
Suisun City Cyberattack Shows Why 911 Needs a Tested Failover
Malware forced Suisun City to shut down its entire IT network, disrupting 911 routing and police and fire dispatch. A county-level failover kept emergency calls and field response operating.
Suisun City, California, declared a local state of emergency after malicious software compromised municipal systems on 7 August 2026. The incident reached beyond email and administrative applications: the city said it affected 911 routing, police and fire dispatch, records and other city services.
Officials shut down the entire city IT network to contain the threat and preserve evidence for a federal investigation. Suisun City activated its Emergency Operations Center and began working with the FBI, the US Department of Homeland Security, the California Governor’s Office of Emergency Services and regional partners.
The most important operational fact is that emergency response did not stop. Suisun City dispatchers shifted 911 and non-emergency call handling to the Solano County dispatch centre, while city police officers and firefighters continued responding to calls.
A rapid shutdown protected safety and evidence
The city dates the initial compromise to roughly 5:45 a.m. on Friday, 7 August. By Saturday morning, the City Council had held a special meeting and declared an emergency under California Government Code Section 8630. The declaration gives the city faster access to emergency support and a route to recover costs arising from the incident.
Taking an entire municipal network offline is disruptive, but it can be the correct containment decision when responders do not yet know how far an attacker has moved. Keeping systems online for convenience can allow malware to spread, give an intruder more time and contaminate evidence needed to understand the breach.
Suisun City’s response also shows why cyber incident plans for local government cannot end with restoring servers. They must identify which public services become safety-critical when their supporting technology fails, who has authority to disconnect systems and how those services continue outside the affected network.
The dispatch failover worked
In its latest published update, issued at 11:30 a.m. on 10 August, the city said police and fire response remained active and that dispatchers were still taking calls through the Solano County dispatch centre. The police lobby remained open for limited services, but City Hall was closed to the public that day. Online city services and internal operations remained temporarily unavailable.
This distinction matters. The attack disrupted the technology used to route and manage emergency calls; it did not eliminate the public’s access to responders because a regional workaround was available.
CISA guidance for emergency communications centres recommends continuity-of-operations plans that are maintained with partner agencies, tested alternate call-handling arrangements and procedures for working when normal dispatch or records systems are unavailable. Suisun City’s transfer to the county centre is the kind of dependency that must be agreed, exercised and understood before an emergency.
Failover capacity is not simply a second server. It includes trained people, radio and telephone paths, current contact lists, authority to exchange incident information and manual procedures for the period when computer-aided dispatch or records systems cannot be trusted.
What is confirmed (and what is not!)
The city has confirmed a compromise involving malicious software and a deliberate network shutdown. It has also confirmed disruption to 911 routing, dispatch, records and city services.
It has not publicly identified the malware, the initial access route or an attacker. There is no public confirmation that the incident was ransomware, that data was stolen, that a ransom was demanded or that the attack is connected to another campaign. Those possibilities should not be presented as facts while the investigation continues.
The lack of an immediate answer about data exposure is normal in a complex investigation. Responders first have to preserve logs and system images, remove attacker access, establish a trustworthy recovery environment and then determine what accounts, systems and records were reached.
The lesson for municipal networks
Emergency communications are increasingly dependent on IP networks, shared identity systems and data flows between call takers, dispatchers and responders. That improves speed and coordination, but it also expands the number of failures that can affect a public-safety workflow.
Municipalities and regional 911 partners should test several assumptions:
- 911 calls can be redirected to an alternate centre without relying on the compromised identity or network environment;
- dispatchers can reach field units through independent communications paths;
- manual call-taking and dispatch procedures are available, current and practised;
- privileged accounts, remote access and vendor connections are isolated and strongly authenticated;
- backups for dispatch, records and administrative systems are separated from normal production credentials;
- logs are retained outside the systems an attacker could disable; and
- public communications can continue when the normal website, email and phone directories are unavailable.
The Suisun City incident is still developing. Its most useful lesson is already visible, however: resilience came from the ability to move a critical function to a regional partner while the compromised environment was isolated. For a 911 operation, that operational fallback is as important as any preventive security control.
Sources and further reading
- City of Suisun City: Cybersecurity Incident Updates
- Los Angeles Times: Cyberattack forces emergency declaration in Suisun City
- DysruptionHub: Suisun City declares local emergency after malware disrupts 911 routing
- CISA: Considerations for Cyber Disruptions in an Evolving 911 Environment
- National 911 Program: Cybersecurity resources for emergency communications
- Solano County: Emergency Communications Center
Continue the series: AMER Cyber & Digital Law Series index



