down its IT network. The fact that dispatchers were able to shift 911 operations to Solano County and keep emergency calls moving is exactly the kind of continuity organizations need to plan for before an incident occurs.”
Government services targeted
The Suisun City cyber attack was not unique, as state-sponsored actors, financially motivated cybercriminals, and hacktivists have frequently targeted government services for extortion and to cause disruption and public panic.
“City services are always a lucrative target due to attackers’ ability to directly impact critical services, residents, and sensitive data,” said Ashley Knowles, Security Consultant for Black Hills Information Security. “Government IT departments often operate with constrained budgets while wearing multiple hats, and in the age of AI-assisted attacks, that combination makes municipalities a prime target.”
In April 2023, a ransomware attack hit the City of Oakland, California, and leaked 600 GB of personal information belonging to current and former employees. Other California cities and municipalities, including Pasadena, Fresno, Fullerton, Modesto, Hayward, Thousand Oaks, Galt, and Lodi, have also experienced ransomware attacks. Bay Area cities of Foster and Pittsburg have also experienced cyber attacks in the past.
In August 2025, a cyber attack also disrupted state services in Nevada, resulting in the closure of all government offices.
“Suisun City, Coweta, Washburn County — these are not outliers; they are a pattern, and the pattern tells us that local government infrastructure is being treated as a reliable target,” said Seemant Sehgal, Founder & CEO, BreachLock. “The people responding to these incidents are doing exactly what you do when you have limited staffing and a network that cannot go dark for long without causing a real emergency, and the hard reality is that the window between ‘contained’ and ‘encrypted’ is often shorter than any reasonable detection and response process can close.”

