Ransomware attacks that disrupted the computer networks of New Britain and Meriden earlier this year may have exposed sensitive personal information belonging to more than 12,600 residents, newly released state data shows.
The records provide the clearest picture yet of the scope of the attacks, which affected city services for days in New Britain and for over a month in Meriden.
According to data breach notices filed with the Office of the Attorney General obtained by CT Examiner, attorneys for New Britain reported in July that the personal data of 10,339 Connecticut residents may have been exposed in the January cyberattack.
Meriden reported in June that 2,325 residents may have had personal data exposed in a cyberattack that the city identified as ransomware.
The information potentially exposed in the two attacks included names, dates of birth, driver’s license numbers, Social Security numbers, passport numbers, financial account information, medical information and health insurance information.
Evan Allard, the director of Connecticut Central Intelligence, said ransomware attacks and the tactics hackers use are increasing nationwide.
“Year over year, ransomware, specifically executed by financially motivated actors, is increasing exponentially, and it’s not just increasing, it’s increasing in the sectors that are targeted,” he said.
The New Britain and Meriden mayor’s offices did not respond to requests for comment about the cyberattacks and have not provided CT Examiner with records on these attacks requested under the state’s Freedom of Information law.
State police public information officers said Thursday they were not aware of any investigations into the attacks by department personnel.
Breach timeline
New Britain’s breach started Jan. 23 and ended Jan. 28. The city claims to have been aware that personal data may have been exposed on Feb. 1. Impacted residents were notified nearly two months later on March 27.
“In response to this incident, the City took steps to respond to the incident and further secure their environment, conducted an investigation, and notified law enforcement,” according to a July 30 letter from Cipriani & Werner, the city’s attorney.
City spokesperson Alisha Rayner did not respond to a request for comment Wednesday. It’s unclear who is involved in the cyberattack investigation and what, if any, measures are being taken to strengthen its cybersecurity.
Meriden’s breach began on Feb. 9, was discovered by the city on Feb. 12, and ended more than a month later on March 13. The city claims it became aware of people’s data being exposed in May, though impacted residents weren’t notified until June 2.
According to a sample notice of the breach to Meriden residents, the city said it wiped and rebuilt affected systems, initiated a review of policies and procedures, and was examining how it stored and managed data.
“Upon detecting this incident, we moved quickly to initiate a response, which includes conducting an investigation with the assistance of forensic specialists and confirming the security of our network environment,” the notice read.
What is a ransomware attack?
Ransomware attacks typically occur when hackers gain access to a computer network, often through phishing emails or malicious links. Once a person clicks on those links, Allard said, it will install malware used to access data.
Hackers can then lock an organization’s data, preventing employees from accessing their systems. Attackers then demand a ransom, often in cryptocurrency, in exchange for restoring access. Some of these ransoms can cost millions of dollars.
Allard said several variables — including the length of negotiations and the type of targeted organization — make it impossible to estimate how long it takes to recover from these attacks.
Ransomware attacks have increasingly targeted the health care, government and public utilities sectors, Allard said. He added that the best way to prevent ransomware attacks is to conduct annual cybersecurity training.
“Ransomware hinges on a critical assumption, and that assumption is that the threat actor can gain access,” Allard said. “These ransomware actors are relying on access to the overall system, so I say the best offense against this is a really good defense.”
Under state law, towns must notify the attorney general’s office of a data breach within 60 days. If a Connecticut resident’s Social Security number or Taxpayer Identification Number is believed to have been compromised in the data breach, state law requires that they be offered 24 months of credit monitoring services.
Allard said in the case of municipal cyberattack, either the town or federal agents will inform Connecticut Central Intelligence.
For people concerned about whether their information has been exposed, Allard recommends checking the website Have I Been Pwned, which tracks data exposed in known breaches. He also recommends changing passwords regularly and avoiding ones that are easily identifiable.
Update: This story was updated to include a comment from state police.
Click Here For The Original Source.
