68,465 docs · 699,649 pages · 89,092 facts · as of 2026-07-30

Record D-33202 · staff_report

Renewal And Continue A Declaration Of A Local Emergency Due To A Ransomware Attack

legistar · 0.6 MB · 4 pages extracted · 0 facts cite this document · retrieved 2026-07-19 · original location · open the PDF

City ResolutionFiled under council matter 23-0199 introduced 2023-03-16
Subject: Renewal And Continue A Declaration Of A Local Emergency Due To A Ransomware Attack From: Office Of The City Administrator Recommendation: Adopt A Resolution Renewing And Continuing The City Council’s Declaration Of Local Emergency Within The Territorial Limits Of The Cit
Other attachments: View Legislation · 89643 CMS

Extracted text

· page 2 of 4 · · see this page in the PDF

Steven Falk, Interim City Administrator Subject: Renew and Continue a Declaration of a Local Emergency Due to Ransomware Attack Date: March 16, 2023 Page 2 City Council March 21, 2023 BACKGROUND / LEGISLATIVE HISTORY On February 14, 2023, the City Administrator acting as Director of the EOC declared a local emergency within the territorial limits of the City of Oakland due to a ransomware attack and the Proclamation is attached as Exhibit A. . On February 16, 2023, the City Council confirmed and ratified the existence of a local emergency within the territorial limits of the City of Oakland pursuant to Oakland Municipal Code Chapter 8.50 and Government Code section 8630 (Reso. 89592 C.M.S.). By adopting this resolution, the City Council will affirm that a local emergency continues to exist due to the ransomware attack and directs the City to take measures to respond to the emergency. ANALYSIS AND POLICY ALTERNATIVES The City has made significant effort to address the ransomware attack, including threat containment, restoration of City applications, file servers, and access to critical documents; however, the recovery is not yet complete. As a result, City Administrator has determined that the recovery effort may require the procurement of professional services, equipment and materials, the activation of emergency workers, and/or the promulgation of orders on an expedited basis and that need is ongoing. Furthermore, the investigation into the attack determined that a data breach occurred resulting in unauthorized access to files and folders that contained personal information and the City has since worked to identify and contact individuals whose information was accessed. The City has determined that both current and former employees have been affected by the breach; and on March 15, 2023, the City began mailing notification letters to California residents via U.S. mail in accordance with California Civil Code Section 1798.29 and is offering notified employees complimentary identity monitoring services. Moreover, the Emergency Operation Center remains activated and continues to meet regularly to respond to the local emergency. Pursuant to Government Code section 8630, the City must renew the local emergency every 60 days. Failure to adopt the resolution may limit the City’s access to resources, including funding, from the state and federal government that are needed to respond and recover from the ransomware attack. FISCAL IMPACT There is no fiscal impact directly associated with this action; however, the declaration of a local emergency is a requirement for a local jurisdiction to be eligible for funding to support disaster recovery post-emergency. PUBLIC OUTREACH / INTEREST There was no public outreach required beyond the posting and noticing of this agenda item.