CSIDB logo
Incident

City of Meriden

Incident posture

Attack window
Mar 2026
Location
United States of America
Status
Ongoing
CIA posture
Available to members
Updated
2026-08-27 00:09

Linked entities

Victim
City of Meriden
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Undetermined
Disclosed
Feb 2026
Resolved
Pending

Summary

The city of Meriden was targeted by a ransomware group named Inc, which claimed responsibility for the breach and said it had stolen data. City officials reported the attack, noting that it caused significant disruptions to municipal services and that recovery efforts were ongoing. The incident contributed to a broader trend of ransomware attacks on local governments, highlighting the vulnerability of public sector networks to cyber extortion.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On February 17, 2026, officials from the City of Meriden, Connecticut, reported that they had detected a cyberattack on municipal systems. The attack was subsequently claimed by a ransomware group identifying itself as Inc. According to the group's statement, they had successfully infiltrated the city's network and exfiltrated data. City officials confirmed that the incident prompted an immediate response to isolate affected systems. The disruption caused by the attack affected multiple city services, though the specific services impacted were not detailed in the source. The ransomware claim was circulated in public reports on March 31, 2026.

More than a month after the initial disclosure, city administrators indicated that restoration efforts were still underway as of March 31, 2026. The ongoing work involved bringing back online systems that had been taken offline during the incident. While the exact volume or type of data taken was not specified, the attackers asserted that data had been stolen. No information was provided about whether any ransom demand was made or paid. The incident contributed to a broader trend of ransomware activity targeting municipal entities noted in other reports. The city's continued restoration activities underscored the persistent impact of the attack on its operational capacity.

Sources

Sources available to members: 1 source.

CSIDB