Skip to content

Greenfield DDoS attack disrupts California internet

Summary

Greenfield Communications logo

A large-scale distributed denial-of-service attack disrupted Greenfield Communications internet, television and phone service in Rancho Murieta and other California communities beginning July 12, 2026. Most customers were restored July 14, but IP-geolocation problems continued affecting streaming applications and some remote work through July 17.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Complete service outage

    A primary service, system, platform, or operational capability became entirely unavailable.

  • Degraded service

    Services remained available but with reduced performance, reliability, functionality, capacity, or responsiveness.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Internet access disruption

    The organization lost or materially restricted internet connectivity.

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Payment processing disruption

    The organization could not process, receive, issue, reconcile, or record payments normally.

  • Transaction processing disruption

    Business, financial, customer, administrative, or operational transactions could not be completed normally.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Backlog created

    The disruption caused an accumulation of unprocessed requests, cases, orders, records, appointments, or other work.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

  • Staff unable to work normally

    Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

  • Third-party service disruption

    The incident materially affected services delivered by or through a vendor, managed service provider, contractor, partner, or other third party.

  • Downstream organization impact

    The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that a large-scale distributed denial-of-service attack disrupted Greenfield Communications’ fiber network in Rancho Murieta and other California communities beginning July 12, 2026. Greenfield initially described a denial-of-service threat; later company statements reported by the River Valley Times characterized the event as a DDoS attack affecting portions of its network infrastructure and other providers’ networks.

Greenfield said engineers isolated affected network portions, implemented temporary workarounds, verified stability and restored customers in phases. Most customers were back online July 14, but network changes produced incorrect IP-geolocation information that continued to interfere with streaming applications and some remote-work security controls. On July 17, Greenfield said its main network was stable while it continued working with streaming providers on the remaining geolocation problems.

Operational significance

The attack left much of Rancho Murieta without internet, television and phone service for more than two days and affected homes, businesses and government operations. Greenfield later announced an automatic two-week internet-service credit for affected subscribers.

The Rancho Murieta Community Services District lost office phone service and normal utility-payment processing. Employees used cellular hotspots to reach email and shared files, while gate officers manually recorded visitor information because the ABDI visitor-management system was unavailable. Mechanical gates remained operational, water and wastewater plants were not affected, and district security reported no interruption to security services or notable security incident.

The Rancho Murieta Country Club also lost phone service and experienced payment and point-of-sale disruption. Staff used cellular hotspots on July 14 until Greenfield service returned. The outage therefore caused documented downstream effects across public administration, access-control, payment and commercial operations without interrupting electric power or the district’s treatment plants.

Disclosure posture

Greenfield’s first customer-wide email on July 13 described a large-scale DDoS attack. The company later acknowledged that its communications during the outage were limited and said it had restricted public detail while the attack was underway to avoid compromising its response. Greenfield subsequently described its restoration process, resiliency improvements and customer credit, and CEO Mike Powers responded in writing to follow-up questions from the River Valley Times.

The reported scope remains partly unresolved. Greenfield said other providers’ networks were affected, while an AT&T spokesperson told the newspaper that AT&T infrastructure had not experienced a disruption. The reviewed evidence does not establish whether Greenfield, an upstream provider or multiple networks were direct attack targets.

Current status

The incident is presumed resolved. Most service returned July 14, and Greenfield said its main network was stable July 17. Residual IP-geolocation problems still affected some applications and remote work on July 17, and no authoritative source provided a later final all-clear or precise time when every affected service normalized.

Confidence and uncertainty

Confidence is high that the incident was a DDoS attack because Greenfield directly characterized it that way and described network isolation, workarounds and phased recovery. Confidence is high in the documented downstream operational effects because the district and affected business representatives described specific service failures and contingency procedures.

The public record does not indicate ransomware or extortion and does not identify an attacker. Data confidentiality and integrity impacts remain unknown; no source reported unauthorized access, theft, alteration, encryption or publication. The outage and loss of access to shared files establish temporary data unavailability for authorized district users but do not imply a breach.

Analytic gaps

The reviewed sources do not establish the attacker, motive, botnet, traffic sources, command infrastructure, traffic volume, mitigation provider, exact geographic footprint, subscriber count or whether law enforcement was involved. They also do not resolve whether an upstream provider was targeted or when the remaining geolocation issues fully cleared.

No public source identifies unauthorized access, affected data categories, record counts, notifications, a ransom demand, DDoS extortion, payment or longer-term financial impact beyond Greenfield’s customer credit and temporary business disruption.

Organizations involved

Impacted locations

Sources

Greenfield cyberattack disrupts internet in California community

A denial-of-service attack disrupted Greenfield Communications internet service in Rancho Murieta and elsewhere in Sacramento County for nearly 48 hours. Greenfield notified customers July 12 that it was responding to a denial-of-service threat; service began returning July 14, while the company did not identify an attacker or say whether customer data was accessed.

Rancho Murieta Community Services District service update

The district said internet and phone service had been restored and its billing department had reopened after the Greenfield outage. Staff were working through messages received while communications were unavailable.

Greenfield Outage Disrupts Service More Than Two Days

River Valley Times reported Greenfield’s July 16 customer statement and July 17 written CEO response confirming a large-scale DDoS attack, network isolation, temporary workarounds and phased restoration. Most customers were restored July 14, but incorrect IP geolocation continued affecting streaming applications and some remote work through July 17.

See something that needs correction?

Signed-in members can report an error, update, or missing source.