Skip to content

Meriden municipal network disruption and INCRansom claim

Summary

City of Meriden logo

Meriden shut down its municipal network after discovering an attempted internet interruption Feb. 13, 2026, disrupting payments, records, meetings, library access and normal staff workflows for weeks. Online payments, hybrid meetings and emergency dispatch had returned by April 23, but the city had not issued a full all-clear; INCRansom’s later claim remains unconfirmed.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

Extortion indicators

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Meriden, Connecticut, experienced a cyber-related municipal network disruption. We reported that the city took internet services and public Wi-Fi offline after an attempted interruption. The city’s Feb. 17 statement referred to cybersecurity concerns and a review for possible breaches, providing qualified affected-organization cyber evidence without identifying ransomware or another mechanism.

INCRansom listed meridenct.gov March 26. The stable claim is concrete external cyber evidence but does not prove the group caused the disruption, deployed ransomware, encrypted systems or stole data. Meriden has not publicly confirmed the claim or attributed the incident.

Operational significance

Meriden later said it discovered the attempted interruption and shut down the network Feb. 13. Internet loss affected every city department, forced employees to record information manually and limited payment and records services. The public library lost internet-dependent computer access, scanning, faxing and printing. The City Council canceled its Feb. 17 meeting, and later meetings initially lacked livestreaming.

The city moved its emergency dispatch center to the Connecticut Statewide Emergency Communications Center while maintaining emergency response. Some email and web publishing returned in early March. By April 23, dispatch had returned to Meriden, online bill payment and hybrid meetings were available again, and residents could pay taxes online, but officials could not say what other services remained affected.

Confidence and uncertainty

Confidence is high that a cyber-related event prompted a prolonged network shutdown because city officials documented the interruption, cybersecurity concerns, breach review and restoration. The technical mechanism and data impact remain unknown. INCRansom attribution and ransomware remain medium confidence because the claim is specific and temporally consistent but uncorroborated by the city.

Disclosure posture

Meriden used qualified cyber and breach language in its first located public statement Feb. 17, before INCRansom’s March 26 listing. That sequence supports organization-confirmed cyber and disruption transparency, or OC-OD, even though the city did not call the incident ransomware.

Current status

April 23 is the latest supported operational-impact date. The city had restored several major functions by then but had not issued a complete all-clear. With more than 30 days since that partial-restoration report and no newer documented impact, the incident is presumed resolved rather than confirmed resolved.

Analytic gaps

The public record does not establish the initial access vector, compromised system or account, attack method, whether an intrusion succeeded, affected hosts, data access or exfiltration, encryption, ransom communications, payment, recovery cost, full restoration date or the city’s assessment of INCRansom’s claim.

Threat actor and claim

Listed as: City of MeridenSource: otherPublished:

Claim details

INCRansom listed meridenct.gov March 26, 2026. Meriden had documented a prolonged cyber-related network shutdown but did not identify INCRansom, confirm ransomware or corroborate encryption or data theft.

Organizations involved

Impacted location

Sources

Meriden identifies attempt to interrupt its internet services

WFSB reported the precautionary city internet and public Wi-Fi shutdown, police investigation, library service limitations and the city’s waiver of penalties tied to the outage.

INCRansom claims City of Meriden attack

The report preserved an INCRansom leak-site claim posted March 26 identifying meridenct.gov. The claim was not confirmed by city officials.

Meriden restores some city services following February internet 'interruption'

Hearst Connecticut Media reported that online payments, hybrid meetings and local emergency dispatch had returned by April 23 after a shutdown beginning Feb. 13, while officials could not identify what other services remained affected.

See something that needs correction?

Signed-in members can report an error, update, or missing source.