Breaking
SecurityDeveloping Story

City Cyberattack Disrupts 911 Services Amid Wave of Attacks

Suisan City declared a state of emergency after a malicious software infection disrupted emergency services, highlighting a pattern of local government attacks.

··2 hours ago·4 min read
a long exposure shot of a city street
Photo by Dmitrii E. on Unsplash

Suisan City, a Northern California municipality of roughly 30,000 residents, is still wrestling with the fallout of a cyber incident that knocked out critical services, including 911 call routing. The attack, which began early on August 7, has forced officials to shut down the city's entire IT network, leaving online services dark and City Hall closed. While the immediate crisis may be contained, the incident is part of a broader surge of cyberattacks hitting US local governments, raising questions about the resilience of essential public infrastructure.

State of Emergency Declared

The City government declared a state of emergency after its IT network was infected by “malicious software” at roughly 5:45 am on August 7. This declaration enables the City to gain access to emergency resources and support at state and federal level.

The attack has affected 911 call routing, police and fire dispatch, records, and City services. In response, the authority shut down its entire IT network to contain the threat and preserve evidence for a federal investigation. This means online services and internal operations remain temporarily unavailable, while City Hall remains closed, impacting in-person meetings across all departments including planning, housing, and water.

Emergency Services Continue

In an update published on its website on August 10, Suisan City assured residents that its police and fire services are able to continue to respond to emergency 911 calls, which are being routed through the Solano County dispatch center. The City also stated that there is no “imminent” threat to the public from the incident.

Despite the disruption, the city emphasized that essential emergency services remain operational, albeit through alternative routing. The closure of City Hall and the suspension of online services, however, continue to affect residents' access to government functions, from planning permits to water services.

Ransomware Suspected

There are indications that the incident impacting Suisan City is ransomware-related, although there has been no official confirmation of the source of the attack or the perpetrators. The absence of a definitive attribution leaves the city in a state of uncertainty about the motives and methods of the attackers.

In a statement posted on her LinkedIn page late on August 10, Suisan City Council Member Princess Washington revealed that an emergency meeting would be taking place on August 11 regarding the continuing effects of the cybersecurity incident. In addition, she said that the Council will consider convening a closed session to “receive information and provide direction regarding threats to public services and facilities, cybersecurity matters and anticipated litigation.”

Demands Considered

California-based news website SFGATE has reported that the emergency meeting would consider the City’s response to demands from a “person or persons” behind the malware attack. This suggests that the attackers may have made specific demands, likely including a ransom payment, though the details have not been made public.

The decision to hold a closed session indicates that the council is weighing sensitive legal and security considerations, potentially including negotiations with the attackers or preparing for litigation. The city's response strategy remains opaque, but the involvement of a federal investigation suggests the incident is being treated with the seriousness it warrants.

Other Cities Hit

Suisan City is not alone. Several other US local authorities have been hit by cyber-attacks in recent weeks. On August 5, 2026, the City of Coweta in Oklahoma revealed it had experienced a “system-wide ransomware attack” and is currently working with cybersecurity experts to recover its systems and assess whether any data was accessed.

On August 6, 2026, Washburn County in Wisconsin issued a press release confirming it is currently responding to a cyber incident, shutting down its technology services as part of the process. No further information has been provided as to whether this incident is ransomware related.

Pattern of Attacks

Numerous US cities and local authorities have been targeted by ransomware in recent years, often resulting in severe disruptions to essential services and substantial IT recovery costs. In August 2025, officials from the City of St. Paul, Minnesota, confirmed that the Interlock ransomware group has published employee data online after refusing the attackers’ payment demands.

In 2024, Clay County in Indiana and Jackson County in Missouri reported being hit by ransomware attacks that had impacted critical government services. These incidents underscore a persistent threat to public sector entities, which often lack the resources of larger organizations.

Expert Commentary

“Municipal IT and security teams, more often than not, operate under resource constraints that most enterprise security organizations would find genuinely difficult to imagine, and when you see three incidents like this in the same news cycle, it's clear that attackers have figured that out.”

— Seemant Sehgal, Founder & CEO, BreachLock

Commenting on the recent incidents, Seemant Sehgal, Founder & CEO, BreachLock, said that the attacks show that local government infrastructure is being treated as a reliable target by threat actors. He added, “Suisun City, Coweta, Washburn County – these are not outliers, they are a pattern.”

Why It Matters

The clustering of attacks on Suisan City, Coweta, and Washburn County within the same week suggests that local governments, particularly smaller municipalities with limited budgets, are increasingly in the crosshairs of cybercriminals. The impact on essential services like 911 dispatch is particularly alarming, as it directly threatens public safety.

For residents and officials in cities of similar size, this incident could mean that robust cybersecurity measures are no longer optional but a necessity. The frequency of these attacks may also force state and federal governments to step in with more support, as local authorities struggle to defend against sophisticated threats with constrained resources.

#cyberattack#ransomware#local government#suisan city#emergency services

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted through our automated editorial pipeline from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our Automation Policy →

← Back to all stories