SUISUN CITY, Calif. — Suisun City has declared a local state of emergency after a cyberattack compromised its information technology network and disrupted systems supporting 911 routing, police and fire dispatch, municipal records and other city services.
The incident began at about 5:45 a.m. on Friday, August 7, when malicious software infected city systems. Officials responded by shutting down the entire IT network to contain the threat and preserve evidence while federal, state and local partners began investigating the breach.
Despite the disruption, Suisun City said there is no imminent threat to the public and emergency response remains active. Dispatchers are taking calls through the neighboring Solano County dispatch center, while local police officers and firefighters continue responding to calls for service.
How the Suisun City cyberattack disrupted city operations
Suisun City, a Northern California community of about 30,000 people between San Francisco and Sacramento, relies on connected systems for emergency communications, records and everyday municipal functions. The breach affected several of those systems at once, forcing officials to move quickly to isolate the wider network.
Online city services and some internal operations remain temporarily unavailable. That can affect routine functions such as digital payments, permits and other services that normally depend on city technology.
The City Council held a special meeting on Saturday, August 8, and unanimously approved the emergency declaration. The move allows the city to access emergency support and recover costs associated with the cybersecurity response.
Suisun City is working with the FBI, the Department of Homeland Security and the California Governor’s Office of Emergency Services as investigators examine the compromised systems and work toward a safe restoration.
Taking an entire network offline can create significant disruption, but isolation is a recognized incident-response measure when multiple systems may be affected. Federal cybersecurity guidance recommends separating compromised systems and, when necessary, taking wider network segments offline to limit further spread and preserve evidence.
That same risk of operational disruption has appeared in other recent incidents. A Mississippi hospital ransomware attack forced clinics to close and disrupted key digital systems, illustrating how cybersecurity incidents can quickly become service-delivery problems when essential operations depend on connected infrastructure.
What remains unknown about the attack
Officials have not publicly identified who carried out the Suisun City attack. They have also not confirmed whether ransomware was used, whether a ransom demand was made or whether sensitive resident information was stolen.
Those distinctions matter. A compromised network does not automatically mean personal data was successfully removed, and describing the incident as ransomware before investigators establish that would go beyond the confirmed information.
The city’s decision to preserve evidence for a federal investigation suggests forensic work will focus on how the attackers gained access, which systems were reached and whether any information left the network.
A separate Craneware data breach investigation confirmed that employee and business records were taken after unauthorized access. That case shows why investigators often need time to distinguish between operational disruption and confirmed data theft.
For residents, the most important immediate point is that 911 and emergency response remain available through contingency arrangements. Anyone encountering unavailable online city services may need to wait for official restoration updates rather than relying on unexpected emails, texts or social-media messages claiming to provide alternative access.
The Cybersecurity and Infrastructure Security Agency’s incident-response guidance recommends isolating affected systems, preserving evidence and coordinating with federal law enforcement during serious cyber incidents.
Why attacks on local governments can have wider consequences
Municipal cyberattacks can affect far more than office computers because local governments increasingly depend on digital systems for emergency communications, public records, payments and internal coordination.
The Suisun City incident demonstrates the value of backup procedures when core technology becomes unavailable. Routing calls through Solano County has allowed emergency communications to continue even while the city’s own network is restricted.
It also shows why recovery can take longer than simply restarting systems. Investigators may need to identify the initial entry point, check for remaining malicious access, examine logs and confirm that restored equipment is safe before reconnecting it.
Fairlife Production Halted After Ransomware Attack Hits Manufacturing Systems
Carnival Data Breach Exposes Personal Information of Nearly 6 Million Customers
What residents should watch for now
The next meaningful updates will be whether investigators identify the intrusion method, confirm any data exposure and provide a timetable for restoring normal city services.
Until then, residents should rely on official Suisun City communications for service-status information and treat unsolicited messages about permits, payments or compromised accounts with caution. The city has not announced any resident compensation program, data-breach claim process or confirmed theft of personal information.
As of the latest available update, public safety operations remain active while cybersecurity specialists continue working to restore the affected municipal systems safely.















