Skip to content

Foster City ransomware incident

Summary

City of Foster City, California logo

Ransomware detected March 19 disrupted Foster City’s municipal services, with staged recovery continuing in April. A later city notice confirmed unauthorized access from Feb. 28 to March 25 and possible viewing or acquisition of personal-information files; no actor or final restoration date is established.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

Data impacts

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Complete service outage

    A primary service, system, platform, or operational capability became entirely unavailable.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

  • Email disruption

    Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.

  • Online portal unavailable

    A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

Extortion indicators

  • Unknown extortion indicators

    The incident may involve extortion, but available evidence does not establish which extortion indicators were present.

Incident narrative

Analyst assessment

Foster City identified ransomware on municipal networks March 19, 2026, and shut down its network, pausing most non-emergency public services. The city’s direct statement confirms ransomware involvement, but the public record does not establish encryption, a ransom demand or a responsible actor.

Operational significance

The network shutdown affected citywide operations, including phones, email, virtual services and public access to municipal functions. The city said 911 and police dispatch remained operational. The Record reported March 20 that the police department’s direct emergency and non-emergency telephone lines were temporarily unavailable and subsequently restored. Those direct lines are distinct from 911 and dispatch; their interruption does not establish a loss of emergency response. CBS San Francisco reported that phone and email connectivity returned March 27, while virtual services were still being reinstated and City Hall offered limited services.

Recovery remained incomplete in April. The San Mateo Daily Journal reported on April 7 that the city still had not regained full network access. Permitting and parks and recreation registrations had returned, but e-TRAKiT and RecTrac were still under evaluation. The affected geography is Foster City in San Mateo County, California.

Data impact and intrusion chronology

A city breach-notification sample filed with California’s attorney general confirms that an unauthorized party accessed certain municipal systems between Feb. 28 and March 25, 2026. The city said files may have been viewed or acquired. Its personal-information review concluded June 10, and recipients were offered one year of monitoring. The redacted template identifies names but leaves other recipient-specific data fields unspecified. It reports no known misuse and no affected-person total.

The notice establishes unauthorized system access, not confirmed theft of files or publication. Feb. 28 is the earliest documented intrusion date; March 19 remains the detection and public-disclosure date. March 25 is the reported end of access, not a service-restoration date.

Current status

The incident is presumed resolved. April 7 is the last documented operational-impact date, and no later continuing impact was found. The public record does not provide an affirmative full-restoration date.

Confidence and uncertainty

Confidence is high that ransomware caused the citywide network and service disruption because Foster City directly identified ransomware. The later city notice confirms unauthorized system access and possible viewing or acquisition of personal-information files. Actual exfiltration, encryption, public release, demands and ransom terms remain unestablished. Searches using the city’s canonical name and fostercity.org found no stable public actor claim.

Analytic gaps

The public record does not establish the access vector, ransomware family, encryption scope, exact data categories and affected-person count, confirmed exfiltration, ransom terms, payment status, responsible actor or final restoration date.

Organizations involved

Impacted location

  • Foster City, California

    Municipality-level physical administrative anchor for city government, whose City Hall is at 610 Foster City Blvd.; not an assertion that every facility was offline.

    Municipal service remit, not an area-wide outage or loss of every function; 911 and dispatch continued.

Sources

Foster City, California, ransomware incident halts most city services

Foster City identified ransomware on municipal networks and paused most non-emergency services; 911 and police dispatch remained operational.

Foster City services impacted by cybersecurity breach

The city said ransomware was identified on its networks, most services were paused and emergency response functions remained available.

Foster City makes progress in restoring services following ransomware attack

Foster City said phone and email connectivity was restored March 27, while virtual city services were still being reinstated and City Hall continued to offer limited services.

Foster City continues recovery from recent cyberattack

The Daily Journal reported April 7 that Foster City still lacked full network access. Permitting and recreation registration had returned, while e-TRAKiT and RecTrac remained under evaluation.

Gazetteer Files

The Census Bureau Gazetteer Files provide authoritative geographic reference data for states, counties, county equivalents and places in the United States.

City of Foster City — submitted breach notification sample

City notice confirms unauthorized access Feb28–Mar25 and possible viewing or acquisition of files.

City of Foster City, California official website

The organization’s official website describes its identity, services, operating role and public or customer-facing programs.

See something that needs correction?

Signed-in members can report an error, update, or missing source.