Suisun City Ransomware Attack: 30,000 Residents Locked Out as Council Weighs Extortion Demand | #ransomware | #cybercrime


Suisun.com

A city of roughly 30,000 residents in Northern California — staffed by a two-person IT department — is now in its seventh day of a ransomware shutdown that has taken down City Hall, knocked out ten municipal departments, and forced its elected council to meet in emergency closed session over a criminal extortion demand whose amount and origin have not been publicly disclosed. The attack on Suisun City is not an anomaly. It is a demonstration, repeated five times in a single week across four states, of how Ransomware-as-a-Service toolkits have systematically transformed small local governments into ransomware’s most reliable revenue source.

Malicious software began moving through Suisun City’s municipal network at approximately 5:45 a.m. on Friday, August 7, according to official Suisun City cybersecurity updates. The intrusion triggered the city’s automated network shutdown — a containment mechanism designed to halt lateral spread and preserve forensic evidence — but not before the malware had compromised systems supporting 911 routing, police and fire dispatch, public records, and public-facing city services. City dispatchers immediately shifted to the Solano County dispatch center, where 911 and non-emergency calls have continued to route without delay. Police and fire departments remain operational.

On Saturday, August 8, the City Council unanimously declared a state of emergency during a special session, unlocking faster access to emergency support and allowing the city to begin recouping costs from state and federal sources. By Monday, closures had expanded to cover Planning, Building, Housing, Water, Finance, Human Resources, Public Works, Administration, and the City Manager’s Office — effectively everything that is not emergency response. City Hall has been shuttered to the public since the attack began and is expected to remain closed through at least Friday, August 14.

On Tuesday, August 11, the City Council convened an emergency closed session to deliberate over demands from the person or persons responsible for the attack. The Infosecurity Magazine report noted the session would cover cybersecurity matters and anticipated litigation. The session’s outcome was not publicly disclosed. The council also received guidance from legal counsel regarding anticipated litigation, according to reporting from local outlets. Councilmember Princess Washington, who had posted about the session on LinkedIn, described the situation in terms that made the stakes plain: “Our records are hostage.”

Criminals Target Cities Where Downtime Pressure Exceeds the Ransom

Suisun City’s IT department consists of two full-time city employees and one third-party contractor. That three-person footprint is not unusual for a municipality its size. It is also, according to cybersecurity researchers, precisely the kind of structural condition that ransomware groups have learned to identify and exploit.

“Criminals see them as easy prey,” David Wagner, a professor at UC Berkeley’s Department of Electrical Engineering and Computer Sciences, said in reporting from KQED News. Chris Hoofnagle, faculty director at the UC Berkeley Center for Law & Technology, explained the financial mechanism: preventing a city from collecting taxes and processing payments is “quite coercive,” he said, adding that cities “might end up paying a ransom to unlock their systems.”

Security firm Huntress has documented this targeting logic explicitly: ransomware operators increasingly focus on high-availability sectors — emergency response, municipal water providers, healthcare — where downtime costs exceed ransom demands. A city cannot take its 911 dispatch system offline indefinitely. It cannot close water billing for months. The pressure to restore services is immediate, structural, and calculable — all of which ransomware operators factor into their pricing.

RaaS Has Lowered the Bar for Targeting Small Governments

The Ransomware-as-a-Service model has fundamentally changed who can execute a ransomware campaign. RaaS platforms — available on criminal dark-web marketplaces — supply affiliates with prepackaged toolkits: an encryption payload, a dedicated leak site for threatening data publication, a victim negotiation portal, and operational infrastructure. The affiliate conducts the intrusion and pays the platform operator a percentage of any ransom received. No advanced technical skill is required on the affiliate’s end. The barrier to entry for attacking a two-person IT team is, functionally, a subscription fee.

Verizon’s 2025 Data Breach Investigations Report found ransomware present in 44% of all breaches analyzed — a 37% increase from the prior year. For small and medium-sized organizations specifically, ransomware appeared in 88% of all breaches, versus 39% for large enterprises. The asymmetry is structural: smaller organizations have weaker incident response capability, slower patch cycles, and under-resourced security teams — conditions that RaaS affiliates can identify and price against.

Between 2018 and 2024, ransomware attacks on U.S. federal, state, and local government entities totaled an estimated $1.09 billion in downtime, across 525 documented incidents, according to a 2026 report from the Information Technology and Innovation Foundation. The government sector saw a 65% surge in ransomware incidents in the first half of 2025 compared to the same period a year earlier, according to research from Comparitech. On average, a ransomware attack on a government entity results in nearly a month of downtime — 27.8 days — at a daily cost of approximately $83,600.

Suisun City Is Not the Bay Area’s First Rodeo

The pattern has become familiar in the region. Earlier in 2026, Foster City declared a state of emergency after a March ransomware attack paralyzed nearly all of its internal government operations, taking phone and email communications offline for more than a week. In February, the city of Pittsburg lost nearly $1 million to a phishing-enabled fraud — most of which was later mostly recovered. In 2023, a ransomware attack on the city of Oakland exposed sensitive employee and resident data and triggered multiple lawsuits. In April 2024, Solano County’s own library system — the same county now providing backup dispatch services to Suisun City — had its public internet and computer services disrupted for nearly four months after attackers demanded a $100,000 ransom.

The same week Suisun City’s network went dark, the town of Coweta, Oklahoma — population roughly 12,000 — reported a ransomware attack on August 5 that disabled all computers, files, and digital services, though police and fire systems on separate off-site infrastructure were spared. Mitchell, South Dakota reported a network intrusion on August 8. Washburn County, Wisconsin, and Coryell County, Texas, also disclosed incidents the same week.

Does the Insurer Decide?

One dimension of the ransom payment deliberation that Suisun City’s public communications have not addressed is the role its cyber insurance policy may play in the outcome. Cybersecurity specialists engaged through the city’s cyber insurance coverage are active participants in the investigation and recovery. What the public record does not describe is the degree to which the insurer’s own financial calculus shapes the payment decision.

A 2019 ProPublica investigation into the ransomware insurance industry documented a recurring pattern: insurers’ preference for fast payment — to avoid recovery costs exceeding policy limits — effectively drove the decision in cities and institutions that believed they were exercising independent judgment. Lake City, Florida’s city spokesman described the outcome there directly: “Our insurance company made [the decision] for us.” Whether that dynamic applies in Suisun City’s closed-session deliberations is not publicly known. But the structural incentive exists regardless of what any individual insurer advises, and residents and elected officials alike have reason to understand it.

Why Does Pay vs. Refuse Matter to Readers?

The ransom payment question is not abstract to the 30,000 people who live in Suisun City, or to residents of any comparably sized municipality. Paying a ransom typically restores operations faster — and may, under the right cyber insurance terms, cost the city only a deductible. But payment funds the operators and affiliates who will use the proceeds to attack the next city. Not paying is more expensive in the short term: Baltimore chose not to pay in 2019 and spent an estimated $18 million on recovery, far exceeding the $76,000 demand. Atlanta spent approximately $17 million recovering from a 2018 attack after declining a $51,000 ransom.

Both paths involve costs that will, in some form, reach taxpayers — either as ransomware payments that incentivize future attacks, or as recovery expenditures that dwarf what the attacker demanded. What residents can do is demand that their municipalities treat cybersecurity investment as a public safety issue before the attack arrives, not a budget line to minimize until it does.

The city officials with no documented technology policy background — neither Councilmember Washington nor Mayor Alma Hernandez has a publicly recorded history of technology legislation or cyber policy engagement — are now navigating a decision that has significant financial and structural implications for their community. That is not a criticism; it reflects how local government is structured across thousands of similar cities nationwide. It is also the point. Decisions of this complexity should not arrive without warning, with City Hall shuttered and a deadline from an anonymous attacker.

How to Reach Suisun City During the Shutdown

The Police Department lobby remains open Monday through Thursday for in-person assistance, vehicle releases, and ticket sign-offs. For residents who need to reach city departments that remain closed — Planning, Building, Housing, Water, Finance, HR, Public Works, or Administration — the city has encouraged email contact before visiting downtown in person. Emergency 911 and non-emergency calls continue to route through Solano County dispatch without delay.

The FBI, DHS, and Cal OES have declined to publicly characterize the incident or name the attacker. The ransom amount remains undisclosed. Full IT restoration carries no publicly stated timeline, though Suisun City is not alone: the average government entity hit by ransomware takes 27.8 days for full recovery. For a city of 30,000 with a two-person IT department, that figure is not a comfort.


Frequently Asked Questions

Should Suisun City pay the ransom?

There is no universally right answer, and the question is more complicated than it appears. Payment typically restores operations faster and may be partly covered by cyber insurance. But ransom payments fund the criminal infrastructure used to attack the next city. Cities that have refused to pay — Baltimore and Atlanta are the prominent examples — have ultimately spent far more on recovery ($18 million and $17 million, respectively) than the original demands ($76,000 and $51,000). Suisun City’s decision will also be shaped by whether its cyber insurer recommends payment to avoid exceeding the policy’s coverage limits — a documented dynamic in similar city-level incidents in which insurers effectively controlled the outcome.

Why are small cities such common ransomware targets?

Ransomware-as-a-Service platforms have made it possible for affiliates with minimal technical skill to deploy sophisticated attack toolkits against any target. Small cities are particularly attractive because they typically maintain two- to three-person IT teams, limited security budgets, aging infrastructure, and high-availability services — 911 dispatch, water billing, permit processing — that cannot stay offline. Attackers calculate that the cost of restoring these services exceeds the ransom demand, creating structural pressure to pay quickly. Verizon’s 2025 Data Breach Investigations Report found ransomware present in 88% of small-organization breaches, compared to 39% at large enterprises.

What can residents do if they can’t access Suisun City services?

Emergency services remain fully operational. Residents can reach 911 and non-emergency dispatch through the Solano County center without delay. The Police Department lobby is open Monday through Thursday. For non-emergency city services — permits, water billing, planning questions — residents should contact city departments by email rather than visiting in person until City Hall reopens. The city has not announced a restoration timeline.

What is Ransomware-as-a-Service, and why does it matter for cities like Suisun City?

Ransomware-as-a-Service is a criminal business model in which a platform operator provides prepackaged attack tools — encryption software, negotiation portals, data-leak sites — to affiliates who conduct intrusions and split the ransom proceeds with the operator. RaaS has commoditized ransomware attacks: an affiliate no longer needs technical expertise to execute an enterprise-grade attack against a city with two IT employees. The attacker who hit Suisun City may not be a sophisticated threat actor at all — just a customer of a platform that specializes in high-pressure extortion of resource-constrained institutions.



Click Here For The Original Source.

——————————————————–

..........

.

.