Everett City Hall Reopens Monday. The City Still Has Not Said What Happened, and the Part That Affects Residents Has Not Started.

Restoring the systems solves the operational problem. It does not publish a cause, and most municipalities never do. Here is what is still owed and how to find out whether a notice was filed.

Everett City Hall reopens Monday, two weeks after the city discovered what it has called a cybersecurity incident on its internal network at about 6:30 p.m. on Sunday, September 6. Basic services have been running out of the Connolly Center on Chelsea Street since the building closed on September 8. Police, fire, public works, schools and libraries were never affected.

The doors opening is the end of the disruption. It is not the end of the city’s obligations, and the part that matters to residents has not started yet. This piece sets out what Everett has said, what it has not, and what the law still requires it to do.

What the city has disclosed

Very little, and that is not unusual.

Everett has described the event as a cybersecurity incident affecting its internal network and technology systems. It has not said what kind of incident it was, whether it involved ransomware, whether a ransom was demanded or paid, how the intruder got in, or whether any resident or employee data was accessed or taken. Mayor Robert Van Campen said during the closure that IT professionals and investigators were working “around the clock,” and that the Everett Police Department was involved.

Nothing in Massachusetts law compelled the city to say more than that. We set out why in our report on three towns hit in twelve days. There is no statutory deadline in days, no duty to describe the attack, and no private right of action.

What is still owed

One thing, and it is triggered by facts the city has not yet stated publicly.

If the incident involved a breach of security affecting personal information, as G.L. c. 93H defines it, Everett must notify the Attorney General, the Office of Consumer Affairs and Business Regulation, and every affected resident, as soon as practicable and without unreasonable delay.

Personal information has a narrow statutory meaning: a resident’s name combined with a Social Security number, a driver’s license or state identification number, or a financial account or card number. A city network holds plenty of all three, in payroll, in tax and water billing, and in personnel files. Whether the intruder reached any of it is the question the forensic review answers, and it is the question that determines whether letters go out.

Two features of those letters surprise people. The notice to the Attorney General must state the nature of the breach, the number of residents affected, the type of information compromised and whether the city maintains a written information security program. The notice to the resident may not state the nature of the breach or the number of people affected. Residents are told less than regulators, by statutory design.

Where Social Security numbers were exposed, G.L. c. 93H, § 3A requires the city to provide credit monitoring at no cost for at least eighteen months, and forbids conditioning it on a waiver of the right to sue.

How to find out whether a notice was filed

Without waiting for a letter.

The Office of Consumer Affairs and Business Regulation maintains a public data breach notification database listing reported breaches. An entry for the City of Everett would be the first hard confirmation that the city concluded personal information was involved. No entry means either that no notice has been filed yet or that the city concluded none was required, and the two are not distinguishable from outside.

The other route is the public records law, G.L. c. 66, § 10. A resident may request the city’s contracts with forensic vendors, the total cost of the response to date, and the date of any notice filed with the Attorney General. Records that would compromise an active law enforcement investigation or jeopardize the security of an information system may be withheld, and the city will likely invoke both for the forensic report itself. The cost figure and the notice date are harder to refuse, and the cost figure is usually what eventually tells a community the size of what happened to it.

The question the reopening does not answer

Everett’s former information technology director, Kevin Dorgan, was arraigned on September 11 on a larceny charge involving city Amazon purchases, in the middle of the closure. We wrote about the coincidence and about why nothing on the public record connects the two in our explainer on the dead man’s switch theory. That remains true. Dorgan was fired in March, six months before the incident, the charge concerns purchases rather than access, and no official or outlet has linked them.

What the reopening does not tell us is what caused the outage. A city that restores its systems has solved an operational problem. It has not necessarily published a cause, and most municipalities never do.

The other two Massachusetts communities hit this month are at different stages. Springfield Public Schools reopened after a week and the FBI has confirmed that student and staff data was breached. Sutton announced its incident on September 16 and is still reviewing what data was affected.

What to watch

Whether an Everett entry appears in the state breach database. Whether the City Council asks for a public briefing, which is the ordinary route to a cause being described. Whether the city’s eventual budget documents show the cost. And whether Everett, like Springfield and Sutton, ends up saying more once the investigation closes than it could while it was open.

Common questions

When does Everett City Hall reopen?

Monday, after being closed to the public since September 8. Services had been available at the Connolly Center, 90 Chelsea Street.

Was resident data taken?

The city has not said. That determination comes from the forensic review and drives whether notices are legally required.

Does the city have to tell residents what happened?

No. A breach notice to a resident is legally forbidden from describing the nature of the breach or the number of people affected, although the notice to the Attorney General must include both.

How will I know if a notice was filed?

Check the Office of Consumer Affairs and Business Regulation’s public data breach notification database for an entry naming the City of Everett.

Is this connected to the former IT director’s case?

No official or news report has connected them. He was fired in March, six months before the incident, and the charge concerns purchases rather than computer access.

Reopening and closure details as reported by Boston 25 News, September 19, 2026, and from the City of Everett’s own notices. Mayor Van Campen’s remarks from the city’s September 14 notice. G.L. c. 93H, §§ 1, 3 and 3A and c. 66, § 10 read at malegislature.gov. Kevin Dorgan is presumed innocent of the larceny charge and has not been accused of any conduct relating to the network incident. General information about Massachusetts law, not legal advice.

About·Contact·Get the Weekly Digest·Opinion Archive·Privacy Policy·Terms of Use·Disclaimer
© 2026 Massachusetts Legal Resources
Massachusetts Legal Resources republishes public-domain opinions of the Massachusetts appellate courts together with original case summaries. Official versions are published in the Massachusetts Reports and Appeals Court Reports. Nothing on this site is legal advice, and reading it does not create an attorney-client relationship.