Suisun City, California, Hit by Cyberattack Disrupting Essential Services
Suisun City, California, declared a state of emergency after a cyberattack on August 7th disrupted police, fire, and other critical city services, potentially linked to ransomware.

Suisun City in Northern California is currently responding to a significant cyber incident that began on August 7th, leading to the declaration of a state of emergency. The attack, which started around 5:45 am, infected the city's IT network with "malicious software," prompting officials to shut down the entire network to contain the threat and preserve evidence for an ongoing federal investigation. This drastic measure has rendered online services and internal operations temporarily unavailable, forcing City Hall to close and impacting meetings across all departments, including planning, housing, and water.
The cyberattack has had a cascading effect on essential public services. 911 call routing, police and fire dispatch, and vital records systems have all been affected. While the City assured residents on August 10th that emergency 911 calls are being successfully routed through the Solano County dispatch center and that there is no "imminent" threat to the public, the disruption to daily operations for its approximately 30,000 residents remains substantial.
Indications suggest the incident may be ransomware-related, although official confirmation of the attack's source or perpetrators is still pending. Suisun City Council Member Princess Washington revealed in a LinkedIn post that an emergency meeting was scheduled for August 11th to discuss the ongoing effects of the cybersecurity incident. The council was also expected to consider a closed session to address "threats to public services and facilities, cybersecurity matters and anticipated litigation," hinting at potential ransom demands.
This incident in Suisun City is part of a concerning pattern of cyberattacks targeting US local government entities. Just days prior, the City of Coweta in Oklahoma reported a "system-wide ransomware attack" on August 5th, and Washburn County in Wisconsin confirmed it was responding to a cyber incident on August 6th, shutting down its technology services. These attacks underscore the vulnerability of municipal IT infrastructure.
Local governments have increasingly become attractive targets for threat actors due to often limited IT and security resources. Experts note that these entities operate with constraints that make them susceptible to sophisticated attacks. The clustering of these incidents within a short timeframe highlights a clear trend, with attackers recognizing the potential for significant disruption and leverage.
Past incidents serve as stark reminders of the impact of ransomware on local authorities. In August 2025, the Interlock ransomware group leaked employee data from the City of St. Paul, Minnesota, after payment demands were refused. Similarly, Clay County in Indiana and Jackson County in Missouri reported ransomware attacks in 2024 that severely impacted critical government services.
The ongoing situation in Suisun City, coupled with recent attacks on Coweta and Washburn County, emphasizes the persistent threat landscape facing local governments. The declaration of a state of emergency and the involvement of federal investigators signal the severity of the breach and the potential for widespread implications for public services and data security.
The cyberattack on Suisun City, California, is part of a broader wave of incidents affecting local governments across the United States. Similar ransomware attacks have recently impacted municipal services in Coweta, Oklahoma; Mitchell, South Dakota; Coryell County, Texas; and Washburn County, Wisconsin. These incidents collectively highlight a significant and growing cybersecurity challenge for public sector entities, often leading to disruptions in essential services and requiring extensive recovery efforts.