New Britain, Connecticut
Incident posture
Linked entities
- Victim
- New Britain, Connecticut
- Threat actors
- 0 actors
- Sources
- 2 sources
Timeline
Summary
A significant ransomware attack struck a Connecticut municipality in late January, paralyzing phone and computer systems across multiple departments while leaving safety operations intact. City officials worked alongside state authorities, the FBI, and independent cybersecurity experts to investigate the scope of network infrastructure impacted and determine how much data had been compromised. As of early March, the city was still calculating the costs of the breach and evaluating system security to reduce future risk, though the majority of core systems had been restored with enhanced monitoring and security protocols implemented. The attack was confirmed as ransomware, but officials did not disclose whether any ransom was paid.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In late January 2026, the city of New Britain, Connecticut experienced a significant ransomware attack that disrupted municipal phone and computer systems across multiple departments. The incident began early on a Wednesday and paralyzed network operations, with the city unable to immediately assess the full scope of the intrusion. By the end of the following Friday, the phone line to the mayor's office was still returning a rapid busy signal, illustrating the extent of the communication outage. Mayor Bobby Sanchez stated that officials hoped to bring systems back online through the weekend and the following week, while acknowledging that the precise scope of the network infrastructure impacted remained unknown at that stage. It was also still uncertain how much data had been taken or required recovery efforts.
City officials confirmed that safety operations, including emergency services, were not impacted by the breach, which allowed critical public safety work to continue uninterrupted. The Connecticut Department of Emergency Services and Public Protection, the FBI, and independent cybersecurity experts were all engaged in the response, assisting with the recovery efforts and investigating the cause of the attack. Sanchez emphasized that the city was working to determine which portions of the network infrastructure were affected, describing the process as one that "takes time" and required careful, methodical execution by teams working around the clock. The city committed to bringing certain systems back online that weekend based on initial assessments, with continued progress expected thereafter.
In the weeks following the initial intrusion, the city of New Britain continued its recovery operations under the leadership of Mayor Sanchez. By early March 2026, officials reported that the city was still calculating the costs associated with the breach and was simultaneously evaluating security measures to reduce future risk. Sanchez stated that the municipality was "making steady progress in its recovery" from the January ransomware incident, having restored the majority of core systems while implementing enhanced monitoring and security protocols. The city also announced it was reviewing additional cybersecurity safeguards, operational redundancies, and training protocols to further protect municipal systems going forward. Outside experts, state authorities, and federal partners continued to collaborate with city personnel throughout the remediation process.
The New Britain incident occurred within a broader pattern of cyber threats targeting Connecticut municipalities during the same period. Meriden, a neighboring city, shut down its cyber network after discovering an "attempted interruption" on February 13, which forced city workers to maintain hand-written records across all departments except public schools. The state of Connecticut stepped in quickly to assist Meriden by relocating its emergency dispatch operation to workstations at the Connecticut Police Academy in Meriden. On March 3, Meriden began slowly restoring some online services, including email access for certain employees, though it remained unclear when systems would be fully restored. After three weeks operating from the Police Academy, the dispatch center returned to its home at the Meriden police station, according to state and local police. While no one classified Meriden's attack as ransomware, city officials in New Britain confirmed that their breach involved ransomware.
The Connecticut Intelligence Center and the Department of Emergency Services and Public Protection subsequently worked to raise awareness about the rising risk of ransomware attacks, in which threat actors gain a foothold into a network and install ransomware to encrypt data, rendering it unusable. The town or city can be forced to pay a ransom to decrypt the data and regain access. The average fee demanded in these ransomware attacks was reported to be approximately $1.1 million. Some hackers were reported to be adding extra payment demands to prevent the sale of stolen data on the dark web. According to a report from the consumer website Comparitech, there were 7,419 ransomware attacks reported worldwide in 2025, with every sector seeing an increase: 6,292 attacks on businesses (up 35% from 2024), 374 on government entities (up 27% from 2024), and 444 on healthcare companies (up 2% from 2024).
Sources
Sources available to members: 2 sources.