Skip to main content

River Valley Times

Greenfield CEO Answers Outage Questions

Jul 21, 2026 08:55AM ● By Gail Bullen, River Valley Times Reporter

Greenfield Communications CEO Mike Powers speaks at a Rancho Murieta event in 2019. File photo by Gail Bullen

RANCHO MURIETA, CA (MPG) - Greenfield Communications President and CEO Mike Powers responded to written questions from the River Valley Times following the more than two-day outage that disrupted internet, television and phone service in Rancho Murieta.

In his responses, Powers explained why the company limited public updates during the cyberattack, why restoration took several days, why some customers experienced lingering internet protocol (IP) issues after service was restored, and what Greenfield is doing to reduce the impact of future attacks.

Powers concluded his response by reassuring customers that no personal information had been compromised and offering a personal reflection on the outage and its impact on Greenfield's employees. Because those remarks help to frame the company’s response, they are presented first.

The following questions and answers have been edited for length and clarity.

RVT: Is there anything else you would like Rancho Murieta customers to know about this incident?

Powers: Only this: No customer data was accessed or compromised at any point during this incident. This was an attack designed to disrupt service, not to steal information, and we want that distinction to be clear for anyone who was worried about their personal information.

The trust the Rancho Murieta community has placed in Greenfield Communications as your internet provider means everything to us, and we don’t take it lightly. This past week weighed on our entire team, who worked around the clock, 24/7, until every customer was safely back online. To our residents and businesses: Thank you sincerely for your patience as we worked through this. We took it very seriously, and we remain committed to earning your trust every day.

RVT: When did Greenfield determine the outage was caused by a distributed denial-of-service (DDoS) attack?

Powers: Our network monitoring identified the traffic pattern as a DDoS attack within minutes of the outage beginning on Sunday afternoon. While the type of attack was identified quickly, safely mitigating it and rebuilding the affected infrastructure took until Tuesday afternoon, when service was fully restored.

RVT: Without revealing security-sensitive information, can you clarify whether Greenfield was the intended target of the attack and what role, if any, upstream providers played?

Powers: This is one area we’re not able to discuss in detail. Our network architecture, the providers we rely on and how traffic moves through our infrastructure are proprietary and security-sensitive. Rather than provide a partial explanation that could mislead or oversimplify a complex technical issue, we’d rather decline to comment further.

RVT: Looking back, should customers have received earlier updates, even if technical details couldn’t yet be shared?

Powers: Looking back, yes. We believe an earlier acknowledgment that we were aware of the problem and actively working on it could have reduced customer frustration without compromising the guidance we received from the FBI and industry security experts. That’s a change we’re already implementing in our incident communication procedures.

RVT: Some residents believed the Rancho Murieta Community Services District regained internet service before most residential customers. Why was that?

Powers: The Community Services District was not restored ahead of residential customers, and no customer type received preferential treatment. Service returned in stages as segments of the network came back online under new network addresses. The order reflected the technical rollout, not whether the customer was residential, business or governmental.

RVT: Was assigning new IP addresses part of Greenfield’s normal incident response plan?

Powers: Reassigning network addresses is a standard industry tool used to recover from this type of attack quickly and safely. While the approach itself is common, the specific implementation was tailored to the circumstances Greenfield encountered during this incident.

RVT: Has Greenfield made changes to reduce the likelihood or impact of a similar outage?

Powers: We continually review our exposure to external threats and our response procedures, but we can’t publicly discuss specific technical or architectural changes because of security considerations.