Two Connecticut cities filed breach notifications with the state Office of the Attorney General disclosing that ransomware intrusions earlier this year may have exposed the personal data of more than 12,600 residents and employees. New Britain reported 10,339 affected Connecticut residents from a January incident; Meriden reported 2,325 from an incident it identified as ransomware. The combined figure of 12,664 comes from the notices themselves, obtained and first reported by CT Examiner on 17 September 2026 and subsequently recirculated by block385 and The Daily Hodl. A caveat worth stating up front: no primary-tier document has been published directly. Every source in this brief is secondary reporting on filings that neither city has released publicly, and both mayors' offices declined to comment.
What Happened
New Britain's network disruption surfaced first. City systems went down around 5 a.m. on Wednesday 28 January 2026, with internet connectivity lost at City Hall. Alisha Rayner, the city's director of operations and communications, said New Britain activated incident response protocols and was working with state and federal partners, engaging outside technical resources "to ensure our systems are secured and restored as quickly and safely as possible." Asked by FOX61 whether the event was a cyberattack, Rayner said the investigation was ongoing but that calling it one was "a fair statement." Police and fire operations continued normally. The breach notification later placed the intrusion window at 23 to 28 January, meaning the city was inside attacker dwell time for roughly five days before the disruption became visible.
Meriden's timeline is messier and the public account diverges from the filing. The city took internet services and public Wi-Fi offline on 17 February after what officials described only as an attempted "internet disruption," cancelling a City Council meeting that evening and rescheduling it for 19 February as an in-person-only session because livestreaming was unavailable. Mayor Kevin M. Scarpati advised residents with appointments at city departments to call ahead. WFSB-TV reported the shutdown was precautionary, that police were investigating, and that late tax or fee payments tied to the outage would not incur penalties. At the time, the city did not say whether the incident was a cyberattack and attributed it to no group. The breach notice filed months later places the incident window at 9 February to 13 March and identifies it as ransomware, which puts the start of intrusion roughly a week before the public shutdown and extends the disruption well past it. CT Examiner characterises Meriden's service impact as lasting over a month, against days in New Britain.
The notification lag on both sides is the part defenders should sit with. New Britain says it became aware of possible data exposure on 1 February and notified residents on 27 March, nearly two months later. Meriden became aware in May and notified on 2 June. Connecticut law requires municipalities to notify the attorney general within 60 days of a breach and to offer credit monitoring where Social Security numbers are involved.
What Was Taken
The two notices describe an identical category set: names, dates of birth, driver's license numbers, Social Security numbers, passport numbers, financial account information, medical information and health insurance information. That combination is the full identity-theft stack. Passport numbers and SSNs together support synthetic identity fabrication with a long useful life; medical and health insurance data supports both insurance fraud and targeted social engineering against people whose conditions are now known to a criminal buyer.
Record counts are consistent across all available reporting at 10,339 for New Britain and 2,325 for Meriden, summing to 12,664. No source reports a competing figure, but note that the New Britain count is explicitly scoped to Connecticut residents, which means the true affected population may be larger if non-residents held records with the city. Neither city has disclosed data volume in bytes or file counts, whether data was exfiltrated as opposed to merely accessible, whether a ransom was demanded or paid, or whether any of the data has appeared on a leak site.
One item requires explicit separation. Breach House indexes a ransomware claim by the group Dark Project against a dental practice in New Britain, Connecticut, published to the operator's leak site on 25 August 2026, involving roughly 8,000 files and a small number of records containing Social Security numbers. That is a different victim, a different sector and a different quarter. Nothing in the sourcing connects Dark Project to either municipal network, and it should not be read as attribution. It is relevant only as evidence that New Britain's local threat surface has drawn more than one ransomware operator this year.
Why It Matters
Neither city named an actor, described an initial access vector, or confirmed exfiltration. That is the normal state of municipal breach disclosure in the United States, and it is the actual finding here. Both cities say they responded by securing systems, conducting investigations, and notifying law enforcement or forensic specialists, but neither has released records: CT Examiner reports that its Freedom of Information requests to both mayors' offices have gone unfulfilled. Accounts of state involvement also differ across CT Examiner's own versions of the story. One states that state police did not respond to a request for comment; another reports that state police public information officers said they were unaware of any departmental investigation into the attacks. Either way, there is no confirmed state-level investigation on the public record.
Evan Allard, director of Connecticut Central Intelligence, framed the trend: "Year over year, ransomware, specifically executed by financially motivated actors, is increasing exponentially, and it's not just increasing, it's increasing in the sectors that are targeted." Connecticut municipalities have absorbed a run of these, including a Christmas Day 2024 breach that led West Haven to shut down systems as a precaution.
For defenders, the sector pattern is the signal. Mid-sized municipal governments hold hospital-grade PII across tax, licensing, HR, benefits and public health functions, operate flat networks built over decades, and run them on staffing levels that cannot sustain 24/7 detection. A five-day dwell window in New Britain and a five-week one in Meriden are what that resourcing gap produces.
The Attack Technique
No initial access vector has been disclosed for either incident, and nothing in the available sourcing supports a TTP claim. What can be read from the timelines is behavioural rather than technical.
In New Britain, encryption or service impact landed on day five of a six-day window, which is consistent with a short, commodity-grade intrusion: access, stage, fire. In Meriden, the filed window spans 9 February to 13 March while the public-facing symptom appeared on 17 February, which is consistent with either a longer collection phase before impact or a protracted containment and rebuild that the city counted as part of the incident. Meriden's own early public framing, an "attempted disruption" of internet service, was later superseded by its ransomware characterisation in the breach notice. That gap between first public statement and filed classification is itself a recurring pattern in municipal incidents and a reason to treat day-one official language as provisional.
Treat any specific actor, ransomware family or entry point you see attached to these two incidents as unsourced until a city or a regulator publishes it.
What Organizations Should Do
- Pre-write the disclosure clock. New Britain took roughly eight weeks from awareness to resident notification, Meriden longer. Draft notification templates, legal review paths and credit-monitoring vendor contracts now, before an incident, so the statutory 60-day window is a floor and not a scramble.
- Instrument dwell time, not just outage. Both incidents were detected by service impact. Deploy EDR with retained telemetry and centralized logging across municipal endpoints and domain controllers so that a five-day staging window produces an alert rather than a forensic footnote.
- Segment the PII-bearing systems. Tax, HR, licensing, health benefits and vital records each hold a different slice of the data set exposed here. Flat municipal networks let one foothold reach all of them. Enforce network segmentation and separate credentials between public safety, administrative and records systems.
- Enforce phishing-resistant MFA on every remote entry point. VPN, RDP, Citrix, webmail and any third-party administrative portal. Municipal environments are disproportionately breached through internet-facing remote access with weak or absent second factors.
- Keep offline, tested backups and rehearse restore, not just backup. Meriden's month-plus service degradation is what an untested recovery path costs. Time your actual restore of a domain controller and a records system, and record the number.
- Build a manual-continuity plan for public services. Meriden waived late payment penalties and reverted to in-person meetings; those were improvised. Decide in advance which services run on paper, which deadlines get suspended, and who has authority to suspend them.
- Flag high-sensitivity fields for stronger controls. Passport numbers, SSNs and health insurance identifiers should be encrypted at rest with separated key management and access-logged, so that a containment report can state what was reachable rather than what may have been reachable.
Sources: Ransomware Attacks May Have Exposed Data of 12,600 in Connecticut -... | Ransomware Attacks May Have Exposed Data ... | Ransomware Attacks May Have Exposed Data of 12,600 in Connecticut... | Meriden CT shuts down city internet after disruption attempt | New Britain, Connecticut City Hall hit by network disruption | Dentist in New Britain, CT — DARK PROJECT Ransomware Attack Breach... | Connecticut Ransomware Attacks May Have Exposed Data of More Than 1... | Connecticut Ransomware Attacks May Have Exposed Data of More Than 1...