top of page

Suisun City Cyberattack Disrupts 911 Systems and Forces Emergency Declaration

  • 27 minutes ago
  • 2 min read

A malware attack knocked municipal systems offline in Suisun City, California, disrupting 911 routing, police and fire communications, and online government services while exposing the growing cyber risk facing local governments.


Suisun City has declared a state of emergency after a cyberattack forced officials to shut down the Northern California municipality’s IT network, disrupting systems connected to emergency communications and other government operations.


The incident affected communications used by the city’s police and fire departments, including the routing of 911 calls. Officials took the broader network offline to contain the attack and preserve evidence while federal authorities and cybersecurity specialists investigate.


Despite the disruption, emergency services remained operational. Dispatchers shifted police and fire calls to the Solano County dispatch center, providing a critical fallback while the city’s own technology environment remained unavailable.


That response highlights a cybersecurity issue extending beyond malware detection and incident containment: whether an organization can continue operating when its primary systems disappear.


“What happened in Suisun City shows why cyber recovery is fundamentally an operational resilience issue,” said Arvind Parthasarathi, CEO and founder of CYGNVS. “Malware affected systems supporting 911 routing, police and fire dispatch, records and other municipal services, forcing the city to shut down its IT network. The fact that dispatchers were able to shift 911 operations to Solano County and keep emergency calls moving is exactly the kind of continuity organizations need to plan for before an incident occurs.”


The attack comes as state and local governments face mounting cybersecurity pressure, particularly around systems responsible for essential public services. Smaller municipalities can present attractive targets because they often operate complex infrastructure with fewer cybersecurity resources than large enterprises or federal agencies.


For Suisun City, containing the intrusion is only one stage of the response. Bringing municipal systems back online requires investigators to determine which assets can be trusted and restored without reintroducing the threat.


“With the city’s systems still offline and every network function needing to be inspected and cleared before restoration, the next challenge is coordinating a safe recovery,” Parthasarathi said.


He said organizations should establish isolated communications environments that remain available when normal corporate networks fail, while bringing security, IT, legal, compliance and outside forensic specialists into the response.


“Those teams need tested playbooks and regular tabletop exercises so that when critical systems go down, they already have the muscle memory to maintain essential operations, investigate the incident, restore systems safely, and manage regulatory and stakeholder reporting.”


The Suisun City attack underscores a lesson increasingly relevant to government cybersecurity: preventing every intrusion may be impossible, but keeping critical services running does not have to be.

bottom of page