City of Foster City, California

Ransomware detected March 19 disrupted Foster City’s municipal services, with staged recovery continuing in April. A later city notice confirmed unauthorized access from Feb. 28 to March 25 and possible viewing or acquisition of personal-information files; no actor or final restoration date is established.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
Unauthorized access to systems, accounts, networks, or data.
An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
A primary service, system, platform, or operational capability became entirely unavailable.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.
A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
The incident may involve extortion, but available evidence does not establish which extortion indicators were present.
Foster City identified ransomware on municipal networks March 19, 2026, and shut down its network, pausing most non-emergency public services. The city’s direct statement confirms ransomware involvement, but the public record does not establish encryption, a ransom demand or a responsible actor.
The network shutdown affected citywide operations, including phones, email, virtual services and public access to municipal functions. The city said 911 and police dispatch remained operational. The Record reported March 20 that the police department’s direct emergency and non-emergency telephone lines were temporarily unavailable and subsequently restored. Those direct lines are distinct from 911 and dispatch; their interruption does not establish a loss of emergency response. CBS San Francisco reported that phone and email connectivity returned March 27, while virtual services were still being reinstated and City Hall offered limited services.
Recovery remained incomplete in April. The San Mateo Daily Journal reported on April 7 that the city still had not regained full network access. Permitting and parks and recreation registrations had returned, but e-TRAKiT and RecTrac were still under evaluation. The affected geography is Foster City in San Mateo County, California.
A city breach-notification sample filed with California’s attorney general confirms that an unauthorized party accessed certain municipal systems between Feb. 28 and March 25, 2026. The city said files may have been viewed or acquired. Its personal-information review concluded June 10, and recipients were offered one year of monitoring. The redacted template identifies names but leaves other recipient-specific data fields unspecified. It reports no known misuse and no affected-person total.
The notice establishes unauthorized system access, not confirmed theft of files or publication. Feb. 28 is the earliest documented intrusion date; March 19 remains the detection and public-disclosure date. March 25 is the reported end of access, not a service-restoration date.
The incident is presumed resolved. April 7 is the last documented operational-impact date, and no later continuing impact was found. The public record does not provide an affirmative full-restoration date.
Confidence is high that ransomware caused the citywide network and service disruption because Foster City directly identified ransomware. The later city notice confirms unauthorized system access and possible viewing or acquisition of personal-information files. Actual exfiltration, encryption, public release, demands and ransom terms remain unestablished. Searches using the city’s canonical name and fostercity.org found no stable public actor claim.
The public record does not establish the access vector, ransomware family, encryption scope, exact data categories and affected-person count, confirmed exfiltration, ransom terms, payment status, responsible actor or final restoration date.

Municipality-level physical administrative anchor for city government, whose City Hall is at 610 Foster City Blvd.; not an assertion that every facility was offline.
Municipal service remit, not an area-wide outage or loss of every function; 911 and dispatch continued.
Foster City identified ransomware on municipal networks and paused most non-emergency services; 911 and police dispatch remained operational.
The city said ransomware was identified on its networks, most services were paused and emergency response functions remained available.
Reports restoration of temporarily unavailable police direct phone lines, distinct from continuing 911 and dispatch.
Foster City said phone and email connectivity was restored March 27, while virtual city services were still being reinstated and City Hall continued to offer limited services.
The Daily Journal reported April 7 that Foster City still lacked full network access. Permitting and recreation registration had returned, while e-TRAKiT and RecTrac remained under evaluation.
Retrospective reference to Foster City’s March shutdown.
The Census Bureau Gazetteer Files provide authoritative geographic reference data for states, counties, county equivalents and places in the United States.
City notice confirms unauthorized access Feb28–Mar25 and possible viewing or acquisition of files.
The organization’s official website describes its identity, services, operating role and public or customer-facing programs.
Signed-in members can report an error, update, or missing source.