Meriden Cyberattack May Have Exposed Data of 2,325 Residents

City records say residents were notified months after the February network incident.

A laptop with a handwritten “No Wi-Fi” note; Meriden’s city network was taken offline after the February cyber incident

MERIDEN, CT — State breach records reported Thursday, Sept. 17, show a February cyberattack on Meriden’s computer network may have exposed personal information belonging to 2,325 Connecticut residents. CT Examiner reported the figure from notices filed with the state Office of the Attorney General.

The records say the breach began Feb. 9, 2026, the city discovered the incident Feb. 12, and the breach continued until March 13. In a February notice, the city said it had identified an attempted interruption of internet services and was reviewing the incident before restoring them.

Meriden breach may have exposed 2,325 residents’ data

In its Feb. 17 notice, the city said its IT department responded after detecting the attempted interruption and that emergency services would not be affected. It warned that non-essential services could be limited or altered and canceled that night’s City Council meeting because of the disruption.

The city’s breach notice, as described by CT Examiner, said officials became aware in May that personal data might have been exposed. The city notified affected residents in June, according to the report. Potentially exposed information included names, birth dates, driver’s license and Social Security numbers, passport numbers, financial account details, medical information, and health insurance information.

A Meriden resident who received a notice told CT Insider he was upset by the delay. The letter said there was no evidence his information had been specifically misused. It also said the FBI was investigating, according to CT Insider.

City responded to internet-services interruption

The city’s public notice from Feb. 17 said officials were conducting a comprehensive review to determine the incident’s scope and nature before returning internet services. It did not give a restoration date. The more recent reporting says the breach ended March 13; it does not establish when all internet services were restored.

As The Quinnipiac Post reported in March, the city ran on a partially restored network for weeks after the shutdown: departments recorded transactions by hand, tax payments were limited to bank checks, the public library’s computers were taken out of service and emergency dispatch was temporarily moved to the Connecticut State Police Academy. Officials said at the time that the incident had not been classified as ransomware. CT Examiner reported that the city’s breach notice identified the attack as ransomware.

What residents were offered

The city’s notice offered affected residents two years of credit monitoring and fraud-resolution services, according to CT Insider. It said the city had worked with forensic specialists, wiped and rebuilt affected systems, and taken steps to strengthen its network. The notice also said the city was reviewing its policies and procedures and examining how it stored and managed data.

Residents who received a breach notice can review it for details about the credit-monitoring and fraud-resolution services offered by the city. The city’s Feb. 17 notice also advised people with appointments at city departments to call those departments to confirm during the outage.


Got a tip? Reach out to us at tips@thequinnipiacpost.com.

Never miss Meriden news

Free local news delivered to your inbox — no spam, unsubscribe anytime.