The City of New Britain, a municipal government in Connecticut serving more than 74,000 residents, has notified the Vermont Attorney General’s Office of a data breach that exposed Social Security numbers and health records belonging to individuals connected to the city.
Government entities that collect and store sensitive personal and health information have a responsibility to protect that data, and a breach of this kind can leave affected individuals vulnerable to identity theft and other forms of fraud.
The City of New Britain’s Data Breach Investigation
The City of New Britain reported to the Vermont Attorney General’s Office on July 30, 2026, that a data breach had exposed Social Security numbers and health records belonging to individuals connected to the city. According to the filing, five Vermont residents were affected. The City of New Britain has not publicly disclosed how the breach occurred, when it was first discovered, or how many individuals nationwide may have been affected beyond the Vermont-specific figure reported to that state’s regulator.
Municipal governments like the City of New Britain routinely maintain large databases containing highly sensitive information on residents, employees, and program participants, including Social Security numbers tied to payroll, tax records, and social services, as well as health records connected to municipal health departments, employee benefits programs, or public health initiatives. This combination of data types, Social Security numbers alongside health records, is particularly valuable to cybercriminals because it can be used not only for traditional identity theft and fraudulent credit applications, but also for medical identity theft, insurance fraud, and highly targeted phishing schemes that reference a victim’s actual medical history to appear more convincing.
Local governments have increasingly become targets of cyberattacks in recent years, in part because municipal IT infrastructure often operates with more limited cybersecurity budgets and staffing than private-sector organizations handling comparable volumes of sensitive data. Ransomware groups and data thieves have specifically targeted city and county governments, school districts, and other public entities, recognizing that these organizations frequently hold decades of resident records while facing real constraints on modernizing their security systems.
When a government entity discloses a breach only to a single state’s attorney general, as the City of New Britain has done here with Vermont, without a broader public statement addressed to Connecticut residents or the general public, it can leave many potentially affected individuals unaware that their information was involved. It is common for a breach affecting a municipality’s own residents, employees, or program participants to also affect a small number of out-of-state individuals who have some connection to the city, such as former employees who have since moved, which is likely why this filing specifically addresses Vermont residents.
Government entities are generally required to notify affected residents and file notices with state regulators within windows set by each state’s breach notification laws. Because these filings are often made on a state-by-state basis, a single filing like the one made with Vermont may represent only a small fraction of the total number of individuals affected by the underlying incident, with other states’ notifications sometimes following on a different timeline.
Because the City of New Britain has not disclosed the cause of the incident, affected individuals should remain alert to phishing attempts that reference the breach. Scammers frequently exploit publicized data breaches by sending fraudulent communications that impersonate the affected organization and request sensitive information under false pretenses. A legitimate government notice will not ask a resident to provide a full Social Security number or other sensitive data by email, text, or phone call.
Anyone with a connection to the City of New Britain, whether as a resident, current or former employee, or program participant, who has not yet received formal notification about this incident should not assume they are unaffected, and should watch closely for any official communication from the city in the coming weeks.
Breach notification timelines for government entities can also be affected by the need to coordinate with law enforcement during an active investigation, particularly when a ransomware attack or unauthorized network intrusion is suspected. In many cases, a municipality is asked to delay public disclosure temporarily so investigators can assess the scope of an intrusion without tipping off the responsible parties, which can add further delay between when a breach is first detected internally and when residents ultimately receive notice. This is a normal part of the regulatory and law enforcement process and does not necessarily indicate that a government entity acted carelessly in how it responded once the incident was discovered.
When Did This Breach Occur?
The City of New Britain reported the breach to the Vermont Attorney General’s Office on July 30, 2026. The city has not publicly disclosed when the underlying security incident actually occurred or when it was first discovered, and it is common for the date of internal discovery to precede a public or regulatory disclosure by weeks or months while an investigation is completed.
What Information Was Breached?
According to the City of New Britain’s filing with the Vermont Attorney General’s Office, the breach exposed Social Security numbers and health records belonging to five Vermont residents. The city has not disclosed whether additional categories of personal information were also involved or whether individuals in other states, including Connecticut, were affected by the same incident.
What You Can Do
If you have received a notice from the City of New Britain about this breach, or believe you may have been affected, consider taking the following steps:
- Review your credit reports for any unfamiliar accounts or inquiries
- Place a fraud alert or credit freeze with the three major credit bureaus
- Monitor your health insurance statements and explanation-of-benefits notices for services you did not receive
- Be cautious of unsolicited emails, texts, or calls referencing the breach
- Consider enrolling in any credit monitoring or identity theft protection services the city may offer
File a Data Breach Lawsuit Against The City of New Britain
If you were notified that your personal information was exposed in the City of New Britain data breach, you may have legal options available to you. Entities that collect sensitive information like Social Security numbers and health records are expected to implement reasonable safeguards to protect it, and a failure to do so can form the basis of a class action lawsuit.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.