Suisan City in California declared a state of emergency after malicious software infected its IT network at approximately 5:45 am on August 7, according to a report published by Infosecurity Magazine on August 10, 2026. The declaration allows the city to access emergency resources and support from state and federal authorities. The incident is part of a recent wave of cyberattacks targeting local governments across the United States.
The attack affected 911 call routing, police and fire dispatch systems, municipal records, and city services, according to the report. City officials shut down the entire IT network to contain the threat and preserve evidence for a federal investigation, leaving online services and internal operations temporarily unavailable. City Hall remains closed, disrupting in-person meetings across all departments including planning, housing, and water. Suisan City, located in Northern California, has a population of roughly 30,000. Police and fire services can still respond to emergency 911 calls, which are being routed through the Solano County dispatch center, and there's no "imminent" threat to the public, city officials assured residents on August 10. Other recent incidents include a system-wide ransomware attack on the City of Coweta in Oklahoma on August 5, 2026, and a cyber incident in Washburn County, Wisconsin on August 6, 2026, which also prompted a technology services shutdown.
The report indicates the Suisan incident may be ransomware-related, though no official confirmation of the attack source or perpetrators has been made. City Council Member Princess Washington revealed on her LinkedIn page late on August 10 that an emergency meeting scheduled for August 11 would address the continuing effects of the cybersecurity incident. According to the report, California news website SFGATE reported that the emergency meeting would consider the city's response to demands from a "person or persons" behind the malware attack. Washington said the Council will consider convening a closed session to "receive information and provide direction regarding threats to public services and facilities, cybersecurity matters and anticipated litigation."
Seemant Sehgal, Founder and CEO of BreachLock, commented that the attacks demonstrate local government infrastructure is being viewed as a reliable target by threat actors. "Municipal IT and security teams, more often than not, operate under resource constraints that most enterprise security organizations would find genuinely difficult to imagine," he said, adding that when three incidents like this appear in the same news cycle, it's clear attackers have identified this vulnerability. The report notes that numerous US cities and local authorities have been targeted by ransomware in recent years, frequently causing severe disruptions to essential services and substantial IT recovery costs. In August 2025, officials from the City of St. Paul, Minnesota, confirmed the Interlock ransomware group published employee data online after the city refused payment demands, while Clay County in Indiana and Jackson County in Missouri both reported ransomware attacks impacting critical government services in 2024. Sehgal concluded that "Suisun City, Coweta, Washburn County – these are not outliers, they are a pattern." The clustering of attacks within days suggests threat actors are systematically exploiting the limited cybersecurity budgets and staffing constraints common among smaller municipalities, making them disproportionately vulnerable compared to larger jurisdictions with dedicated security operations. For cities evaluating their cyber preparedness, the gap between available defenses and evolving threats may already be too wide to bridge without external intervention.

