Analyst assessment
DysruptionHub assesses with high confidence that Meriden, Connecticut, experienced a ransomware-related municipal network disruption. Our initial report documented a precautionary shutdown and qualified city cybersecurity language. Later reporting on city breach notices establishes unauthorized network access rather than only an unsuccessful interruption attempt.
CT Examiner reported Sept. 17 that Meriden identified the attack as ransomware in a June filing with Connecticut’s attorney general. The city reported possible exposure affecting 2,325 Connecticut residents. The reported intrusion window was Feb. 9–March 13, with discovery Feb. 12; the city identified potential personal-data exposure in May and sent notifications in June. Those dates describe intrusion and notification, not the duration of service disruption.
Operational significance
Meriden shut down its network Feb. 13. Internet loss affected city departments, manual recordkeeping, payments, public Wi-Fi and library computer, scanning, fax and printing services. The City Council canceled its Feb. 17 meeting; later meetings initially lacked livestreaming.
Emergency dispatch relocated to the Connecticut Statewide Emergency Communications Center while emergency response continued. Some email and web publishing returned in early March. By April 23, online payments, hybrid meetings and local dispatch had returned, but officials could not identify what other services remained affected. The city’s subsequent online permitting announcement describes a new offering, not an incident-wide all-clear. Geographic overlays represent the city’s municipal remit, not an area-wide outage or loss of every public-safety function.
Data impact and response
Hearst Connecticut Media reported June 24 that a city letter acknowledged unauthorized access and possible exposure of names, Social Security and driver’s license numbers, bank accounts and routing numbers, with no identified misuse of that recipient’s information. It described an FBI investigation and two years of monitoring. Reporting on the notices also describes forensic assistance, rebuilding affected systems and security-policy reviews. These findings support unauthorized access and possible exposure, not confirmed exfiltration, publication or encryption.
Attribution and confidence
INC Ransom listed meridenct.gov March 26. Ransomware confidence is now high because reporting conveys the city’s own characterization; actor confidence remains medium. Neither the city notices nor newly reviewed coverage corroborates INC Ransom responsibility. The group’s listing does not independently prove encryption or theft.
Disclosure posture
The city’s Feb. 17 statement referred to cybersecurity concerns and breach review before the March 26 actor claim. Organization-confirmed cyber and disruption transparency, OC–OD, remains appropriate. Later notices provide more specific acknowledgment without changing the earliest located disclosure date.
Current status and gaps
April 23 remains the latest supported operational-impact date. Without a complete all-clear or newer documented disruption, the incident remains presumed resolved, with no established end date. Initial access, affected hosts, confirmed data theft or encryption, ransom demands or payment, recovery costs and full restoration timing remain unresolved. The attorney-general filing was not directly inspected; its details are attributed to reporting rather than presented as our independent examination.