Published September 29, 2026.
In September 2025, Form Energy, the iron-air battery maker headquartered at 30 Dane Street in Somerville, Massachusetts, discovered a ransomware attack. The company took affected systems offline, brought in outside security experts, and in October 2025 began mailing letters to current and former employees whose personal and financial information was exposed.
This was an attack on a Somerville employer, not on the City of Somerville. No ransomware attack on the city government has been confirmed.
What happened in the Form Energy ransomware attack?
The timeline comes from the notice Form Energy filed with the Massachusetts Attorney General and from reporting by ISSSource:
- September 16, 2025: Form Energy discovered the ransomware attack, took affected systems offline and hired outside cybersecurity experts.
- October 22, 2025: notification letters began going out to affected current and former employees.
- October 28, 2025: the company filed notice with the attorneys general of Massachusetts, New Hampshire and California (Massachusetts filing).
Filings report 622 affected Massachusetts residents and 23 in New Hampshire (ClaimDepot summary of state filings). Form Energy offered 24 months of Experian IdentityWorks credit monitoring. The company has not said who was behind the attack, whether a ransom was demanded or paid, or how the attackers got in.
What employee information was exposed?
According to the notice, the exposed information included names, addresses, dates of birth, Social Security numbers, bank account numbers, beneficiary information and I-9 identity documents such as driver’s licenses, permanent resident cards and passports.
That list is what makes employee records so valuable to attackers. An HR file holds everything needed to open credit in someone’s name, redirect a paycheck or pass an identity check, and it often covers former employees who left years ago.
Why are HR and payroll systems such an attractive target?
Most businesses guard customer data closely and give far less thought to the HR share, the payroll portal and the scanned I-9 folder. Those files sit on file servers, in shared drives and in outside payroll and benefits platforms, each with its own logins and vendors.
When Triton takes on a new client, we sweep the whole environment, from the firewall and network to email and user accounts, to see who can log in and whether that access is still needed. We ask the client before removing anything and usually disable accounts rather than delete them, so the logs are kept. HR and payroll access gets the same review: who can open the files, which outside companies can log in, and whether records for people who left years ago still need to be kept online at all.
What does Massachusetts law require after a breach like this?
A business that owns or licenses personal information about Massachusetts residents must notify the Attorney General, the Office of Consumer Affairs and Business Regulation, and every affected resident as soon as practicable and without unreasonable delay. When Social Security numbers are exposed, it must offer at least 18 months of free credit monitoring. Form Energy offered 24.
The details, including what the notice must contain, are in our guide to the Massachusetts data breach notification law. Massachusetts also requires a written information security program under 201 CMR 17.00, which is where HR and payroll access controls should be written down before an incident, not after.
How does a business recover from ransomware without paying?
Recovery depends on having clean copies of your systems and data that the attacker could not reach, and on having tested that they restore. Backups stored on the same network with the same credentials are encrypted along with everything else.
Speed matters more than a truck in the parking lot. A technician on site does not stop ransomware; knowledge, preparation and the right tools do, and almost all of that work happens remotely.
Before an attack, confirm three things: that backups are kept separately and cannot be deleted with ordinary admin credentials, that a restore has actually been tested and documented, and that someone knows the first steps to contain an attack. The CISA StopRansomware site publishes a free response checklist.
Sources
To see where your organization stands on these controls, take the Check Your Security Readiness assessment.
Let's Discuss Your IT Needs
Triton Technologies delivers managed IT services, cybersecurity, and IT support for businesses across New England. Contact our team today to start a conversation about your technology environment.


