Skip to content

Meriden municipal network disruption and INCRansom claim

Summary

City of Meriden logo

Meriden’s municipal network shutdown disrupted payments, records, meetings and library services. Later city breach notices identified ransomware and possible exposure affecting 2,325 Connecticut residents; INC Ransom attribution remains unconfirmed.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

Data impacts

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

Extortion indicators

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Meriden, Connecticut, experienced a ransomware-related municipal network disruption. Our initial report documented a precautionary shutdown and qualified city cybersecurity language. Later reporting on city breach notices establishes unauthorized network access rather than only an unsuccessful interruption attempt.

CT Examiner reported Sept. 17 that Meriden identified the attack as ransomware in a June filing with Connecticut’s attorney general. The city reported possible exposure affecting 2,325 Connecticut residents. The reported intrusion window was Feb. 9–March 13, with discovery Feb. 12; the city identified potential personal-data exposure in May and sent notifications in June. Those dates describe intrusion and notification, not the duration of service disruption.

Operational significance

Meriden shut down its network Feb. 13. Internet loss affected city departments, manual recordkeeping, payments, public Wi-Fi and library computer, scanning, fax and printing services. The City Council canceled its Feb. 17 meeting; later meetings initially lacked livestreaming.

Emergency dispatch relocated to the Connecticut Statewide Emergency Communications Center while emergency response continued. Some email and web publishing returned in early March. By April 23, online payments, hybrid meetings and local dispatch had returned, but officials could not identify what other services remained affected. The city’s subsequent online permitting announcement describes a new offering, not an incident-wide all-clear. Geographic overlays represent the city’s municipal remit, not an area-wide outage or loss of every public-safety function.

Data impact and response

Hearst Connecticut Media reported June 24 that a city letter acknowledged unauthorized access and possible exposure of names, Social Security and driver’s license numbers, bank accounts and routing numbers, with no identified misuse of that recipient’s information. It described an FBI investigation and two years of monitoring. Reporting on the notices also describes forensic assistance, rebuilding affected systems and security-policy reviews. These findings support unauthorized access and possible exposure, not confirmed exfiltration, publication or encryption.

Attribution and confidence

INC Ransom listed meridenct.gov March 26. Ransomware confidence is now high because reporting conveys the city’s own characterization; actor confidence remains medium. Neither the city notices nor newly reviewed coverage corroborates INC Ransom responsibility. The group’s listing does not independently prove encryption or theft.

Disclosure posture

The city’s Feb. 17 statement referred to cybersecurity concerns and breach review before the March 26 actor claim. Organization-confirmed cyber and disruption transparency, OC–OD, remains appropriate. Later notices provide more specific acknowledgment without changing the earliest located disclosure date.

Current status and gaps

April 23 remains the latest supported operational-impact date. Without a complete all-clear or newer documented disruption, the incident remains presumed resolved, with no established end date. Initial access, affected hosts, confirmed data theft or encryption, ransom demands or payment, recovery costs and full restoration timing remain unresolved. The attorney-general filing was not directly inspected; its details are attributed to reporting rather than presented as our independent examination.

Threat actor and claim

Listed as: City of MeridenSource: otherPublished:

Claim details

INC Ransom listed meridenct.gov March 26, 2026. Later reporting on city notices acknowledges unauthorized network access and identifies ransomware, but does not attribute the event to INC Ransom or independently confirm encryption, exfiltration or publication.

Organizations involved

Impacted location

  • Meriden, Connecticut

    Citywide municipal service remit; this overlay does not assert an area-wide outage or disruption of every service. Preserve the supported Meriden municipality anchor.

Sources

Meriden identifies attempt to interrupt its internet services

WFSB reported the precautionary city internet and public Wi-Fi shutdown, police investigation, library service limitations and the city’s waiver of penalties tied to the outage.

INCRansom claims City of Meriden attack

The report preserved an INCRansom leak-site claim posted March 26 identifying meridenct.gov. The claim was not confirmed by city officials.

Meriden restores some city services following February internet 'interruption'

Hearst Connecticut Media reported that online payments, hybrid meetings and local emergency dispatch had returned by April 23 after a shutdown beginning Feb. 13, while officials could not identify what other services remained affected.

City Permitting and Licensing Now Available Online

City announces online permitting and licensing for multiple departments.

Ransomware Attacks May Have Exposed Data of 12,600 in Connecticut

Reporting on city breach notices identifies ransomware and possible exposure affecting 2,325 Connecticut residents for Meriden.

See something that needs correction?

Signed-in members can report an error, update, or missing source.