City of New Britain

A ransomware attack disrupted New Britain municipal systems beginning Jan. 28, 2026, forcing manual workarounds while police and fire services remained operational. The city later said limited unauthorized activity may have exposed sensitive personal information.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
Unauthorized access to systems, accounts, networks, or data.
An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
Internal or external network connectivity was unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.
The extortion activity involved unauthorized encryption of systems or data, with restoration or decryption conditioned on payment.
The City of New Britain experienced a confirmed ransomware attack that disrupted municipal systems beginning Jan. 28, 2026. The city’s Jan. 29 media advisory said certain systems were affected and that state and federal authorities were assisting. WFSB later reported that officials confirmed ransomware.
Phone and computer systems in multiple departments were disrupted, and some employees used pen and paper. Police and fire services remained operational. The city began a phased restoration by Feb. 2, but no public notice establishing a final restoration date was located.
In April, Connecticut Public reported that the city found the unauthorized activity was limited in scope but that some records containing names, dates of birth, government identification numbers, financial-account information or health information may have been accessed. The city offered identity-protection services to potentially affected people.
Confidence is high that ransomware caused operational disruption. The public record supports possible exposure of sensitive records but does not establish the full affected population, complete data inventory, initial-access method, ransom demand or payment. No named threat actor or independently verified leak-site claim was located.
City statements confirmed the disruption and response; subsequent public reporting attributed ransomware to city officials and described the potential data exposure.
The incident is presumed resolved because services entered phased restoration and later reporting focused on investigation and notification rather than a continuing outage. A final restoration date was not found.

We reported network disruption, manual workarounds, ransomware confirmation and later data-breach disclosures.
WFSB reported municipal system disruption and the continued operation of police and fire services.
The city said certain systems were affected, public safety remained operational and state and federal authorities were assisting.
Connecticut Public reported the city’s disclosure of limited unauthorized activity and possible personal-information exposure.
Signed-in members can report an error, update, or missing source.