Cyberattack on Suisun City Disrupts 911 Services

Suisun City, CA Declares Emergency After Cyberattack on 911

HIGH
August 10, 2026
5m read
CyberattackIncident ResponseRegulatory

Impact Scope

People Affected

30,000 residents

Industries Affected

GovernmentCritical Infrastructure

Geographic Impact

United States (local)

Related Entities

Organizations

FBI Department of Homeland Security California Office of Emergency Services

Other

Suisun CitySolano County

Full Report

Executive Summary

On August 8, 2026, the City of Suisun City, California, declared a local state of emergency after a cyberattack involving "malicious software" compromised its entire information technology network. The attack, which began on August 7, had a severe impact on critical public safety infrastructure, affecting 911 call routing and police and fire dispatch services. In response, the city initiated a full network shutdown to contain the threat and has rerouted emergency dispatch through a neighboring county. The incident has triggered a multi-agency investigation involving the FBI and the Department of Homeland Security. While officials state emergency services remain operational via backups, the attack has crippled other municipal functions and highlights the growing threat of cyberattacks against local governments.

Threat Overview

The cyberattack on Suisun City began around 5:45 a.m. on Friday, August 7, 2026. The city's IT systems detected an intrusion by what has been described only as "malicious software." The system's automated defenses reportedly triggered a network-wide shutdown to contain the infection. The nature of the malicious software has not been disclosed, but such incidents targeting municipalities often involve ransomware.

The primary impact was on the city's public safety operations. Key systems affected include:

  • 911 call routing software
  • Police and fire dispatch systems
  • Access to city records

To maintain continuity of operations, Suisun City's emergency dispatch was transferred to the Solano County dispatch center. This workaround ensures that 911 calls are still answered and responders are dispatched, but it represents a significant disruption to normal operating procedures.

Technical Analysis

While specific technical details and Indicators of Compromise (IOCs) have not been released due to the ongoing investigation, we can assess likely attack vectors and techniques based on similar incidents targeting municipalities.

Impact Assessment

The declaration of a state of emergency underscores the severity of the attack's impact on the city of approximately 30,000 residents. The immediate consequences include:

  • Disruption of Public Safety: While workarounds are in place, reliance on a neighboring county's dispatch system can introduce delays and communication challenges during emergencies.
  • Suspension of City Services: Non-emergency municipal functions, such as processing water bills and permits, have been halted, affecting residents and city revenue.
  • Financial Costs: The emergency declaration allows the city to seek state and federal funding to cover the significant costs of incident response, system restoration, and potential recovery from the attack. These costs can be substantial, often running into millions of dollars for municipalities.
  • Investigative Overhead: The involvement of federal agencies like the FBI indicates a serious criminal investigation that will consume significant city resources.

IOCs — Directly from Articles

No specific Indicators of Compromise (IOCs) have been publicly released in the source articles.

Cyber Observables — Hunting Hints

Security teams at other municipalities may want to hunt for early signs of compromise. The following patterns could indicate related activity:

  • Log Sources: Monitor VPN logs, remote desktop access logs, and email security gateway logs for anomalous login attempts or suspicious attachments.
  • Process Names: Watch for the execution of common remote access tools like AnyDesk.exe or ScreenConnect.exe on systems where they are not authorized.
  • Command Line Patterns: Audit PowerShell logs (Event ID 4104) for encoded commands or scripts related to network discovery (e.g., net group "Domain Admins") or disabling security features.

Detection & Response

For municipalities seeking to improve their defensive posture against similar attacks:

  1. Endpoint Detection and Response (EDR): Deploy EDR solutions to detect and block malicious processes and scripts characteristic of ransomware attacks. Utilize Process Analysis (D3-PA) to identify anomalous behavior.
  2. Network Segmentation: Implement robust network segmentation to prevent threats from moving laterally from the IT network to critical public safety or operational technology (OT) networks. This is a core principle of Network Isolation (D3-NI).
  3. Backup and Recovery: Maintain and regularly test offline, immutable backups of all critical systems. This is the most crucial defense against ransomware.
  4. Incident Response Plan: Develop and regularly drill a comprehensive incident response plan that includes communication strategies and clear procedures for failover to backup systems, as Suisun City did with its dispatch services.

Mitigation

  1. Multi-Factor Authentication (MFA): Mandate MFA for all remote access, cloud services, and privileged accounts. This is a critical defense against credential compromise. See MFA (D3-MFA).
  2. Patch Management: Aggressively patch internet-facing systems and critical software. Many municipal breaches start with the exploitation of known vulnerabilities.
  3. User Training: Conduct regular phishing and security awareness training for all employees to help them identify and report suspicious emails and links.
  4. Least Privilege: Enforce the principle of least privilege for all user and service accounts to limit an attacker's ability to move laterally after an initial compromise.

Timeline of Events

1
August 7, 2026
Cyberattack begins, and malicious software is detected on Suisun City's IT network.
2
August 8, 2026
Suisun City's City Council holds a special meeting and approves a declaration of a local state of emergency.
3
August 10, 2026
This article was published

MITRE ATT&CK Mitigations

Properly segmenting networks can prevent an intrusion in the IT environment from spreading to critical public safety and operational systems.

Regular security awareness and phishing training can help prevent the initial compromise that often starts with a malicious email.

Implementing MFA on all remote access points and for all privileged accounts is one of the most effective controls against credential-based attacks.

Maintain a rigorous patch management program to close known vulnerabilities before they can be exploited by threat actors.

Timeline of Events

1
August 7, 2026

Cyberattack begins, and malicious software is detected on Suisun City's IT network.

2
August 8, 2026

Suisun City's City Council holds a special meeting and approves a declaration of a local state of emergency.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

CyberattackGovernment911State of EmergencyIncident ResponseCalifornia

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.