Suisun City, California
Most breaches expose what you bought. This one reached the records of who called 911.
What happened?
Suisun City, California reported a cyber incident affecting municipal systems, with reporting indicating impact to 911 routing and police and fire dispatch records. Scope remains under investigation and specific data types have not been publicly detailed.
Suisun City has a population of roughly 29,000. No threat actor has been publicly attributed as of this writing.
What data was actually inside?
Not yet disclosed. Reporting identifies 911 routing and dispatch systems as affected.
What a computer-aided dispatch record contains, as a matter of how the system functions and labeled here as inference: the caller's name and callback number, the address the call originated from, the nature of the emergency as coded by the dispatcher, the units assigned, and the timestamps of the response. Many CAD systems also carry narrative free-text fields where dispatchers record what the caller said.
Read across several years, that is a record of every domestic violence call, overdose, psychiatric crisis, and death in a city, tied to street addresses.
Who gets hurt and how?
Residents who called for help, which is a different population from the residents of any other breach in this series. Nobody opts into a dispatch record. It is created because something went wrong.
The harm is disclosure rather than fraud. A record showing police were dispatched to an address for a mental health crisis, an overdose, or a domestic incident is damaging in ways credit monitoring does not touch — in custody proceedings, in employment, in housing, and among neighbours. Domestic violence victims are a specific concern: a dispatch history can confirm to an abuser that a partner called police, and can confirm a current address.
The people most exposed are the people who were already having the worst day of their lives.
What did they think they were doing right?
Public safety systems are usually treated as the crown jewels of a municipal network, and for the right reason: availability. Dispatch has to work at three in the morning during a power cut. Redundancy, failover, and continuity planning get genuine attention and budget, because a dispatch outage is an immediate threat to life.
Confidentiality is the axis that receives less attention. The operational risk everyone rehearses is the system going down, not the archive going out. Retention is typically set to indefinite because records may be needed for litigation, and nobody writes a deletion policy for evidence.
What did they not know about their own data?
Dispatch data is a category most data classification schemes have no entry for, because most organisations do not hold it. Classification models are built around identity elements — Social Security numbers, financial accounts, health records under HIPAA. A CAD narrative describing a psychiatric crisis at a named address matches none of those definitions while being more damaging to the individual than any of them.
Small municipalities compound the problem structurally. Dispatch is frequently operated jointly with a county or a neighbouring city, hosted by a regional authority, maintained under contract, and integrated with records management and mobile data terminals in patrol vehicles. The number of copies is larger than the city's own IT footprint, and no single party owns the map.
If your business runs on databases, you probably have similar records—customer data, credentials, financial information. Do you know what's actually in yours?
What does attribution look like the morning after?
California's breach notification statute is triggered by unauthorised acquisition of personal information as the statute defines it, with SB 446 imposing a 30-day notification requirement effective January 1, 2026; filings appear on the California AG breach list. Whether a dispatch narrative meets that definition is a genuine legal question rather than a rhetorical one, and the answer may well be no.
Which produces the difficult scenario. The most harmful records in the incident may carry no notification obligation at all, while an incidental spreadsheet of employee data triggers the full process. There are additional overlays for law enforcement records — CJIS security policy requirements, and evidentiary integrity questions if case records were altered rather than merely read. A city of 29,000 has no in-house capacity for any of this.
What would have changed the outcome?
A classification model that rates records by harm to the person rather than by whether a statute names the field — and an inventory built on that model.
Your most sensitive record type is often the one no notification law describes. Dispatch narratives, treatment rosters, shutoff lists, and safeguarding files all share that property: severe consequences on disclosure, no statutory trigger, and therefore no compliance pressure to inventory them. If the only data your organisation has mapped is the data a regulator forced you to map, the gap is precisely where the worst harm lives. See also our analysis of the Organization for Transformative Works breach, where an email address was the most dangerous field in the file.
Suisun City found out the hard way.
Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.