The Department of Children and Families accidentally issued duplicate payments to 141 providers in July, resulting in an overpayment of more than $1.2 million, experienced a large data breach at the department exposing personal information and records of an estimated 15,000 individuals, as well as detailed report regarding an employee who worked a second job while collecting workman compensation benefits, according to a monthly loss report to state auditors.
According to the report, a manual attempt to correct business related data resulted in two payments being executed on July 7 and 9, resulting in $1.22 million being delivered to DCF providers on July 17. DCF officials were notified of the duplicate payment just four days later and began instituting measures to document the overpayments and recoup the funds.
“We have been reaching out to providers directly to notify them of the overpayment,” DCF wrote in its loss report to state auditors. “We are then requesting they provide us with a repayment by check or money order or if that is not feasible, we are recouping the overpaid amount through deductions from future monthly payments.”
“To date, $23,000 has been recouped from these efforts through checks remitted to the Department,” the report continued. “DCF has a project manager assigned to this effort to ensure we have a single point of contact tracking all of our recovery efforts.”
The duplicated payments were made through DCF’s new CT-KIND system, which the department announced in August 2025 on social media, stating that the updated system, “is easier for staff to navigate, allows for enhanced data to be collected and analyzed, and overall, will result in greater efficiencies as we conduct our work.”
DCF is also dealing with a data breach that is estimated to have affected “15,000 individuals,” including 75 whose social security numbers were “compromised.” The breach was the result of phishing email scams that gained access to two email accounts that contained “approximately 173,000 emails” that were “compromised as a result of the phishing incident.”
The breach was discovered two days after the phishing incidents on May 18, 2026, and the department learned one month later that “some of the emails that were compromised may have contained ‘personal information,’” or confidential records as defined in state statute. However, the department indicated it does not appear that any personal health information or HIPAA records were part of the data breach.
According to the statute cited in the report, “personal information” is defined as first name or initial and last name in combination with any variety of other information, including social security number, driver’s license number, taxpayer identification, and financial account number, along with numerous other identification numbers. “Records,” as cited, is defined as “information created or obtained in connection with the department’s child protection activities or other activities related to a child while in the care or custody of the department.”
DCF officials indicated they are working with the Department of Administrative Services (DAS) and the Office of the Attorney General to investigate the breach and comply with the required notification of those affected.
Lastly, DCF found that one of its employees was “receiving income while listed as temporarily totally disabled by worker’s comp, and conducting private therapy sessions with a DCF client.”
The discovery was the result of an investigation by the Office of Labor Relations into Janelle Myers that began in November 2025. According to the investigation, Myers, a social worker hired in 2012, claimed she was injured in January 2025 and placed on light duty, working in the office for 90 days. She was then listed as “totally disabled and received Worker’s Comp payments,” until she returned to the office in November, again with light duty restrictions.
When asked, Myers admitted that she worked a second counselling job while out on workers comp, seeing clients both in person and virtually, and claimed she did not know she needed to report this second job to DCF or workers comp, and that her second job was unaware of her worker’s comp benefits. During her time counseling, she also worked with a DCF client.
The labor investigation determined there was “just cause” for disciplinary action as Myers had engaged in “deliberate violation” of state law, regulation or agency rule; engaged in employment related misconduct, and engaged in an activity, “which is detrimental to the best interests of the agency.”
According to DCF’s letter, Myers received a “formal counseling memorandum” as her discipline. State open records show that Meyers, a social worker hired in 2012, remains employed and is projected to receive a salary of $104,045 this year.
The loss report comes following DCF’s last full state audit that found a 94 percent increase in the number of runaway children and an instance in which a foster parent was paid nearly $20,000 to watch their foster children under the auspices of “childcare.”
The Department, which was formally released from federal oversight in 2022, has also been criticized following several high-profile child deaths and abuse cases and is facing increased scrutiny by the legislature following reports issued by the Office of the Child Advocate. The Department recently updated its telework rules to ensure there is in-person supervision of trainees. Connecticut’s telework agreement with state employee unions allows employees to work from home four days per week, if not more.
While DCF is certainly not alone in experiencing a data breach, the number of individuals potentially affected is significant. Connecticut’s health insurance exchange experienced 51 data breaches affecting 161 individuals, according to an audit report. The Connecticut Port Authority in 2026 fell victim to a phishing scam and lost over $16,000.
The Department of Social Services in January 2026 reported the theft of over $400,000 by multiple individuals over two years after they somehow obtained banking information for a child support payment account. DSS had successfully recovered most of the funds, and the Connecticut State Police were charged with investigating.
In DCF’s letters to state auditors, they indicated they were “exploring” how to best notify so many individuals of the data breach and provide credit monitoring for those whose social security numbers were exposed.
For the $1.2 million duplicate payment, the department indicated it was “working to develop and enact a plan to ensure this human error will not be [sic] occur again moving forward.”


