CSIDB logo
Incident

Suisun City

Incident posture

Attack window
Aug 2026
Location
United States of America
Status
Ongoing
CIA posture
Available to members
Updated
2026-09-24 06:20

Linked entities

Victim
Suisun City
Threat actors
0 actors
Sources
17 sources

Timeline

Occurred
Aug 2026
Discovered
Aug 2026
Disclosed
Aug 2026
Resolved
Pending

Summary

Suisun City experienced a cyber attack that infected its IT network with malicious software, disrupting records, 911 routing, and police and fire dispatch. The city shut down its entire network to contain the threat and preserve evidence, moving emergency dispatch to the Solano County center and declaring a state of emergency. While public safety remained operational through the county system, most administrative services, including water billing, permits, and human resources, were suspended. Officials worked with federal and state agencies to investigate the incident and gradually restored limited services, such as the water counter for in‑person cash or check payments, while keeping other departments closed pending security verification.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

At approximately 5:45 a.m. on Friday, August 7, 2026, malicious software compromised the information technology network of Suisun City, California, affecting records, 911 call routing, police and fire dispatch, and a range of municipal services including administration, planning, building, housing, water, finance, human resources, and public works. In response, city officials shut down the entire IT network to contain the incident and preserve evidence for investigation, which rendered online city services and internal operations temporarily unavailable. Police and fire dispatch functions were transferred to the Solano County dispatch center, allowing emergency responders to continue taking 911 and non‑emergency calls while the city’s own systems remained offline. The city disclosed the cybersecurity incident on Saturday, August 7, and activated its Emergency Operations Center, engaging federal, state, and regional agencies such as the FBI, the Department of Homeland Security, and the California Office of Emergency Services to assist with the investigation and restoration efforts. On August 8, 2026, Suisun City declared a state of emergency as a direct result of the cyber attack.

The disruption prevented residents from paying water bills, obtaining building permits, or securing business licenses, and led to the closure of City Hall and most public‑facing departments, including the planning, building, housing, finance, human resources, public works, city manager’s office, and administrative offices. Despite the shutdown, the police department lobby remained open for ticket sign‑offs, vehicle releases, speaking with an officer, and general assistance, operating Monday through Thursday from 7 a.m. to 5 p.m. with a possible lunch closure from noon to 12:30 p.m. On Tuesday, August 18, 2026, the city reopened its water counter for in‑person service at City Hall, accepting only cash or check while credit and debit card payments remained unavailable; all other public‑facing services continued to remain closed. City officials postponed the City Council meeting to provide staff additional time to prepare and ensure necessary systems were available, and they continued to balance the need to restore systems with the requirement to maintain security before bringing them back online. Throughout the incident, the city posted updates and answers to frequently asked questions at Suisun.com/CybersecurityUpdates.

Officials stated that there was no imminent threat to the public and that emergency police and fire services remained available through the Solano County dispatch center. They also said there was no evidence that residents’ personal information had been stolen, although they noted that litigation could follow if personal data were exposed. The city has not disclosed whether any data was stolen, whether a ransom was demanded, or whether the attack involved ransomware, and no threat actor has claimed responsibility or been identified by authorities. The incident is being viewed as part of a broader trend of cyberattacks targeting local government entities, with references to prior ransomware events in Oakland, Pasadena, Fresno, Fullerton, Modesto, Hayward, Thousand Oaks, Galt, Lodi, Foster, and Pittsburg, as well as a 2025 cyber attack that disrupted Nevada state services. City Manager Bret Prebula described the response as a day‑by‑day effort, employing protocols and structures similar to those used during natural disasters to maintain essential operations and continuity of government. The city’s website continues to provide information about the cybersecurity incident and its impact on city services. This ongoing work reflects the city’s focus on restoring systems while preserving security and essential public safety functions.

Sources

Sources available to members: 17 sources.

CSIDB