Winona County Pays $128K Ransom After Two Cyberattacks

Winona County Pays $128K Ransom After Two Cyberattacks

First seen 31 Aug 2026, 19:59 UTC KttcKimt 52.5

Article Content

Browse articles
ThreatCluster

Winona County, Minnesota, confirmed that it paid a ransom of $128,539.57 following a ransomware attack that began on January 22, 2026. The initial attack disrupted several county computer networks and delayed municipal services. A second, unrelated ransomware incident occurred on April 7, 2026, further impairing the county's ability to deliver essential services. The county is currently reviewing the data compromised in the April attack and plans to notify affected individuals. They will also offer credit monitoring services for those whose sensitive information was accessed. County officials are implementing upgrades to their digital infrastructure to enhance security. The decision to pay the ransom was made in consultation with their insurance carrier to protect residents' data and services.

Key Points: • Winona County paid $128,539.57 to recover from a ransomware attack in January 2026. • A second ransomware incident occurred in April 2026, unrelated to the first attack. • The county is offering credit monitoring to individuals affected by the April breach.

Timeline

2026-01-22
First ransomware attack detected
Winona County's network was compromised, causing service delays. The attack prompted a ransom negotiation.
Kttc
2026-04-07
Second ransomware attack detected
A separate ransomware strain affected the county's network, severely disrupting emergency services.
Kttc
2026-05-12
Notification of data breach
Impacted individuals were informed about the January attack after a thorough data review.
Kttc