Westfield Fire District in Middletown, Connecticut sent breach notification letters in May 2025 about a cyberattack from November 2024. The Medusa ransomware group claimed the attack and demanded a $100,000 ransom. The district offered 24 months of credit monitoring, which under Connecticut law usually means Social Security numbers were exposed.
What happened
According to Comparitech, Westfield Fire District in Middletown, Connecticut had an IT outage on November 14, 2024. The Medusa ransomware group claimed responsibility on December 12, 2024 and demanded a $100,000 ransom. The district has not confirmed Medusa's claim or said whether it paid. In May 2025, the district sent breach notification letters. The notice said certain files may have contained personal information belonging to its members. The district did not disclose how many people were notified or exactly what data was taken. It offered 24 months of free credit monitoring, which Connecticut law requires for at least 24 months when Social Security numbers are among the exposed data.
Why small fire districts get breached
Fire districts, water districts, and regional dispatch centers often run lean IT operations. They hold HR files, payroll, and sometimes patient-care records on shared servers, without the security budget of a large state agency. That combination — soft systems holding sensitive data — can make them attractive targets for ransomware crews.
A district holds records on two groups: its own personnel and the residents it serves. When files leak, both can be exposed. Westfield's notice did not break down whose data was in the affected files, so members and residents alike were told to watch their credit.
What this means for you
If you work for a Connecticut fire department or EMS agency, this is the gap. Section 1-217 lets sworn police officers, judges, and firefighters file a written request to keep their home addresses out of public records, but it does not cover EMS or dispatchers. And it only reaches government records. A breach like Westfield's can still push your name and personal details into a buyer's database, and from there onto people-search sites that publish home addresses.
Connecticut's 2026 privacy law will eventually give residents a state-run way to ask data brokers to delete their data, but that deletion tool is not required until 2028. The state has no first-responder-specific removal law like New Jersey's Daniel's Law, which lets covered officers demand that data brokers and websites take down their home address and unpublished phone number. Until the new tools exist, filing removals at the brokers is the step you control — it does not wait on a statute.
Frontline Privacy finds those broker listings, files removal requests, and keeps checking for records that come back.
What reduces this risk
A small fire district cannot easily stop a ransomware crew, and no individual member could have prevented this breach. What you can limit is what happens after data leaks: whether your home address ends up searchable on people-search sites. Connecticut's residential-address nondisclosure law (Conn. Gen. Stat. § 1-217) lets sworn police officers, judges, and firefighters ask public agencies to keep their home addresses out of public records, but it does not list EMS or dispatchers — and it only reaches government records, not the data brokers that resell your address. In 2026 the state passed a broad consumer privacy law (Public Act 26-64) that will let residents ask registered data brokers to delete their information through a state-run tool, though that tool is not required to be running until July 1, 2028. Filing removals at the data brokers now is the step that does not wait on a statute.
Public sources
- Connecticut fire department notifies residents of data breach claimed by ransomware gang — Comparitech, 2025-05-08