Cyberattacks Hit Local Governments in Four States, Disrupt 911 Services
A wave of cyberattacks has struck local governments across four U.S. states over the past week, disrupting 911 services, court operations, and essential public utilities. The most severe incident hit Suisun City, California, a 30,000-person town roughly 30 miles from Napa Valley, where malware compromised the city's IT network on Friday and took down 911 routing, police and fire dispatch, and records systems. The city shut down its entire IT infrastructure, activated emergency dispatch through the Solano County call center, and declared a state of emergency on Saturday to unlock recovery funding. The FBI is now investigating alongside federal and state partners.
In Coweta, Oklahoma, a ransomware attack last Wednesday encrypted all computers, files, and digital services across the town's 12,000-resident government. Fire and police departments remained operational using off-site systems, but city hall stopped accepting credit and debit card payments for utilities. Officials have pledged not to disconnect water service for nonpayment while backups are restored. Cybersecurity contractors have been engaged to clean the ransomware from systems before restoring data from offline backups.
Additional incidents were reported Friday in Mitchell, South Dakota, where attackers forced a full shutdown of government networks, and in Coryell County, Texas, and Washburn County, Wisconsin, both of which disclosed cyberattacks affecting court and county operations. In Mitchell, the mayor confirmed emergency services were unaffected, but the Davison County state's attorney's office instructed employees not to open any emails from city government domains—an indicator that initial intrusion vectors may involve phishing. Washburn County's phone and fax lines remained down through Monday, with court hearings disrupted.
The clustering of incidents across multiple jurisdictions in a single week highlights the vulnerability of municipal IT environments, many of which run legacy systems with limited segmentation. Security teams responding to similar events should prioritize network isolation, verify external-facing infrastructure with a port scanner, and audit SSL/TLS configurations on any exposed services via an SSL/TLS checker. For residents concerned about potential exposure of personal data, a breach check can confirm whether credentials appear in known leaks.