All posts

A California City Shut Down Its Entire Network to Stop a Cyberattack From Spreading. Here's What Your Team Should Check Right Now.

KynodexKynodex
12 min read
A California City Shut Down Its Entire Network to Stop a Cyberattack From Spreading. Here's What Your Team Should Check Right Now.

At roughly 5:45 a.m. on Friday, August 7, malicious software began compromising the IT systems of Suisun City, California — a city of about 29,500 people 45 miles from San Francisco. By Saturday, the city council had voted unanimously to declare a state of emergency, taken the entire municipal network offline, and rerouted every 911 call through a neighboring county's dispatch center.

No ransom demand has been made public. No suspect has been named. What is public is a plain, well-documented sequence of what happened and what the city did about it — and that sequence is a genuinely useful checklist for any organization, public or private, running infrastructure it can't afford to lose.


What Happened

According to the city's own public statements and multiple independent news outlets, the timeline is consistent and well-corroborated:

Friday, August 7, approximately 5:45 a.m. — Malicious software infected and compromised Suisun City's information technology systems. The city has not yet disclosed publicly how the malware gained initial access.

Systems affected — The incident hit critical public safety operations directly: 911 call routing, police and fire dispatch, city records, and general city services. This wasn't a peripheral IT outage; it struck the systems emergency responders depend on to receive and act on calls for help.

The response: a full network shutdown — Rather than trying to isolate and clean the infection while keeping systems running, the city made the more drastic call to take its entire computer network offline — both to stop the malware from spreading further and to preserve forensic evidence for a federal investigation.

Saturday, August 8, 11 a.m. — The city council held a special meeting and voted unanimously to declare a local state of emergency under California Government Code 8630. That declaration does two concrete things: it gives the city faster access to emergency support services, and it creates a legal path to recoup the costs of the incident.

The continuity workaround — With the city's own 911 routing offline, Suisun City dispatchers began taking emergency calls through the Solano County dispatch center instead. Police and fire personnel continued responding to calls for service throughout. The city has been explicit and consistent in its public messaging: there is no imminent threat to the public, and all public safety services remain active — just rerouted through a neighboring jurisdiction's infrastructure.

Who's involved in the response — The city activated its Emergency Operations Center and is working directly with the FBI, the Department of Homeland Security, and the California Office of Emergency Services, alongside additional regional agencies, to investigate the incident and restore affected systems.

What's still unknown, as of this writing — The city has not disclosed how the malware got in, whether it involved ransomware specifically, whether any data was exfiltrated, or who is believed to be responsible. Given the active federal investigation, that information gap is expected and appropriate at this stage — premature disclosure could compromise the investigation itself.


Why This Incident Is Worth Every Organization's Attention, Not Just Municipal IT

It's easy to read a story like this and file it under "small-town government, not my problem." That reaction misses what actually matters here.

The response, not the attack, is the template. Suisun City did several things correctly and quickly: it made an aggressive, if costly, decision to fully isolate the network rather than let malware spread through partial containment; it had a functioning continuity plan (county dispatch backup) that it could activate immediately; it declared an emergency through an established legal mechanism that unlocked resources and cost recovery; and it brought in federal expertise rather than trying to investigate and remediate alone. That's a genuinely well-executed incident response under real pressure — a useful reference point regardless of your organization's size or sector.

The target profile is the actual warning. This is a 29,500-person city — not a Fortune 500 company, not a state capital, not a major metro area. If your organization's security posture assumes "we're too small to be a target," this incident is direct evidence against that assumption. Attackers increasingly target smaller municipal and organizational infrastructure precisely because it tends to be under-resourced and under-defended relative to larger targets.

Critical infrastructure connected to the general internet is a recurring theme in 2026. Reporting on this incident specifically references a broader pattern — U.S. water systems across multiple states have also been targeted in a wave of attacks this year, and earlier 2026 saw urgent federal warnings about state-backed actors attempting to disrupt American infrastructure networks. Suisun City isn't an isolated event; it's a data point in an active, ongoing trend.


How to Check Your Own Security Posture Right Now

This isn't a theoretical exercise. Here's a concrete, prioritized set of checks your team can run this week, informed directly by what went wrong and right in this incident.

1. Confirm your network segmentation actually works

Suisun City's decision to shut down its entire network suggests the infection either was, or was assessed as likely to be, capable of spreading laterally across systems that should have been isolated from each other. Ask directly: can your critical systems — dispatch, emergency response, payment processing, customer data — actually be isolated from your general corporate network without shutting the entire organization down? If the honest answer is "not without turning everything off," that's a segmentation gap worth fixing before an incident forces the question.

2. Verify your incident response plan names a specific, tested continuity path

The single most important operational fact in this incident is that Suisun City had somewhere to route 911 calls when its own system went down. That backup wasn't improvised in the moment — it existed as a known, activatable option. Does your organization have a specific, named, tested fallback for your most critical function if your primary system has to go offline entirely? "We'd figure something out" is not a continuity plan.

3. Check whether critical infrastructure is exposed to the general internet unnecessarily

A recurring theme across expert and public commentary on this specific incident is a direct question: why do systems this critical need general internet connectivity at all? Audit your own infrastructure for exactly this — dispatch systems, industrial control systems, critical databases — and ask whether each one's internet exposure is a deliberate, necessary design decision or an inherited default nobody has revisited.

4. Confirm your team knows how to preserve evidence, not just stop the bleeding

Suisun City's shutdown decision explicitly served two purposes: containment and evidence preservation for a federal investigation. Under real incident pressure, the instinct to immediately wipe and restore systems is strong — and it can destroy the forensic evidence needed to actually determine how the breach happened and whether it's fully resolved. Confirm your incident response plan includes an explicit evidence-preservation step before remediation begins, and that whoever is on call actually knows the difference.

5. Know your state's emergency declaration mechanism in advance

California Government Code 8630 gave Suisun City fast access to emergency resources and a path to cost recovery — but only because the mechanism already existed and the city knew how to invoke it under pressure. If you're a public sector or critical infrastructure organization, know your equivalent legal and administrative mechanisms before an incident, not while you're in the middle of one.

6. Test your actual mean-time-to-detect

The malware began compromising systems at approximately 5:45 a.m. Friday. The full picture wasn't publicly confirmed and acted on until a special council meeting the following morning. That gap — however it broke down internally between detection, escalation, and decision — is worth measuring in your own environment. How long would it take your team to detect, escalate, and make a full-shutdown-level decision if the same thing happened to you at 5:45 a.m. on a Friday?


Preventive Actions Worth Taking Now

Beyond auditing your current posture, here are concrete steps that reduce the odds of ending up in Suisun City's position in the first place.

Segment critical systems by default, not by exception. Emergency dispatch, payment processing, and any system where downtime has physical-world consequences should sit on isolated network segments with tightly controlled, monitored connections to the rest of your infrastructure — not general network access that happens to include them.

Maintain a tested, named fallback for every mission-critical function. Not a hypothetical plan — an actual documented, periodically tested procedure, the way Suisun City's dispatchers could immediately start routing through Solano County because that arrangement already existed and worked.

Run tabletop incident response exercises that include the "shut everything down" decision specifically. Most incident response drills focus on detection and remediation. Fewer organizations actually practice the harder call: when do you accept the operational cost of a full shutdown versus attempting a more surgical, partial containment that risks the malware spreading further? Practicing that decision under simulated pressure, before it's real, measurably improves how fast and how well it gets made when it counts.

Audit every system with unnecessary internet exposure. For any critical system, ask explicitly: does this need to be reachable from the general internet, or has it simply always been configured that way? Air-gapping or strict network isolation for genuinely critical infrastructure remains one of the highest-leverage, lowest-glamour security investments available.

Invest specifically in detection speed, not just prevention. Prevention will eventually fail against a sufficiently motivated or lucky attacker. The organizations that come through incidents like this one with minimal harm are consistently the ones that detect and respond fast — not the ones that never get targeted at all. Monitoring, alerting, and a genuinely fast escalation path are not optional extras.

Know your legal and financial recovery mechanisms before you need them. Whether it's a state emergency declaration process, cyber insurance, or a specific federal assistance program, understand what's available to your organization and how to invoke it, well before an actual incident forces you to learn on the fly.

Build the muscle memory for public communication under pressure. Suisun City's public messaging was consistent, clear, and specific — 911 services remain active, calls are rerouted through county dispatch, there is no imminent threat. That kind of calm, factual public communication during an active incident is itself a skill worth rehearsing, not something to improvise for the first time during a real crisis.


Key Takeaways

  • Suisun City, California declared a state of emergency after malware compromised its IT systems on August 7, 2026, disrupting 911 routing, police and fire dispatch, records, and general city services — the city shut down its entire network to contain the threat and preserve forensic evidence.

  • The city's continuity plan worked because it existed and was actually testable in advance — dispatchers immediately began routing 911 calls through the Solano County dispatch center, keeping emergency response functioning throughout the incident.

  • This incident is direct evidence against "we're too small to be a target." A city of under 30,000 people was hit hard enough to warrant a full network shutdown and a formal state of emergency — smaller, less-resourced organizations are not safe by virtue of being small.

  • Six concrete checks worth running this week: network segmentation, tested continuity paths, unnecessary internet exposure on critical systems, evidence-preservation procedures, awareness of your emergency-declaration mechanisms, and your actual mean-time-to-detect.

  • This fits a broader 2026 pattern, not an isolated event — reporting on this incident directly references concurrent attacks on U.S. water systems across multiple states and earlier federal warnings about state-backed actors targeting American infrastructure.

  • Prevention will eventually fail; detection speed and tested continuity plans are what actually determine outcomes. The organizations that weather incidents like this one well are the ones that detect fast and have a real fallback ready — not the ones that assume they'll never be targeted.


Conclusion

The most useful thing about this incident isn't the attack itself — details on the actual intrusion vector remain undisclosed pending a federal investigation, and speculating further than the confirmed facts would be irresponsible. The useful thing is the response: a small city, under real pressure, made a series of defensible, well-executed decisions — aggressive containment, evidence preservation, an emergency declaration that unlocked resources, and a continuity plan that had actually been tested before it was needed.

Every organization running infrastructure it can't afford to lose should treat this as a live case study, not a distant headline. Run the six checks above this week. If any of them expose a real gap, that's not a failure — that's the entire point of running them before an incident forces the question at 5:45 a.m. on a Friday.


References


At Kynodex, we help organizations build the network segmentation, continuity planning, and detection infrastructure that determine whether an incident like this one becomes a contained disruption or a full-scale emergency. If your team needs a real security posture review before an incident forces the question, talk to us.


Powered by Synscribe

Comments

No comments yet. Be the first to start the conversation.

Ready to build?

Turn your AI vision into a production system

We build the AI infrastructure that powers your next stage of growth.

Book a Strategy Call