Three Massachusetts Towns, Twelve Days, Three Cyberattacks. Here Is What the Law Makes Them Tell You, and What It Does Not.

No fixed deadline, no duty to say what happened, no private lawsuit, and no statewide security standard for municipalities. What residents can still obtain, and why a shared vendor is the thing to look for.

Everett City Hall has been closed to the public since September 8. Springfield canceled a week of school. Sutton announced Wednesday that it is investigating an incident on the town network that may reach its public schools. Three Massachusetts municipalities in twelve days, and no official has said whether any of them are related.

Municipal networks get attacked constantly, and most incidents never become public because nothing visible breaks. What makes this stretch notable is that all three broke something residents could see: a closed city hall, canceled classes, and a town telling families it is reviewing what data was touched. This piece sets out what is known about each, what Massachusetts law requires a city or town to do, and the gap between what residents want to know and what a municipality is permitted or required to tell them.

The three

Everett discovered an incident on its internal network at about 6:30 p.m. on Sunday, September 6, and announced it the next day. City Hall closed on September 8 and has stayed closed, most recently through September 17, with basic services running out of the Connolly Center on Chelsea Street. Police, fire, public works, schools and libraries have operated normally, and third-party online payment systems have kept working. The city has not said what kind of incident it was, whether data was taken, or when the building reopens. We covered what residents can do during the closure in our guide.

Springfield Public Schools canceled classes for a week after an outside group gained access to the district’s network and blocked access to third-party systems including student medical records, transportation and food services. Students returned September 14. This week the district and the FBI confirmed that student and staff data was breached. The scope has not been stated. What the district owes families is in our report.

Sutton announced its incident Wednesday. Town and school officials said they contained it when it was found, and that law enforcement and cybersecurity and forensic experts are working to determine the scope and what data may have been affected. Municipal services are operating. The town’s statement included the sentence that every one of these notices eventually contains: “If the investigation determines that personal information was involved and that notification is required under applicable law, affected individuals will be notified as appropriate.”

That sentence is not corporate hedging. It is a description of what the statute requires, and it is worth unpacking.

What the law actually requires

The Massachusetts data breach statute, G.L. c. 93H, applies to any “agency,” which the statute defines to include any authority “of any political subdivision” of the Commonwealth. Cities, towns and school districts are covered. There is no municipal exemption.

The obligation is triggered by a breach of security involving “personal information,” which the statute defines narrowly: a resident’s name combined with a Social Security number, a driver’s license or state identification number, or a financial account or card number. A resident’s name, address, email or even medical appointment history, standing alone, is not personal information under Chapter 93H.

That definition is why these announcements take weeks to become notices. A town cannot say whether notification is required until it knows which categories of record were accessed. It is also why an incident can be serious, disruptive and expensive without ever producing a single letter to a resident.

When the obligation is triggered, three notices are due “as soon as practicable and without unreasonable delay”: to the Attorney General, to the Office of Consumer Affairs and Business Regulation, and to each affected resident. The notices to the two state offices must describe the nature of the breach, the number of residents affected, the type of information compromised, and whether the municipality maintains a written information security program. The notice to the resident must state the right to obtain a police report, how to request a security freeze, and that the freeze is free. And the statute expressly forbids the resident’s notice from describing the nature of the breach or the number of people affected.

Where Social Security numbers were exposed, G.L. c. 93H, § 3A requires the entity to provide credit monitoring at no cost for at least eighteen months and forbids conditioning it on a waiver of the right to sue.

What the law does not require

This is the part residents find hardest to accept.

No deadline in days. “As soon as practicable and without unreasonable delay” is the whole standard, and law enforcement may ask a municipality to hold notice while an investigation runs. An FBI investigation, as in Springfield, is exactly that circumstance.

No duty to say what happened. Nothing in Chapter 93H obligates a city to tell the public whether it was ransomware, whether a ransom was demanded or paid, or how the intruder got in. Municipalities routinely decline on the advice of counsel and their insurers, partly because describing an unpatched entry point before it is closed helps the next attacker.

No private lawsuit. Chapter 93H creates no private right of action. Enforcement belongs to the Attorney General. A resident’s tort claim against a municipality runs into the Tort Claims Act, G.L. c. 258, with its presentment requirement, its $100,000 cap, and its discretionary function immunity, before ever reaching the problem of proving actual harm rather than increased risk.

No cybersecurity standard for municipalities. Massachusetts requires businesses that hold personal information to maintain a written information security program under the Attorney General’s data security regulations. There is no equivalent statewide mandate that a town meet any particular security baseline, and no state body audits municipal networks. The 93H notice form asks whether the entity maintains a written program, which is a question, not a requirement.

What residents can actually get

The public records law, G.L. c. 66, § 10, reaches municipal records, and an incident response is documented: contracts with forensic vendors, communications with insurers, invoices, and the notices sent to the Attorney General. Those are ordinary municipal records and a request costs nothing to make.

The exemptions are real. Records that would compromise an active law enforcement investigation may be withheld, and so may records whose disclosure would jeopardize the security of an information system. A town will invoke both. But a request for the vendor contract, the total cost to date, and the date of the notice filed with the Attorney General is usually harder to refuse than a request for the forensic report, and the cost figure is what eventually tells a community what happened to it.

The other route is the Attorney General’s breach notification database, which publishes reported breaches. A notice filed there confirms that a municipality concluded personal information was involved, which is the fact a town’s own statements tend to leave unresolved for months.

Whether these are connected

Nobody has said so, and it should not be assumed. NBC10 Boston noted directly that authorities have not said whether the incidents are related.

There are two ordinary explanations that do not require a single actor. Municipalities and school districts run similar software from a small number of vendors, so one vulnerability can produce a cluster of unrelated intrusions in the same weeks. And the start of the school year is a period when districts are onboarding accounts at volume, which is when phishing works best.

A shared vendor would be the thing to look for, and it is the kind of detail that emerges from breach notices months later rather than from press statements now.

What to watch

Whether Everett reopens City Hall on schedule, and whether it eventually says what happened. Whether any of the three files a notice with the Attorney General, which is the first hard confirmation that personal information was involved. What Springfield’s notice says when it arrives, given the FBI’s confirmation that data was breached. And whether the Legislature takes any interest, because the practical answer to a municipal cybersecurity gap is money and a standard, and Massachusetts currently mandates neither.

Common questions

Does the Massachusetts breach law cover cities and towns?

Yes. G.L. c. 93H applies to any agency of a political subdivision, which includes municipalities and school districts.

How long does a town have to notify residents?

As soon as practicable and without unreasonable delay. There is no fixed number of days, and law enforcement may request a delay during an active investigation.

Why will a town not say whether it was ransomware?

Nothing in the statute requires it. Municipalities generally withhold that on advice of counsel and insurers, and because describing an entry point before it is secured creates further risk.

Can residents sue a town over a breach?

Not under Chapter 93H, which has no private right of action. A tort claim faces the Tort Claims Act’s presentment rule, a $100,000 cap and discretionary function immunity, plus the requirement to prove actual harm.

Are the Everett, Springfield and Sutton incidents connected?

No official has said so. Authorities have not stated whether any of the incidents are related.

Sutton facts and the town’s quoted statement as reported by NBC10 Boston and WCVB, September 16, 2026. Everett facts from the city’s own notices and prior reporting. Springfield facts as reported by WBUR, Boston 25 News, WCVB and NBC10 Boston, September 15 and 16. G.L. c. 93H, §§ 1, 3 and 3A, c. 258 and c. 66, § 10 read at malegislature.gov. General information about Massachusetts law, not legal advice.

About·Contact·Get the Weekly Digest·Opinion Archive·Privacy Policy·Terms of Use·Disclaimer
© 2026 Massachusetts Legal Resources
Massachusetts Legal Resources republishes public-domain opinions of the Massachusetts appellate courts together with original case summaries. Official versions are published in the Massachusetts Reports and Appeals Court Reports. Nothing on this site is legal advice, and reading it does not create an attorney-client relationship.