Timeline diagram of the City of Modesto Police Department ransomware attack, data breach notification, five-week recovery, $1M cost, and later risk-assessment governance gaps
Back to Blog
GOVERNMENT Insights Published May 18, 2026 Updated August 23, 2026 14 min read

City of Modesto Ransomware Attack Timeline and Lessons

City of Modesto data breach 2025-2026 facts: Modestogov.com searches, Stanislaus County ransomware questions, the 2023 Police attack, and readiness lessons.

Dan J Sturdivant, Vice President at Datapath

By

Dan J Sturdivant

Vice President

Modestoransomwaremunicipal

Quick summary

  • The City of Modesto's February 2023 ransomware attack disabled Modesto Police Department systems for roughly five weeks, exposed employee Social Security and driver's license numbers, and cost the city more than $1 million in recovery and tooling.
  • City of Modesto data breach 2025-2026 and Modestogov.com breach searches appear to point to the verified 2023 Police Department ransomware attack, not a separately confirmed new city breach in 2025 or 2026.
  • A later enterprise risk assessment found the city still needed comprehensive IT policies, data governance, access-control and data-privacy policies, periodic penetration testing, earlier detection, MFA coverage, immutable backups, and a tested restoration order.

What happened in the City of Modesto ransomware attack?

The City of Modesto ransomware attack was a February 2023 ransomware incident in which the Modesto Police Department’s IT network was compromised, personally identifiable information was accessed, patrol-vehicle laptops and police technology were disrupted, and the city incurred a roughly five-week, $1 million-plus recovery effort.1234

If you searched for City of Modesto data breach ransomware 2025 2026, City of Modesto cyber attack 2025 2026, or Modesto Bee data breach 2025 2026, the public record still points back to the verified 2023 Police Department ransomware event, the later enterprise risk-assessment findings, and ongoing local scrutiny rather than a separately confirmed new City breach in 2025 or 2026. Confirm any new claim against the California Attorney General breach-notification list before treating it as a new incident.56

The practical answer is this: there was a verified Modesto Police Department ransomware and data-breach event in 2023; 2025-2026 searches are largely about later reporting and the enterprise risk assessment that documented unfinished policy, governance, and penetration-testing work. For municipal and mid-market leaders, the story is less about a headline and more about what must be fixed before the next incident.

This post walks through what actually happened, what it cost, what the risk assessment found, and what mid-market and municipal IT leaders should take away from it. We are based in Modesto. We work with regulated organizations across the Central Valley. We do not enjoy writing about local incidents, but we believe security maturity in our region only improves when leaders look at the facts honestly. For context on how Datapath approaches that, see our cybersecurity consulting in Modesto overview.

Need a Modesto ransomware readiness review?

Datapath helps local organizations assess identity controls, endpoint coverage, backup recoverability, vendor access, data governance, and incident-response ownership before a breach turns into a public recovery effort.

Review Modesto cybersecurity services

Quick answers for current Modesto breach searches

Search behavior around the City of Modesto incident now blends public-record verification, Stanislaus County concerns, and local backup-readiness intent. Use the search phrase to decide whether you need facts, readiness work, or a recovery review.

Search phraseWhat the public record points toDatapath path
City of Modesto data breach ransomware 2025 2026The verified 2023 Modesto Police Department ransomware and data-breach event, plus later 2025 risk-assessment discussion.Read the timeline below, then review Modesto cybersecurity services
Modestogov.com data breach 2025 2026City-hosted notices, agenda records, and risk-assessment materials connected to the 2023 incident and later governance findings.Confirm official notices, then start a cyber risk assessment
Stanislaus County ransomware breach 2025 2026 newsA county-level search pattern that should be verified separately from the City of Modesto incident before assuming the same affected systems or notice obligations.Use it as a prompt for Stanislaus County breach readiness
Data backup ModestoA local service need: confirm backups are isolated, restorable, tested, and tied to a restoration order before ransomware or system failure creates downtime.Review data backup and disaster recovery services

How should Modesto Bee and California city breach searches be verified?

Many searches around this incident use phrases such as Modesto Bee data breach 2025 2026, Modestogov.com data breach 2025 2026, City of Modesto cyber attack 2025 2026, and Stanislaus County ransomware breach 2025 2026 news. Treat those phrases as verification prompts, not as proof that a separate 2025 or 2026 breach occurred.

The Modesto Bee was a local reporting source for the City of Modesto Police Department ransomware story. Based on the public sources cited below, there is no separate, widely confirmed 2025 or 2026 data breach of the Modesto Bee newspaper itself. The verified thread is the 2023 Modesto Police ransomware incident, the city’s later risk-assessment findings, and broader Central Valley concern about municipal cybersecurity readiness.

Search patternSafer interpretationWhat to verify before acting
Modesto Bee data breach 2025 2026Usually a search for local coverage of the City of Modesto ransomware and data-exposure story, not confirmed proof that the newspaper was breached.Check whether the claim names the newspaper, the City, a vendor, or another organization.
Modestogov.com data breach 2025 2026Usually a search tying the City of Modesto domain to public notices, agenda records, and breach-verification questions.Check City notices, agenda packets, and the California Attorney General breach-notification list.
City of Modesto cyber attack 2025 2026Usually the 2023 Police Department incident resurfacing through later coverage and 2025 risk-assessment discussion.Separate incident date, notice date, risk-assessment date, and any later confirmed notice.
Stanislaus County ransomware breach 2025 2026 newsA county-level or local-news query that may overlap geographically but should not be treated as the same incident.Check county, city, vendor, insurer, and state filings separately.
Fresno, Hanford, Visalia, Barstow, or other California city breach searchesSimilar public-agency verification intent, sometimes triggered by local reporting or alleged actor claims.Confirm through official notices and credible reporting before assuming operational disruption or exposed data.

For residents, the strongest public source is usually the California Attorney General breach-notification database when a reportable California notice exists. For IT leaders, the useful action is to pressure-test the same controls that repeatedly appear in local breach coverage: information-security policy, data governance, privileged access, vendor access, endpoint monitoring, backup recoverability, incident-response ownership, and tested communications.

When did the City of Modesto cyber attack start and end?

According to letters the city later sent to affected individuals, unauthorized activity inside the Modesto Police Department’s digital network began on January 31, 2023, and was first detected by city staff on February 3, 2023.1 The city did not publicly confirm the incident until a follow-up statement after media inquiries, and only formally confirmed in early March 2023 that it was a ransomware event with potential exposure of Social Security numbers and driver’s license numbers.23

The Snatch ransomware group claimed responsibility, posted 15 files on its dark-web leak site that it said contained Modesto data, and began releasing portions of that data publicly in April 2023 — consistent with the typical “double-extortion” model where ransomware operators steal data first and threaten release if no ransom is paid.3

It took the city about five weeks to bring Modesto Police Department systems back online, including:2

  • patrol-vehicle mobile data computers (officers temporarily reverted to handheld radios and paper)
  • the department’s dispatch and records-adjacent tools
  • internal Police Department network access

Through it all, 911 call answering and emergency response stayed operational. That was the right priority, and the city deserves credit for protecting it.

What did the City of Modesto ransomware attack actually cost?

Publicly reported figures put the total cost north of $1 million, broken down approximately as follows:2

  • Up to $586,645 for outside incident-response and recovery work, primarily through MoxFive (with Entara as a subcontractor)
  • Up to $497,000 in new and upgraded cybersecurity tooling — endpoint protection, monitoring, and detection capabilities
  • $100,000 insurance deductible

City officials told the Modesto Bee at the time that they expected cyber insurance to cover most of the rest. That is consistent with what we see across municipal incident-response engagements: the hard out-of-pocket cost is usually the deductible plus tooling and process work the city should have funded before the event.

For more on how to plan that funding, our guide on cyber insurance readiness for regulated businesses is a good companion read.

What was exposed in the City of Modesto data breach?

The exposed data was, by the city’s own description, “limited” but real. According to notification letters and follow-up reporting, the impacted records included:13

  • names
  • home addresses
  • Social Security numbers
  • driver’s license numbers

The largest share of affected individuals were Modesto Police Department employees, with a smaller number of other city employees and a small population of non-employees included. The city offered one year of complimentary credit monitoring to people whose data may have been accessed.

For a non-PD employee whose information ended up in a leaked file, “limited” is not very comforting. That is one of the reasons we routinely tell municipal clients that the goal of a security program is not just to keep data out of attackers’ hands, but to keep the minimum necessary data inside the systems most likely to be targeted in the first place.

What did the 2025 City of Modesto risk assessment find?

This is the part of the story most residents probably missed.

A later enterprise risk assessment for the City of Modesto found that the city, after the Police Department ransomware attack, still had material information-technology governance and cybersecurity gaps. The report recommended completing comprehensive IT policies, keeping cybersecurity oversight durable, continuing regular staff cybersecurity training, and conducting periodic penetration testing.5

Specific findings included:

  • no established information security policy setting the framework, roles, and responsibilities for protecting city information assets
  • incomplete policies for access control, physical security, and data privacy
  • no formal, documented IT governance policy
  • no formal data governance policy, though one was being developed
  • the need for periodic penetration testing to identify vulnerabilities and guide remediation

That is a significant finding for any organization, and it is a particularly significant finding for a city that already paid the price of a ransomware event. Tooling went up. Spending went up. The governance scaffolding underneath, based on the 2025 review, did not catch up at the same pace.

That gap matters. Tooling without policy tends to drift. Without a written information security policy, you cannot consistently answer questions like “who owns admin accounts,” “what data is sensitive,” “what is the change-control standard,” or “who approves exceptions.” Without a data governance policy, you cannot consistently answer “where does this data live, who can see it, how long do we keep it, and when is it destroyed.” Without regular penetration testing, you do not get an outside view of how an attacker would actually move through your environment today.

The same local reporting that surfaced these gaps is essentially what people are now Googling when they search Modesto Bee data breach coverage. The question is what other Central Valley organizations do with what it revealed.

Why are people searching for City of Modesto data breach 2025-2026?

People are searching for City of Modesto data breach 2025-2026 because the original ransomware attack, later breach discussion, and subsequent risk-assessment findings are being conflated into one current search pattern. The clean timeline is: unauthorized activity began January 31, 2023; the city detected the incident February 3, 2023; public reporting and notification followed in 2023; and later risk-assessment materials kept the story relevant in 2025 and 2026.

That distinction matters. Searchers looking for a new 2025 or 2026 breach should check official City notices and the California Attorney General breach-notification database. IT leaders looking for lessons should focus on the repeatable controls: information-security policy, data governance, access control, penetration testing, incident response, backup validation, and executive reporting.

What could the City of Modesto have done better?

Based on the publicly reported facts and the 2025 risk assessment findings, here is a candid view of what could have improved the outcome.

1. Faster detection inside the network

The unauthorized activity reportedly began on January 31, 2023 and was not detected until February 3, 2023.1 Three days is not catastrophic by national averages, but it is enough time for a competent ransomware operator to do staging, credential theft, and data exfiltration before encryption. Modern managed detection and response (MDR) and endpoint detection and response (EDR) telemetry, monitored 24/7, would have closed that window. For more on the difference, see our post on EDR vs. antivirus.

2. Multi-factor authentication everywhere it mattered

External analysis of the incident specifically called out that “most attacks do succeed as a result of basic security shortcomings like not using MFA” where it is needed.2 We do not know which specific accounts were compromised in Modesto, but the pattern is consistent: privileged accounts without MFA are the single most reliable foothold for ransomware operators today.

3. Immutable, segmented backups with tested restores

Recovery work confirmed that the response team had to verify “backups are valid and usable” and “rebuild hardware to eliminate possible infection.”2 That is exactly the kind of work that goes faster when backups are immutable, isolated from the production identity plane, and routinely test-restored. Our backup immutability checklist for ransomware-resilient IT environments walks through the controls.

4. A pre-approved restoration order

Five weeks is a long time for a police department to operate on radios and paper. Some of that time is unavoidable — forensics, rebuild, segmentation — but a meaningful portion comes from leadership and IT having to decide during the incident which systems come back first. Our companion post on a city government ransomware recovery plan covers the restoration-order discipline that compresses that timeline.

5. Faster, clearer public disclosure

The city initially declined to confirm the incident, and only formally acknowledged it was ransomware after a follow-up statement and media inquiry.23 We understand the reason — protecting the investigation — but for a public-sector entity, prolonged ambiguity erodes trust. California’s own 30-day breach notification timeline, formalized under SB 446 in late 2025 and effective January 1, 2026, raises the bar further for future incidents involving California residents.7

6. A written information security and data governance program — before the next event

This is the single biggest message from the risk assessment. A city or mid-market organization does not need another product purchase before it knows who owns information security, who owns sensitive data, how access is approved, how exceptions are reviewed, and how often independent testing occurs. None of that is glamorous. All of it would shorten the next incident.

What should other municipal and mid-market IT leaders take away?

The honest takeaway for IT leaders watching this story from Stanislaus County, Merced, Stockton, Fresno, or any mid-market organization in regulated industries is:

  • Assume you are a target. Snatch, LockBit, BlackSuit, and their successors have repeatedly hit small and mid-sized U.S. cities. Local government is squarely in scope.
  • Tooling alone is not a program. A million dollars in new tools without a written security policy, defined data ownership, and tested processes is a partial solution.
  • The 2025 risk assessment pattern is common. We see organizations across the Central Valley invest in EDR, MDR, and backup upgrades after an incident, but still lack the governance documents that would make those investments durable.
  • Insurance is not a strategy. It funded part of Modesto’s recovery, but it did not put officers back in cruisers any faster. The cheapest dollar is still the one you spend on prevention and detection.

If your organization is in the middle of any of this — post-incident, post-audit, or post-renewal — that is the moment a properly scoped cybersecurity risk assessment and a written remediation plan tend to pay back fastest.

How Datapath thinks about local incidents like this

We are headquartered in Modesto. Our VP of operations and many of our engineers live and work here. We did not work on the City of Modesto incident, and nothing in this post is informed by non-public information. Everything cited is from public reporting and from the city’s own statements and risk-assessment findings.

The reason we write about it at all is because the lessons translate directly to other Central Valley organizations — school districts, healthcare groups, county agencies, financial-services firms, and mid-market businesses with 100 to 1,000 employees. The pattern is consistent: ransomware finds the gap between tooling and program. Closing that gap is what Datapath’s Accountability-as-a-Service model is designed to do.

If you are an IT leader in a public-sector or regulated environment trying to harden against the next incident, start with Modesto cybersecurity services, incident response retainer services, and cybersecurity risk assessment services — or, if you want a structured place to begin, see our city government ransomware recovery plan post and CJIS incident response plan requirements guide.

For a public-sector service path, see Government IT Services for municipal ransomware readiness, continuity planning, public-sector reporting, and cybersecurity ownership.

FAQ: City of Modesto data breach ransomware searches

Was there a new City of Modesto data breach in 2025 or 2026?

Based on public reporting available as of June 15, 2026, the verified public record points to the February 2023 Modesto Police Department ransomware incident and later risk-assessment findings. Searchers should verify any claim of a new 2025 or 2026 breach against official City notices and the California Attorney General breach-notification list.

What does Modestogov.com data breach 2025 2026 refer to?

Modestogov.com data breach 2025 2026 searches usually point to City of Modesto public materials connected to the 2023 Police Department ransomware incident, follow-up notices, agenda records, and enterprise risk-assessment findings. Treat the query as a public-record verification step, not proof of a separate new breach.

Is Stanislaus County ransomware breach news the same as the City of Modesto ransomware incident?

Not necessarily. Stanislaus County ransomware breach news searches should be verified against the specific county agency, vendor, or public notice involved. The City of Modesto incident is a municipal Police Department ransomware event; county-level searches can overlap geographically but should not be treated as the same incident without official confirmation.

Why do City of Modesto cyber attack searches include 2025 and 2026?

The 2025 and 2026 wording appears to reflect follow-up reporting, risk-assessment discussion, and current local concern rather than the start date of the original attack. The unauthorized activity began on January 31, 2023, and was detected on February 3, 2023.

What did the 2025 City of Modesto risk assessment find?

The city’s enterprise risk assessment identified missing or incomplete governance foundations, including no established information security policy, incomplete access-control and data-privacy policies, no formal documented IT governance policy, no formal data governance policy, and a recommendation to conduct periodic penetration testing.

What should Modesto businesses do after reading about the City ransomware attack?

Businesses should use the incident as a readiness prompt: enforce MFA, review vendor access, test backup restores, confirm endpoint and alert monitoring, document incident-response roles, map sensitive data, and assign owners for remediation work.

Who helps with data backup in Modesto after ransomware concerns?

Datapath helps Modesto organizations review backup coverage, immutable or isolated copies, restore testing, retention assumptions, Microsoft 365 and SaaS recovery gaps, restoration order, and executive-ready disaster recovery evidence.

Which Datapath service fits this risk?

Most organizations should start with Modesto cybersecurity services, a cybersecurity risk assessment, or an incident response retainer depending on whether they need prevention, gap validation, or emergency-response readiness.

Sources and further reading

Footnotes

  1. Government Technology, “Personal Data Exposed in Cyber Attack on Modesto, Calif., PD,” https://www.govtech.com/security/personal-data-exposed-in-cyber-attack-on-modesto-calif-pd 2 3 4

  2. Government Technology, “Ransomware Attack Could Cost Modesto, Calif., $1M,” https://www.govtech.com/security/ransomware-attack-could-cost-modesto-calif-1m 2 3 4 5 6 7

  3. Government Technology, “Hackers Behind Modesto PD Attack Begin Releasing Data,” https://www.govtech.com/security/hackers-behind-modesto-pd-attack-begin-releasing-data 2 3 4 5

  4. City of Modesto, “Cybersecurity,” https://www.modestogov.com/Blog.aspx?IID=104

  5. City of Modesto, “Enterprise Risk Assessment Final Report,” https://agenda2.modestogov.com/OnBaseAgendaOnlineCouncil/Documents/DownloadFileBytes/ENTERPRISE%20RISK%20ASSESSMENT%20FINAL%20REPORT%20DATED%2001-05-26.PDF.pdf?documentType=1&isAttachment=True&isSection=False&itemId=77491&meetingId=2282&publishId=107955 2

  6. California Attorney General, “Search Data Security Breaches,” https://oag.ca.gov/privacy/databreach/list

  7. California Legislative Information, “SB-446 Data breaches: customer notification,” https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB446

See also

Disclaimer: This blog is intended for marketing purposes only, and nothing presented in here is contractually binding or necessarily the final opinion of the authors.

Need a practical roadmap for regulated-industry IT performance?

Datapath can benchmark your current model and define the next 90 days of high-impact improvements.

Book an IT Consultation