Prevent This: When Your City Goes Offline
Ransomware gangs are targeting small towns because they know they'll pay. Here's how you can be ready if your city goes dark.
Last week, residents of a small California city woke up to find that all of their city’s services were offline and non-operational due to a cyberattack. Calling 911 didn’t work. No one could pay a water bill, pull a building permit, or reach anyone at City Hall. We will dive into how it happened and what you can do to be ready in case your city goes off-line.
What Happened in Suisun City
At 5:45 a.m. on Friday, August 7, malicious software hit the IT systems serving Suisun City, a community of about 29,500 people in Solano County, roughly 50 miles northeast of San Francisco. The city’s automated intrusion detection caught it, and administrators immediately shut down the entire network to stop it from spreading.
That was the right call. It also meant that nearly every digital service the city provides went dark at the same time.
911 calls had to be rerouted to the Solano County dispatch center. Police and fire dispatch systems went offline. Bill payment, records management, and building permits all became unavailable. City Hall ground to a halt.
By Saturday morning, the City Council voted unanimously to declare a State of Emergency. The FBI, DHS, and the California Office of Emergency Services are all investigating. As of today, the city’s systems remain offline. Officials have not confirmed what type of malware was involved, whether any data was stolen, or who is responsible.
This Keeps Happening
Suisun City is the third Bay Area municipality to be hit by a cyberattack in 2026 alone.
In March, Foster City declared a state of emergency after a ransomware attack shut down city services for more than a week. Earlier in the year, Pittsburg, California dealt with its own cyber incident. Now Suisun City.
These are not large cities with dedicated cybersecurity teams. They are mid-size communities where a handful of IT staff manage everything from email to emergency dispatch, running the same services as a major city on a fraction of the budget.
That gap is why attackers target them. Same pressure to restore services. Fewer resources to do it without paying. The FBI ranked government facilities as the third most targeted sector by ransomware in 2025, behind healthcare and critical manufacturing.
Who Does This and Why
Officials have not attributed the Suisun City attack to any specific group. The investigation is ongoing. But the broader pattern is well documented.
The financial logic
Ransomware crews target organizations that run essential services on tight budgets. A city that cannot dispatch police, a hospital that cannot access patient records, a school district that cannot run payroll: hard deadlines, no room to wait. Attackers price accordingly.
In 2025, 72% of state and local government organizations that were hit by ransomware paid the ransom, the highest rate of any sector (per Sophos). The median payment was $2.5 million. Average total recovery cost: $2.83 million, more than double the prior year.
It is not just criminals
Nation-state actors are in this space too. In late 2023, CyberAv3ngers, a group affiliated with Iran’s Islamic Revolutionary Guard Corps, began attacking water and wastewater systems across the US. They exploited default passwords on industrial control systems at facilities in Pennsylvania, Georgia, South Dakota, and at least nine other states.
In July 2026, a coordinated attack attributed to the same group hit more than 30 community water systems in Minnesota in a single weekend. A joint advisory from the FBI, CISA, the NSA, and three other federal agencies confirmed the group has expanded to target energy, healthcare, manufacturing, and government services.
The Suisun City attack has not been linked to CyberAv3ngers or any Iranian group. Federal investigators reportedly suspect Iranian involvement, but no formal attribution has been made. The point is not to assign blame here. Small-city infrastructure is now a target for both criminal organizations and nation-state actors.
How they get in
These attacks rarely involve exotic techniques. The most common entry points (Verizon DBIR, 2025):
Unpatched VPN and remote-access equipment. Confirmed entry point in 73% of network intrusions (Coalition, 2025). Attackers scan the internet for VPN appliances with known vulnerabilities and walk through the front door.
Stolen or weak credentials. 22% of breaches. Shared passwords, reused credentials, no multi-factor authentication.
Phishing emails. A city employee clicks a link or opens an attachment. In public administration, 69% of breaches involve a human element.
These are not sophisticated zero-day exploits. They are unlocked doors.
What This Means for You
You probably do not manage your city’s IT systems. But you depend on them, and there are things worth doing before the next incident.
1. Save your county’s backup dispatch number.
In Suisun City, 911 still worked because calls were rerouted to Solano County. In some jurisdictions, that handoff is not automatic. Find your county sheriff or county dispatch non-emergency number and save it in your phone. If 911 goes down, that number still reaches someone who can send help.
2. Keep paper copies of critical documents.
When city systems go down, so do digital records. If you are in the middle of a building permit, property transaction, or business license renewal, keep your own copies. Printed confirmations, permit numbers, and correspondence protect you if systems are offline for weeks.
3. Know how to pay without the portal.
When online bill payment goes down, your bills do not. Utility payments, property taxes, and fees can go into default while systems are being restored. Know how to pay by check, by phone, or in person. Set calendar reminders for due dates.
4. Sign up for your city’s emergency alerts.
Search “[your city name] emergency alerts” or check your city’s website. During an incident, official channels are the only reliable source of information about what services are available and what workarounds exist.
5. Watch for scam emails referencing the attack.
After every publicized cyberattack, scammers send phishing emails pretending to be the affected organization. Expect emails asking you to “verify your account” or “update your payment information.” Your city will never email you asking for passwords or payment card numbers. Delete it. Go directly to your city’s official website (type the address yourself) for real updates.
What Should Your City IT Staff Be Doing?
The steps above are things you can do personally. The next six are for your city, your employer, your school district, or any small organization. If you sit on a city council, serve on a school board, or run a small business, these apply directly. If not, they are worth asking about at your next public meeting.
1. Test the backups, not just make them.
A backup that has never been tested is a hope, not a plan. CISA recommends the 3-2-1 rule: three copies of your data, two different storage types, one copy offline. The offline copy is critical. If backups are on the same network as everything else, the attackers encrypt them too. The question to ask: “When was the last time we tested restoring from our offline backups?”
2. Require multi-factor authentication on every account.
If any employee, contractor, or vendor can log in with just a username and password, that system is vulnerable. MFA (a second verification step, like a code from your phone) blocks the vast majority of credential-based attacks. It is the cheapest improvement any organization can make.
3. Separate the critical systems from everything else.
In Suisun City, the attack took down 911 dispatch, building permits, bill payment, and internal operations all at once. When every system is on the same network, one breach reaches everything. Network segmentation puts walls between systems so that a compromised email server cannot reach 911 dispatch. Those systems should not be able to see each other.
4. Have an incident response plan. Practice it.
Suisun City’s response was solid: intrusion detection caught it, they shut down the network to contain it, declared an emergency for state and federal resources, and communicated with residents early. That sequence does not happen by accident. CISA provides free tabletop exercise packages (100+ templates) that walk organizations through ransomware scenarios with facilitator guides included.
5. Use the free federal help that already exists.
CISA offers free cybersecurity services for organizations that cannot afford commercial alternatives:
Free vulnerability scanning: CISA’s Cyber Hygiene program scans your internet-facing systems weekly. Organizations see roughly 40% risk reduction in the first year. Enroll at vulnerability_info@cisa.dhs.gov.
Free phishing assessments: Simulated phishing campaigns to test employee awareness.
Free incident response: If you are attacked, CISA will deploy analysts remotely or on-site, no charge.
Regional Cybersecurity Advisors: CISA field staff for hands-on local guidance.
SLCGP grants: $91.7 million in FY2025, 80% required to pass through to local governments.
6. Patch the remote-access equipment first.
VPN appliances, firewalls, and remote-access tools are the most common entry point. When a security update comes out for a Fortinet, SonicWall, Cisco, or Ivanti device, it needs to be applied within days, not months. Many municipal attacks in 2025 and 2026 exploited vulnerabilities that had patches available for months. The fix existed. It just had not been installed.
The Bigger Picture
The services that run a city are all software now. Dispatching police, treating water, processing building permits, managing traffic signals. That transition made those services faster and cheaper. It also made them attackable.
A fire station does not stop existing when the network goes down. Firefighters still show up. But the system that tells them where to go can be degraded or gone. The difference between a five-minute response and an eight-minute response is measured in outcomes.
Free federal resources exist. Grant money exists. The gap is awareness. Most small-city councils do not know these programs are available, and most residents do not know to ask.
The question is not whether your city will be targeted. It is whether you and your city will be ready when it is.
Stay safe out there.
Questions? Feedback? Reply to this email or reach us at contact@intruvent.com.





