Two things happened in Everett in the same week. On Sunday, September 6, the city discovered a “cybersecurity incident” on its internal network, and City Hall has been closed to the public ever since, now through at least September 17. On Friday, September 11, the city’s former director of information technology, Kevin Dorgan, was arraigned in Malden District Court on a larceny charge over city Amazon purchases. He ran the IT department for ten years and was fired in March.
The question arrives in our inbox and in comment threads in the same words: is this the same story? Did a fired IT director leave something behind, a “dead man’s switch,” that went off? The honest answer is that nothing on the public record connects the two, no official has suggested it, and the charge against Dorgan has nothing to do with computer access. But the question is a reasonable one for a resident to ask, because insider sabotage by departed IT staff is a real and prosecuted category of crime. So this piece takes the question seriously: what a dead man’s switch is, what the cases where one was actually used looked like, why the Everett timeline cuts against the simplest version of the theory, what investigators would look for, and what would have to become public for anyone to say more than “no evidence.”
One thing first. Dorgan is presumed innocent of the larceny charge, and he has not been accused of anything connected to the network incident by anyone. This article does not accuse him. It explains why the question is being asked and how it would be answered.
The two timelines, side by side
Dorgan joined Everett’s IT department around 2012 and was appointed director in January 2016 by then-Mayor Carlo DeMaria. The City Council reappointed him in May 2024 through January 5, 2026. That was the day Robert Van Campen was inaugurated as mayor after defeating DeMaria. Dorgan was fired in March 2026. The city has never said why. After the termination, according to the Middlesex District Attorney’s office, the city inventoried his office and found stacks of unopened packages, which led to the review of the city’s Amazon account and, six months later, the larceny charge. Neal Ellis served as interim IT director; in August the mayor appointed Norilyz Valentin, formerly of the state’s IT division and the City of Chelsea, as the permanent director. Ellis said at the time that “many of the systems we’re using today are 15 to 20 years behind current standards.” Our full report on the charge is here.
The incident was discovered at about 6:30 p.m. on Sunday, September 6. City Hall closed Tuesday, September 8, was extended through Thursday, then through September 17. The city’s statements say its “IT professionals and investigators are working around the clock,” that the Everett Police Department is involved, and that the incident affects the “internal network and technology systems.” Police, fire, public works, schools and libraries are unaffected, and third-party online payment systems still work. The city has not said what kind of incident it is, whether ransomware is involved, whether any data was taken, or whether any outside agency is investigating. Our guide to the closure and to what the city must disclose if resident data was taken is here.
The same weekend, Springfield’s public schools were shut for a week by what the district described as an outside group that gained access to its network. Municipal and school networks in Massachusetts are attacked constantly. The most common explanation for a city network going down in September 2026 is the common one.
What a dead man’s switch is
In the computer context, a dead man’s switch, or logic bomb, is code planted inside a system that does nothing until a condition is met, and then does damage. The condition can be a date, a missed check-in, or, in the version the phrase usually refers to, the disabling of the planter’s own account. The idea is that the person who built it is the only one who knows it is there, and it fires when they are gone.
These are not hypothetical. The clearest recent example is the case of Davis Lu, a software developer at a company headquartered in Beachwood, Ohio, from 2007 to 2019. After a 2018 reorganization reduced his responsibilities and access, he planted code in the company’s production systems, including a routine he named “IsDLEnabledinAD,” short for “Is Davis Lu enabled in Active Directory.” It checked whether his own account still existed and, if it did not, locked out every user. On September 9, 2019 he was placed on leave and told to return his laptop. His credentials were disabled, the switch fired, and thousands of users worldwide were locked out. A federal jury in Cleveland convicted him in March 2025 of intentionally damaging a protected computer, and in August 2025 he was sentenced to four years in prison. The company said it took more than a year to be sure his code was gone.
An older and different case is Terry Childs, the San Francisco network administrator who in 2008 changed the administrative passwords on the city’s core network after being disciplined and refused for twelve days to give them to anyone else. That was not a planted switch. It was a live lockout, and he was in custody while it ran. He was convicted of felony network tampering in 2010 and sentenced to four years.
Two features of those cases matter for Everett. In both, the trigger was the loss of the insider’s access, and the damage followed immediately: the same day for Lu, within hours for Childs. And in both, the perpetrator was a technical employee with deep administrative access who had a recent grievance against the employer.
Why the Everett timeline cuts against the simple version
If a dead man’s switch of the Lu type had existed in Everett, the moment it would have fired was March, when Dorgan was terminated and, if the city followed ordinary practice, his accounts were disabled. Nothing has been reported about a network failure in March. The incident came six months later, after an interim director had spent the spring and summer evaluating the systems closely enough to conclude they were fifteen to twenty years out of date, and a month after a new permanent director was named.
That does not make the theory impossible. Logic bombs can be set to a date rather than to an account check, and code can sit dormant for a long time in a large, old environment. But it makes the simple version, fired employee’s switch goes off, a poor fit for the facts as they are known. It also raises the opposite question, which is the one an investigator would actually ask: not whether Dorgan planted something, but whether the city fully disabled a departed administrator’s access at all. An account left live for six months is not sabotage by the former employee. It is an offboarding failure by the employer, and in a department running systems that far behind, it is a more ordinary failure than a logic bomb.
There is a third possibility that has nothing to do with the former director: that the same weaknesses an interim director could see from the inside were visible from the outside, and someone walked in. That is what happened in Springfield the same weekend, on the district’s own account.
What investigators actually look for
The city’s statement refers to “investigators,” which in a municipal incident usually means an outside incident response firm retained through the city’s cyber insurance carrier, working with police. Whether a federal agency is involved has not been stated. The work is the same regardless of who does it: build a timeline from logs, identify the first point of entry, identify what ran and when, and identify whose credentials did it.
That last step is where an insider theory lives or dies. If the first malicious action was taken with an external attacker’s tools after a phishing email or an exposed remote-access service, the investigation goes outward. If it was a scheduled task, a service account or an administrative login that traces to a former employee’s access, the investigation goes to that employee, and the city would be obligated to refer it to prosecutors. Investigators also look at whether the former employee’s accounts were disabled and when, whether any accounts were created in the former employee’s tenure that survived his departure, and whether backups were touched.
None of that is public, and it will not be for a while. Cities do not narrate forensic investigations in real time, on advice of counsel and of their insurers, and because describing the entry point before it is closed helps the next attacker.
What the law would say if it were true
If, and this is a hypothetical about a category of crime rather than about any person, a former employee had planted code that damaged a Massachusetts city’s network, the charges would look like Lu’s. The federal Computer Fraud and Abuse Act, 18 U.S.C. § 1030(a)(5)(A), reaches anyone who “knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer.” A municipal network qualifies. That is the statute Lu was convicted under, and the penalty is up to ten years.
Massachusetts’s own computer statutes are weaker. G.L. c. 266, § 120F, unauthorized access to a computer system, carries a maximum of thirty days in a house of correction. The state charge with real weight would be G.L. c. 266, § 127, willful and malicious destruction of property, which carries up to ten years in state prison or a fine of three times the damage. Whether data on a municipal server is “property” within that statute is a question prosecutors would have to answer, and it is one reason cases like this tend to be brought federally.
None of these charges has been brought against anyone in connection with the Everett incident.
What would settle the question
Any of four things. A statement from the city, the Middlesex District Attorney or a federal agency naming a cause. A public after-action report, which some Massachusetts municipalities have produced after incidents and which the City Council could request. A breach notification under G.L. c. 93H, which the city would have to send to affected residents if personal data was taken and which would describe the incident in general terms. Or a charge.
Until one of those happens, the responsible statement is the one the city’s own silence supports: the cause of the September 6 incident has not been disclosed, the larceny case against the former IT director concerns purchases and nothing else, and no one in a position to know has connected them. Readers who want to keep asking should ask the City Council, in public session, two specific questions that the city can answer without compromising the investigation: were all of the former director’s credentials disabled at termination, and is any current or former employee a subject of the incident investigation. A yes to the first and a no to the second would end the speculation. The city has not been asked in public yet.
Common questions
Has anyone said the Everett cyberattack is connected to Kevin Dorgan?
No. No official, court filing or news report has connected them. Dorgan’s charge is larceny over city Amazon purchases. He is presumed innocent of that charge and has not been accused of anything involving the network.
What is a dead man’s switch in computing?
Code planted in a system that stays dormant until a condition is met, often the disabling of the planter’s own account, and then does damage. The Davis Lu case, in which a developer’s “kill switch” locked out thousands of users the day he was placed on leave in 2019, is the leading recent prosecution.
Why does the timing matter?
Account-triggered switches fire when access is revoked. Dorgan was fired in March 2026. The incident was discovered September 6, six months later. A date-triggered bomb is possible but the simple version of the theory does not fit.
What would the charges be if an insider did it?
Federally, 18 U.S.C. § 1030(a)(5)(A), intentional damage to a protected computer, up to ten years. In Massachusetts, G.L. c. 266, § 127, malicious destruction of property, up to ten years; § 120F, unauthorized access, carries only thirty days.
What has the city said about the cause?
Nothing. It has described a “cybersecurity incident affecting its internal network and technology systems,” said IT professionals, investigators and Everett police are working on it, and extended the closure through September 17.
Everett incident statements from the City of Everett’s September 7 and September 14 notices and CBS Boston. Dorgan charge from the Middlesex District Attorney’s statement as reported by Boston 25 and NBC10 Boston; his tenure from the Everett Independent. Davis Lu facts from the U.S. Department of Justice release of August 21, 2025. Terry Childs facts as reported by Computerworld and Help Net Security, 2010. Statutes read at malegislature.gov and the Cornell Legal Information Institute. Kevin Dorgan is presumed innocent of the larceny charge and has not been accused of any conduct relating to the network incident. General information about Massachusetts law, not legal advice.
