A city in Northern California is under a state of emergency after a cyberattack took down the city’s 911 dispatch system, officials said.
A citywide state of emergency was declared on Aug. 8 by the City Council of Suisun City, which has a population of around 29,000 and is located roughly northeast of the San Francisco Bay Area, officials said in a statement.
Officials found that “malicious software infected and compromised IT systems” on the morning of Aug. 7, according to the statement. The city will now be able to “quickly access emergency support services and to recoup costs incurred as a result of the cybersecurity incident” under the state of emergency, it said.
The attack, which officials only described as a “cybersecurity incident,” targeted Suisun City’s “critical public safety operations, including 911 routing, police and fire dispatch, records and City services.”
“To contain the threat and preserve evidence for a federal investigation, the City shut down its entire IT network,” officials said. “The City swiftly activated its Emergency Operations Center and is working alongside federal, state and regional agencies, including the FBI, Department of Homeland Security and California Office of Emergency Services to maintain emergency services, investigate the incident, and restore systems.”
While officials did not say where the attack may have originated, they cautioned that there is “no immediate threat to the public” and that emergency services are still active. An investigation into the matter is ongoing, the statement said.
Dispatchers for the city are taking emergency-related calls through the Solano County dispatch center, while police and fire officials are still responding to service calls, the city statement added. However, online services and some internal operations are not available.
The cyberattack comes as the FBI and the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) have both warned of cyberattacks against water systems in Minnesota and Michigan in recent weeks.
“At least seven states have reported incidents to the FBI, and some of that activity degraded water operations,” the FBI said.
“These threat actors are targeting water entities of all sizes,” CISA also said.
Tenable, a security exposure management company, suggested the cyberattack in Minnesota might be related to the U.S.–Iran conflict.
“Federal and state officials have not publicly attributed the Minnesota attacks to any specific actor,” Tenable said on July 28. “However, the operational pattern is consistent with the CyberAv3ngers threat ecosystem, a state-directed group the U.S. government has formally attributed to Iran’s Islamic Revolutionary Guard Corps Cyber-Electronic Command.”







