What happened in the City of Modesto ransomware attack?
The City of Modesto ransomware attack was a February 2023 ransomware incident in which the Modesto Police Department’s IT network was compromised, personally identifiable information was accessed, patrol-vehicle laptops and police technology were disrupted, and the city incurred a roughly five-week, $1 million-plus recovery effort.1234
If you searched for City of Modesto data breach ransomware 2025 2026, City of Modesto cyber attack 2025 2026, or Modesto Bee data breach 2025 2026, the public record still points back to the verified 2023 Police Department ransomware event, the later enterprise risk-assessment findings, and ongoing local scrutiny rather than a separately confirmed new City breach in 2025 or 2026. Confirm any new claim against the California Attorney General breach-notification list before treating it as a new incident.56
The practical answer is this: there was a verified Modesto Police Department ransomware and data-breach event in 2023; 2025-2026 searches are largely about later reporting and the enterprise risk assessment that documented unfinished policy, governance, and penetration-testing work. For municipal and mid-market leaders, the story is less about a headline and more about what must be fixed before the next incident.
This post walks through what actually happened, what it cost, what the risk assessment found, and what mid-market and municipal IT leaders should take away from it. We are based in Modesto. We work with regulated organizations across the Central Valley. We do not enjoy writing about local incidents, but we believe security maturity in our region only improves when leaders look at the facts honestly. For context on how Datapath approaches that, see our cybersecurity consulting in Modesto overview.
Need a Modesto ransomware readiness review?
Datapath helps local organizations assess identity controls, endpoint coverage, backup recoverability, vendor access, data governance, and incident-response ownership before a breach turns into a public recovery effort.
Quick answers for current Modesto breach searches
Search behavior around the City of Modesto incident now blends public-record verification, Stanislaus County concerns, and local backup-readiness intent. Use the search phrase to decide whether you need facts, readiness work, or a recovery review.
| Search phrase | What the public record points to | Datapath path |
|---|---|---|
| City of Modesto data breach ransomware 2025 2026 | The verified 2023 Modesto Police Department ransomware and data-breach event, plus later 2025 risk-assessment discussion. | Read the timeline below, then review Modesto cybersecurity services |
| Modestogov.com data breach 2025 2026 | City-hosted notices, agenda records, and risk-assessment materials connected to the 2023 incident and later governance findings. | Confirm official notices, then start a cyber risk assessment |
| Stanislaus County ransomware breach 2025 2026 news | A county-level search pattern that should be verified separately from the City of Modesto incident before assuming the same affected systems or notice obligations. | Use it as a prompt for Stanislaus County breach readiness |
| Data backup Modesto | A local service need: confirm backups are isolated, restorable, tested, and tied to a restoration order before ransomware or system failure creates downtime. | Review data backup and disaster recovery services |
How should Modesto Bee and California city breach searches be verified?
Many searches around this incident use phrases such as Modesto Bee data breach 2025 2026, Modestogov.com data breach 2025 2026, City of Modesto cyber attack 2025 2026, and Stanislaus County ransomware breach 2025 2026 news. Treat those phrases as verification prompts, not as proof that a separate 2025 or 2026 breach occurred.
The Modesto Bee was a local reporting source for the City of Modesto Police Department ransomware story. Based on the public sources cited below, there is no separate, widely confirmed 2025 or 2026 data breach of the Modesto Bee newspaper itself. The verified thread is the 2023 Modesto Police ransomware incident, the city’s later risk-assessment findings, and broader Central Valley concern about municipal cybersecurity readiness.
| Search pattern | Safer interpretation | What to verify before acting |
|---|---|---|
| Modesto Bee data breach 2025 2026 | Usually a search for local coverage of the City of Modesto ransomware and data-exposure story, not confirmed proof that the newspaper was breached. | Check whether the claim names the newspaper, the City, a vendor, or another organization. |
| Modestogov.com data breach 2025 2026 | Usually a search tying the City of Modesto domain to public notices, agenda records, and breach-verification questions. | Check City notices, agenda packets, and the California Attorney General breach-notification list. |
| City of Modesto cyber attack 2025 2026 | Usually the 2023 Police Department incident resurfacing through later coverage and 2025 risk-assessment discussion. | Separate incident date, notice date, risk-assessment date, and any later confirmed notice. |
| Stanislaus County ransomware breach 2025 2026 news | A county-level or local-news query that may overlap geographically but should not be treated as the same incident. | Check county, city, vendor, insurer, and state filings separately. |
| Fresno, Hanford, Visalia, Barstow, or other California city breach searches | Similar public-agency verification intent, sometimes triggered by local reporting or alleged actor claims. | Confirm through official notices and credible reporting before assuming operational disruption or exposed data. |
For residents, the strongest public source is usually the California Attorney General breach-notification database when a reportable California notice exists. For IT leaders, the useful action is to pressure-test the same controls that repeatedly appear in local breach coverage: information-security policy, data governance, privileged access, vendor access, endpoint monitoring, backup recoverability, incident-response ownership, and tested communications.
When did the City of Modesto cyber attack start and end?
According to letters the city later sent to affected individuals, unauthorized activity inside the Modesto Police Department’s digital network began on January 31, 2023, and was first detected by city staff on February 3, 2023.1 The city did not publicly confirm the incident until a follow-up statement after media inquiries, and only formally confirmed in early March 2023 that it was a ransomware event with potential exposure of Social Security numbers and driver’s license numbers.23
The Snatch ransomware group claimed responsibility, posted 15 files on its dark-web leak site that it said contained Modesto data, and began releasing portions of that data publicly in April 2023 — consistent with the typical “double-extortion” model where ransomware operators steal data first and threaten release if no ransom is paid.3
It took the city about five weeks to bring Modesto Police Department systems back online, including:2
- patrol-vehicle mobile data computers (officers temporarily reverted to handheld radios and paper)
- the department’s dispatch and records-adjacent tools
- internal Police Department network access
Through it all, 911 call answering and emergency response stayed operational. That was the right priority, and the city deserves credit for protecting it.
What did the City of Modesto ransomware attack actually cost?
Publicly reported figures put the total cost north of $1 million, broken down approximately as follows:2
- Up to $586,645 for outside incident-response and recovery work, primarily through MoxFive (with Entara as a subcontractor)
- Up to $497,000 in new and upgraded cybersecurity tooling — endpoint protection, monitoring, and detection capabilities
- $100,000 insurance deductible
City officials told the Modesto Bee at the time that they expected cyber insurance to cover most of the rest. That is consistent with what we see across municipal incident-response engagements: the hard out-of-pocket cost is usually the deductible plus tooling and process work the city should have funded before the event.
For more on how to plan that funding, our guide on cyber insurance readiness for regulated businesses is a good companion read.
What was exposed in the City of Modesto data breach?
The exposed data was, by the city’s own description, “limited” but real. According to notification letters and follow-up reporting, the impacted records included:13
- names
- home addresses
- Social Security numbers
- driver’s license numbers
The largest share of affected individuals were Modesto Police Department employees, with a smaller number of other city employees and a small population of non-employees included. The city offered one year of complimentary credit monitoring to people whose data may have been accessed.
For a non-PD employee whose information ended up in a leaked file, “limited” is not very comforting. That is one of the reasons we routinely tell municipal clients that the goal of a security program is not just to keep data out of attackers’ hands, but to keep the minimum necessary data inside the systems most likely to be targeted in the first place.
What did the 2025 City of Modesto risk assessment find?
This is the part of the story most residents probably missed.
A later enterprise risk assessment for the City of Modesto found that the city, after the Police Department ransomware attack, still had material information-technology governance and cybersecurity gaps. The report recommended completing comprehensive IT policies, keeping cybersecurity oversight durable, continuing regular staff cybersecurity training, and conducting periodic penetration testing.5
Specific findings included:
- no established information security policy setting the framework, roles, and responsibilities for protecting city information assets
- incomplete policies for access control, physical security, and data privacy
- no formal, documented IT governance policy
- no formal data governance policy, though one was being developed
- the need for periodic penetration testing to identify vulnerabilities and guide remediation
That is a significant finding for any organization, and it is a particularly significant finding for a city that already paid the price of a ransomware event. Tooling went up. Spending went up. The governance scaffolding underneath, based on the 2025 review, did not catch up at the same pace.
That gap matters. Tooling without policy tends to drift. Without a written information security policy, you cannot consistently answer questions like “who owns admin accounts,” “what data is sensitive,” “what is the change-control standard,” or “who approves exceptions.” Without a data governance policy, you cannot consistently answer “where does this data live, who can see it, how long do we keep it, and when is it destroyed.” Without regular penetration testing, you do not get an outside view of how an attacker would actually move through your environment today.
The same local reporting that surfaced these gaps is essentially what people are now Googling when they search Modesto Bee data breach coverage. The question is what other Central Valley organizations do with what it revealed.
Why are people searching for City of Modesto data breach 2025-2026?
People are searching for City of Modesto data breach 2025-2026 because the original ransomware attack, later breach discussion, and subsequent risk-assessment findings are being conflated into one current search pattern. The clean timeline is: unauthorized activity began January 31, 2023; the city detected the incident February 3, 2023; public reporting and notification followed in 2023; and later risk-assessment materials kept the story relevant in 2025 and 2026.
That distinction matters. Searchers looking for a new 2025 or 2026 breach should check official City notices and the California Attorney General breach-notification database. IT leaders looking for lessons should focus on the repeatable controls: information-security policy, data governance, access control, penetration testing, incident response, backup validation, and executive reporting.
What could the City of Modesto have done better?
Based on the publicly reported facts and the 2025 risk assessment findings, here is a candid view of what could have improved the outcome.
1. Faster detection inside the network
The unauthorized activity reportedly began on January 31, 2023 and was not detected until February 3, 2023.1 Three days is not catastrophic by national averages, but it is enough time for a competent ransomware operator to do staging, credential theft, and data exfiltration before encryption. Modern managed detection and response (MDR) and endpoint detection and response (EDR) telemetry, monitored 24/7, would have closed that window. For more on the difference, see our post on EDR vs. antivirus.
2. Multi-factor authentication everywhere it mattered
External analysis of the incident specifically called out that “most attacks do succeed as a result of basic security shortcomings like not using MFA” where it is needed.2 We do not know which specific accounts were compromised in Modesto, but the pattern is consistent: privileged accounts without MFA are the single most reliable foothold for ransomware operators today.
3. Immutable, segmented backups with tested restores
Recovery work confirmed that the response team had to verify “backups are valid and usable” and “rebuild hardware to eliminate possible infection.”2 That is exactly the kind of work that goes faster when backups are immutable, isolated from the production identity plane, and routinely test-restored. Our backup immutability checklist for ransomware-resilient IT environments walks through the controls.
4. A pre-approved restoration order
Five weeks is a long time for a police department to operate on radios and paper. Some of that time is unavoidable — forensics, rebuild, segmentation — but a meaningful portion comes from leadership and IT having to decide during the incident which systems come back first. Our companion post on a city government ransomware recovery plan covers the restoration-order discipline that compresses that timeline.
5. Faster, clearer public disclosure
The city initially declined to confirm the incident, and only formally acknowledged it was ransomware after a follow-up statement and media inquiry.23 We understand the reason — protecting the investigation — but for a public-sector entity, prolonged ambiguity erodes trust. California’s own 30-day breach notification timeline, formalized under SB 446 in late 2025 and effective January 1, 2026, raises the bar further for future incidents involving California residents.7
6. A written information security and data governance program — before the next event
This is the single biggest message from the risk assessment. A city or mid-market organization does not need another product purchase before it knows who owns information security, who owns sensitive data, how access is approved, how exceptions are reviewed, and how often independent testing occurs. None of that is glamorous. All of it would shorten the next incident.
What should other municipal and mid-market IT leaders take away?
The honest takeaway for IT leaders watching this story from Stanislaus County, Merced, Stockton, Fresno, or any mid-market organization in regulated industries is:
- Assume you are a target. Snatch, LockBit, BlackSuit, and their successors have repeatedly hit small and mid-sized U.S. cities. Local government is squarely in scope.
- Tooling alone is not a program. A million dollars in new tools without a written security policy, defined data ownership, and tested processes is a partial solution.
- The 2025 risk assessment pattern is common. We see organizations across the Central Valley invest in EDR, MDR, and backup upgrades after an incident, but still lack the governance documents that would make those investments durable.
- Insurance is not a strategy. It funded part of Modesto’s recovery, but it did not put officers back in cruisers any faster. The cheapest dollar is still the one you spend on prevention and detection.
If your organization is in the middle of any of this — post-incident, post-audit, or post-renewal — that is the moment a properly scoped cybersecurity risk assessment and a written remediation plan tend to pay back fastest.
How Datapath thinks about local incidents like this
We are headquartered in Modesto. Our VP of operations and many of our engineers live and work here. We did not work on the City of Modesto incident, and nothing in this post is informed by non-public information. Everything cited is from public reporting and from the city’s own statements and risk-assessment findings.
The reason we write about it at all is because the lessons translate directly to other Central Valley organizations — school districts, healthcare groups, county agencies, financial-services firms, and mid-market businesses with 100 to 1,000 employees. The pattern is consistent: ransomware finds the gap between tooling and program. Closing that gap is what Datapath’s Accountability-as-a-Service model is designed to do.
If you are an IT leader in a public-sector or regulated environment trying to harden against the next incident, start with Modesto cybersecurity services, incident response retainer services, and cybersecurity risk assessment services — or, if you want a structured place to begin, see our city government ransomware recovery plan post and CJIS incident response plan requirements guide.
For a public-sector service path, see Government IT Services for municipal ransomware readiness, continuity planning, public-sector reporting, and cybersecurity ownership.
FAQ: City of Modesto data breach ransomware searches
Was there a new City of Modesto data breach in 2025 or 2026?
Based on public reporting available as of June 15, 2026, the verified public record points to the February 2023 Modesto Police Department ransomware incident and later risk-assessment findings. Searchers should verify any claim of a new 2025 or 2026 breach against official City notices and the California Attorney General breach-notification list.
What does Modestogov.com data breach 2025 2026 refer to?
Modestogov.com data breach 2025 2026 searches usually point to City of Modesto public materials connected to the 2023 Police Department ransomware incident, follow-up notices, agenda records, and enterprise risk-assessment findings. Treat the query as a public-record verification step, not proof of a separate new breach.
Is Stanislaus County ransomware breach news the same as the City of Modesto ransomware incident?
Not necessarily. Stanislaus County ransomware breach news searches should be verified against the specific county agency, vendor, or public notice involved. The City of Modesto incident is a municipal Police Department ransomware event; county-level searches can overlap geographically but should not be treated as the same incident without official confirmation.
Why do City of Modesto cyber attack searches include 2025 and 2026?
The 2025 and 2026 wording appears to reflect follow-up reporting, risk-assessment discussion, and current local concern rather than the start date of the original attack. The unauthorized activity began on January 31, 2023, and was detected on February 3, 2023.
What did the 2025 City of Modesto risk assessment find?
The city’s enterprise risk assessment identified missing or incomplete governance foundations, including no established information security policy, incomplete access-control and data-privacy policies, no formal documented IT governance policy, no formal data governance policy, and a recommendation to conduct periodic penetration testing.
What should Modesto businesses do after reading about the City ransomware attack?
Businesses should use the incident as a readiness prompt: enforce MFA, review vendor access, test backup restores, confirm endpoint and alert monitoring, document incident-response roles, map sensitive data, and assign owners for remediation work.
Who helps with data backup in Modesto after ransomware concerns?
Datapath helps Modesto organizations review backup coverage, immutable or isolated copies, restore testing, retention assumptions, Microsoft 365 and SaaS recovery gaps, restoration order, and executive-ready disaster recovery evidence.
Which Datapath service fits this risk?
Most organizations should start with Modesto cybersecurity services, a cybersecurity risk assessment, or an incident response retainer depending on whether they need prevention, gap validation, or emergency-response readiness.
Sources and further reading
- Government Technology — Cyber Incident Disrupts Modesto, Calif., Police Department
- Government Technology — Personal Data Exposed in Cyber Attack on Modesto, Calif., PD
- Government Technology — Hackers Behind Modesto PD Attack Begin Releasing Data
- Government Technology — Ransomware Attack Could Cost Modesto, Calif., $1M
- City of Modesto — Cybersecurity statement
- City of Modesto — Enterprise Risk Assessment Final Report
- California Attorney General — Data Security Breach Notices
- California Legislative Information — SB 446
Footnotes
-
Government Technology, “Personal Data Exposed in Cyber Attack on Modesto, Calif., PD,” https://www.govtech.com/security/personal-data-exposed-in-cyber-attack-on-modesto-calif-pd ↩ ↩2 ↩3 ↩4
-
Government Technology, “Ransomware Attack Could Cost Modesto, Calif., $1M,” https://www.govtech.com/security/ransomware-attack-could-cost-modesto-calif-1m ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7
-
Government Technology, “Hackers Behind Modesto PD Attack Begin Releasing Data,” https://www.govtech.com/security/hackers-behind-modesto-pd-attack-begin-releasing-data ↩ ↩2 ↩3 ↩4 ↩5
-
City of Modesto, “Cybersecurity,” https://www.modestogov.com/Blog.aspx?IID=104 ↩
-
City of Modesto, “Enterprise Risk Assessment Final Report,” https://agenda2.modestogov.com/OnBaseAgendaOnlineCouncil/Documents/DownloadFileBytes/ENTERPRISE%20RISK%20ASSESSMENT%20FINAL%20REPORT%20DATED%2001-05-26.PDF.pdf?documentType=1&isAttachment=True&isSection=False&itemId=77491&meetingId=2282&publishId=107955 ↩ ↩2
-
California Attorney General, “Search Data Security Breaches,” https://oag.ca.gov/privacy/databreach/list ↩
-
California Legislative Information, “SB-446 Data breaches: customer notification,” https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB446 ↩