Skip to content

City of Santa Paula Cyber Incident

Summary

City of Santa Paula logo

Santa Paula reported a Nov. 12, 2025, citywide network outage affecting email and internal servers and potentially limiting city services. Qilin later listed the city as a claimed victim, but the city has not confirmed ransomware, data theft or the group’s responsibility.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Email disruption

    Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

Extortion indicators

  • Public leak threat

    The actor explicitly threatened to publish or publicly release victim data or incident details.

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

Incident narrative

Analyst assessment

The City of Santa Paula said in a Nov. 12 notice that a citywide network outage affected email and internal servers, with some services unavailable or operating at reduced capacity. Our Nov. 28 report linked that documented disruption to a later Qilin leak-site claim. The city itself did not identify a cyberattack or ransomware. The stable external claim supplies cyber-specific evidence, but the attack type and actor attribution remain unconfirmed by the victim.

Operational significance

City email and internal servers were unavailable, and officials warned of limited municipal services. The notice did not identify every department affected or report interruption to 911, police dispatch or water operations. Santa Paula is linked both as the municipal service area and the city-office physical anchor; the overlay does not mean every resident experienced a loss of service.

Claim and data uncertainty

Third-party monitoring observed Qilin naming Santa Paula and its spcity.org domain on Nov. 27. The group alleged stolen city data and threatened publication, but the reviewed article reported no publicly posted full sample files and no city verification of exfiltration. Qilin’s general practice elsewhere cannot establish that this particular outage involved encryption or data theft.

Current status

The city had not announced a comprehensive restoration date in the reviewed material. With no documented continuing disruption after November 2025, operational status is presumed resolved pending an official all-clear.

Confidence and uncertainty

Confidence is high in the outage because the city acknowledged it. Confidence in ransomware and Qilin responsibility is low because it rests on an unverified claim. The initial access route, affected systems beyond email and servers, data impact, ransom demand and recovery details remain open. A fresh claim-index search did not return a matching listing; the Qilin claim remains grounded in contemporaneous reporting, not an official attribution.

Threat actor and claim

Listed as: Santa PaulaSource: otherPublished:

Claim details

Qilin listed Santa Paula and spcity.org as a claimed victim; city did not verify attribution or data theft.

Organizations involved

Impacted location

Sources

Qilin claims ransomware hit on Santa Paula, California

Ransomware gang Qilin says it breached the city of Santa Paula, California, after officials reported a Nov. 12 network outage that knocked out city email and limited some services.

See something that needs correction?

Signed-in members can report an error, update, or missing source.