30,000 residents
On August 8, 2026, the City of Suisun City, California, declared a local state of emergency after a cyberattack involving "malicious software" compromised its entire information technology network. The attack, which began on August 7, had a severe impact on critical public safety infrastructure, affecting 911 call routing and police and fire dispatch services. In response, the city initiated a full network shutdown to contain the threat and has rerouted emergency dispatch through a neighboring county. The incident has triggered a multi-agency investigation involving the FBI and the Department of Homeland Security. While officials state emergency services remain operational via backups, the attack has crippled other municipal functions and highlights the growing threat of cyberattacks against local governments.
The cyberattack on Suisun City began around 5:45 a.m. on Friday, August 7, 2026. The city's IT systems detected an intrusion by what has been described only as "malicious software." The system's automated defenses reportedly triggered a network-wide shutdown to contain the infection. The nature of the malicious software has not been disclosed, but such incidents targeting municipalities often involve ransomware.
The primary impact was on the city's public safety operations. Key systems affected include:
To maintain continuity of operations, Suisun City's emergency dispatch was transferred to the Solano County dispatch center. This workaround ensures that 911 calls are still answered and responders are dispatched, but it represents a significant disruption to normal operating procedures.
While specific technical details and Indicators of Compromise (IOCs) have not been released due to the ongoing investigation, we can assess likely attack vectors and techniques based on similar incidents targeting municipalities.
T1566.001 - Spearphishing Attachment, T1190 - Exploit Public-Facing Application, or compromised credentials obtained via T1078 - Valid Accounts.T1204.002 - Malicious File.T1486 - Data Encrypted for Impact to force payment. The shutdown of the network, whether automated or manual, is a direct consequence of T1489 - Service Stop or an attempt to contain the threat.The declaration of a state of emergency underscores the severity of the attack's impact on the city of approximately 30,000 residents. The immediate consequences include:
No specific Indicators of Compromise (IOCs) have been publicly released in the source articles.
Security teams at other municipalities may want to hunt for early signs of compromise. The following patterns could indicate related activity:
AnyDesk.exe or ScreenConnect.exe on systems where they are not authorized.Event ID 4104) for encoded commands or scripts related to network discovery (e.g., net group "Domain Admins") or disabling security features.For municipalities seeking to improve their defensive posture against similar attacks:
Properly segmenting networks can prevent an intrusion in the IT environment from spreading to critical public safety and operational systems.
Regular security awareness and phishing training can help prevent the initial compromise that often starts with a malicious email.
Implementing MFA on all remote access points and for all privileged accounts is one of the most effective controls against credential-based attacks.
Maintain a rigorous patch management program to close known vulnerabilities before they can be exploited by threat actors.
Cyberattack begins, and malicious software is detected on Suisun City's IT network.
Suisun City's City Council holds a special meeting and approves a declaration of a local state of emergency.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.