Skip to content
Phishing Attack Compromises Emails at Connecticut DCF

Phishing Attack Compromises Emails at Connecticut DCF

First seen 10 Jul 2026, 03:25 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 14:16 UTC
  • •Phishing attack on Connecticut DCF compromised two staff email accounts.
  • •Personal information may have been accessed; ongoing review of affected emails.
  • •State agencies are collaborating with law enforcement for investigation.

On May 20, 2026, the Connecticut Department of Children and Families (DCF) reported a phishing incident that compromised email accounts of two staff members. The attack involved a sophisticated external phishing email that allowed the attacker to download emails from these accounts. The Department of Administrative Services (DAS) quickly expelled the attacker from state systems and removed the malicious email from all user inboxes. DCF is currently reviewing the affected emails to determine the extent of personal information or confidential records compromised. Notifications will be sent to affected individuals, offering credit monitoring and identity theft protection services. The incident has been referred to law enforcement, and the investigation is ongoing. DCF emphasizes the importance of cybersecurity training for state employees to prevent such attacks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 10d ago How this analysis works

Timeline

2026-05-20
Phishing email received by DCF employees
DCF employees received a sophisticated phishing email that led to the compromise of two email accounts.
Wtnh
2026-05-20
Attacker expelled from state systems
The Department of Administrative Services expelled the cyber attacker from state systems on the same day the phishing email was received.
Connecticut.News12
2026-07-09
Public disclosure of phishing incident
DCF publicly addressed the phishing incident and its implications for personal data security.
Nbcconnecticut

More articles in this cluster (3)

Common questions

What personal information was compromised?
The investigation is ongoing to determine how many emails contained personal information or confidential records.
What steps is DCF taking to mitigate the impact?
DCF is reviewing affected emails, notifying impacted individuals, and offering credit monitoring and identity theft protection services.
How can state employees prevent phishing attacks?
State employees receive regular cybersecurity training to recognize suspicious messages and prevent phishing attacks.