Skip to main content
FrontlinePrivacy
Address exposure

Westfield Fire District in Middletown, CT notified residents of a 2024 ransomware data breach

FILE 371Middletown, Connecticut2024-11-14
CLOSED

Westfield Fire District in Middletown, Connecticut sent breach notification letters in May 2025 about a cyberattack from November 2024. The Medusa ransomware group claimed the attack and demanded a $100,000 ransom. The district offered 24 months of credit monitoring, which under Connecticut law usually means Social Security numbers were exposed.

What happened

According to Comparitech, Westfield Fire District in Middletown, Connecticut had an IT outage on November 14, 2024. The Medusa ransomware group claimed responsibility on December 12, 2024 and demanded a $100,000 ransom. The district has not confirmed Medusa's claim or said whether it paid. In May 2025, the district sent breach notification letters. The notice said certain files may have contained personal information belonging to its members. The district did not disclose how many people were notified or exactly what data was taken. It offered 24 months of free credit monitoring, which Connecticut law requires for at least 24 months when Social Security numbers are among the exposed data.

What reduces this risk

A small fire district cannot easily stop a ransomware crew, and no individual member could have prevented this breach. What you can limit is what happens after data leaks: whether your home address ends up searchable on people-search sites. Connecticut's residential-address nondisclosure law (Conn. Gen. Stat. § 1-217) lets sworn police officers, judges, and firefighters ask public agencies to keep their home addresses out of public records, but it does not list EMS or dispatchers — and it only reaches government records, not the data brokers that resell your address. In 2026 the state passed a broad consumer privacy law (Public Act 26-64) that will let residents ask registered data brokers to delete their information through a state-run tool, though that tool is not required to be running until July 1, 2028. Filing removals at the data brokers now is the step that does not wait on a statute.

Public sources