Published September 29, 2026.

Two Connecticut cities were hit by ransomware in early 2026. New Britain and Meriden have since reported that the attacks may have exposed the personal information of more than 12,600 residents, according to notices filed with the Connecticut Attorney General and reported by CT Examiner. The exposed data included Social Security numbers, driver’s license and passport numbers, financial account information and health information.

What happened in the New Britain and Meriden ransomware attacks?

  • New Britain: the attack ran from January 23 to 28, 2026. The city discovered it on February 1, notified residents on March 27 and filed notice with the Attorney General in July. 10,339 residents were possibly exposed. The city said it secured its environment, investigated and notified law enforcement.
  • Meriden: the attack ran from February 9 to March 13, 2026. The city discovered it on February 12, notified residents on June 2 and filed notice in June. 2,325 residents were possibly exposed. The city said it wiped and rebuilt affected systems and began a review of its policies and procedures, working with forensic specialists.

Both cities offered 24 months of credit monitoring, as Connecticut law requires when Social Security numbers are involved. Neither has named the ransomware group or said whether a ransom was paid (CT Examiner).

Consultant and business owner discussing a data breach response in a small town office

Why do attackers keep targeting Connecticut towns and small organizations?

Cities and small businesses share the same problem: years of systems added one at a time, many outside vendors with remote access, and a small team expected to watch everything. Attackers look for the easiest door, and an old account or an unwatched alert is usually it.

Meriden’s attack lasted about a month after it was first discovered. Stopping an attacker once they are inside means finding every way they got in and every account they touched, which is slow work if nobody documented the environment beforehand.

Almost every business we take over has alarms and notifications that nobody acts on. Reading security alerts is not an office manager’s job, and many IT providers react only to what lands directly in front of them. Triton runs its own SIEM (security information and event management) and monitoring so warnings are reviewed and patches are applied on schedule.

What should a Connecticut business do before an attack like this?

When Triton takes on a new client, we sweep the whole environment, from the firewall and network to email and user accounts, to see who can log in and whether that access is still needed. We ask the client before removing anything and usually disable accounts rather than delete them, so the logs are kept.

  • List every outside company that can log in, confirm each uses its own account with MFA, and remove access that is no longer needed.
  • Keep backups separate from the network, protected from deletion, and tested with a documented restore.
  • Make sure someone reviews security alerts every day, including weekends.
  • Know who your cyber insurance carrier wants you to call first, and write down the first steps to contain an attack.

Does multifactor authentication stop ransomware?

Multifactor authentication stops the most common way in: a stolen password. CISA calls phishing-resistant MFA, such as FIDO2 security keys, the gold standard, and says app-based codes or push approvals with number matching are the best option for small and medium-size businesses that cannot adopt it right away (CISA fact sheet).

The most common fix we make in small offices is password resets and multifactor setup. MFA does not have to be a maze: with simple tokens and one standard method, staff sign in securely without odd phone calls or extra steps.

MFA is one layer. It works alongside patching, monitoring, backups and a response plan, and it only helps on the accounts where it is actually turned on.

Employee approving a multi-factor sign-in request on her phone

Sources

To see where your organization stands on these controls, take the Check Your Security Readiness assessment.

Let's Discuss Your IT Needs

Triton Technologies delivers managed IT services, cybersecurity, and IT support for businesses across New England. Contact our team today to start a conversation about your technology environment.

Triton Technologies support engineer at workstation

related posts