Skip to content

Foster City ransomware incident

Summary

City of Foster City, California logo

Foster City found ransomware on municipal networks March 19 and shut down its network, pausing most non-emergency public services while 911 and police dispatch remained operational. Phone and email connectivity returned March 27, but virtual services were still being restored; on April 7, the city still lacked full network access despite restoring permitting and recreation registration. No stable public actor claim was identified.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Complete service outage

    A primary service, system, platform, or operational capability became entirely unavailable.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

  • Email disruption

    Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.

  • Online portal unavailable

    A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

Extortion indicators

  • Unknown extortion indicators

    The incident may involve extortion, but available evidence does not establish which extortion indicators were present.

Incident narrative

Analyst assessment

Foster City identified ransomware on municipal networks March 19, 2026, and shut down its network, pausing most non-emergency public services. The city’s direct statement confirms ransomware involvement, but the public record does not establish encryption, a ransom demand or a responsible actor.

Operational significance

The network shutdown affected citywide operations, including phones, email, virtual services and public access to municipal functions. Emergency services, including 911 and police dispatch, remained fully operational. CBS San Francisco reported that phone and email connectivity returned March 27, while virtual services were still being reinstated and City Hall offered limited services.

Recovery remained incomplete in April. The San Mateo Daily Journal reported on April 7 that the city still had not regained full network access. Permitting and parks and recreation registrations had returned, but e-TRAKiT and RecTrac were still under evaluation. The affected geography is Foster City in San Mateo County, California.

Current status

The incident is presumed resolved. April 7 is the last documented operational-impact date, and no later continuing impact was found. The public record does not provide an affirmative full-restoration date.

Confidence and uncertainty

Confidence is high that ransomware caused the citywide network and service disruption because Foster City directly identified ransomware. Data impact and extortion details remain unresolved: the city initially investigated possible access to sensitive information but did not confirm compromise, encryption, a demand or ransom terms. Searches using the city’s canonical name and fostercity.org found no stable public actor claim.

Analytic gaps

The public record does not establish the access vector, ransomware family, encryption scope, data-access scope, ransom terms, payment status, responsible actor or final restoration date.

Organizations involved

Impacted location

Sources

Foster City, California, ransomware incident halts most city services

Foster City identified ransomware on municipal networks and paused most non-emergency services; 911 and police dispatch remained operational.

Foster City services impacted by cybersecurity breach

The city said ransomware was identified on its networks, most services were paused and emergency response functions remained available.

Foster City makes progress in restoring services following ransomware attack

Foster City said phone and email connectivity was restored March 27, while virtual city services were still being reinstated and City Hall continued to offer limited services.

Foster City continues recovery from recent cyberattack

The Daily Journal reported April 7 that Foster City still lacked full network access. Permitting and recreation registration had returned, while e-TRAKiT and RecTrac remained under evaluation.

City of Foster City, California official website

The organization’s official website describes its identity, services, operating role and public or customer-facing programs.

Gazetteer Files

The Census Bureau Gazetteer Files provide authoritative geographic reference data for states, counties, county equivalents and places in the United States.

See something that needs correction?

Signed-in members can report an error, update, or missing source.