Skip to content

Iowa County ransomware attack

Summary

Iowa County logo

A ransomware attack detected April 28, 2025, deleted a significant portion of Iowa County, Wisconsin’s network, disrupting land records, deed processing, tax operations and other county services. The county later said an unauthorized party accessed or acquired limited personal information, and it rebuilt the searchable land-record index by Aug. 20, 2026. No attacker has been publicly identified, and the county said it did not pay a ransom.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

Data impacts

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

  • Data deletion or destruction

    Data was intentionally deleted, wiped, destroyed, or made permanently unrecoverable.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

  • Backup compromise

    Backup data or backup systems were accessed, encrypted, deleted, altered, disabled, or otherwise compromised.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Online portal unavailable

    A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Payment processing disruption

    The organization could not process, receive, issue, reconcile, or record payments normally.

  • Transaction processing disruption

    Business, financial, customer, administrative, or operational transactions could not be completed normally.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Records processing disruption

    The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

Extortion indicators

  • Payment denied

    An authoritative source stated that no ransom or extortion payment was made.

Incident narrative

Analyst assessment

Iowa County, Wisconsin, detected unauthorized activity in its computer network on April 28, 2025, and later confirmed that the incident was ransomware. The county said the attacker intentionally deleted a significant portion of its network, including backups for some systems, leaving some data unrecoverable and requiring a lengthy reconstruction effort.

DysruptionHub assesses with high confidence that ransomware caused a material county-government disruption. The county’s own updates establish unauthorized access, destructive activity, backup compromise and service effects. The public record does not identify the attacker, and mandatory searches found no stable public victim claim that would support attribution to Qilin or another named group.

Operational significance

The attack disrupted real estate transactions, land-record searches, deed services, tax-office operations and public access to records. County staff used phased restoration, vendor assistance, public-access computers, manual receipts and alternative payment arrangements while rebuilding affected systems. Phone and email remained operational, vital-record services were functional by May 2, 2025, document recording resumed May 14, and online tax payment later returned.

The land-record impact persisted far beyond the initial outage. Iowa County restored searchable years in stages through 2026 and announced a complete searchable grantor/grantee index from 1835 to the present on Aug. 20, 2026. The prolonged loss of normal search and retrieval capability affected residents, lenders, title companies, businesses and professionals handling property transactions.

Disclosure posture

Our May 1 report documented the county’s initial response and warning that nonemergency services could be delayed while emergency functions remained available. The county subsequently confirmed ransomware, described deleted network data and backups, and on Aug. 8, 2025, said an unauthorized party accessed or acquired a limited amount of personal information. The affected information could include names, birthdates, addresses, government identifiers, financial details and limited medical information.

Current status

The county’s Aug. 20, 2026, index-rebuild notice is the strongest public restoration signal. Because the county has not issued a broader final all-clear for every affected system, the incident is assessed as presumed resolved rather than resolved. A Sept. 17, 2026, report described continuing financial uncertainty related to recovery but did not identify a county service that remained unavailable; the county administrator said no ransom was paid.

Confidence and uncertainty

Confidence is high that the ransomware attack occurred and materially disrupted county operations because Iowa County directly confirmed the attack, documented the deleted network and backups, and maintained detailed restoration updates. Confidence is also high that some personal information was accessed or acquired because the county issued notices after completing its investigation and data review.

Threat-actor attribution remains unresolved. The existing public evidence does not identify a ransomware group, and searches of the county name and its current and legacy domains found no stable actor claim. Ransomware confirmation does not by itself establish the strain, affiliate, initial access method, encryption scope or extortion process.

Analytic gaps

The public record does not establish the initial access vector, exploited vulnerability, ransomware family or variant, whether or how broadly systems were encrypted, whether the county received a ransom demand, the amount of any demand, the total number of affected individuals, or the exact number of records accessed or acquired. It also does not provide a countywide final technical report or all-clear covering every affected system.

Organizations involved

Impacted locations

  • Dodgeville, Wisconsin

    Dodgeville is the county seat and physical administrative anchor for Iowa County government. This relationship does not assert a documented outage at every facility or for every resident in Dodgeville.

  • Iowa County, Wisconsin

    Iowa County is the affected county government’s service area. The overlay models the victim’s physical remit and does not imply that every county service or resident experienced a documented outage.

Sources

Iowa County Cyber Incident

The county confirmed ransomware, destructive network and backup deletion, prolonged service disruption, personal-data impact and phased restoration.

Amid Cyber Attack Recovery, Iowa County, Wis., Eyes a Budget

The county administrator said Iowa County did not pay a ransom and declined to characterize the attack’s outstanding effects.

About Iowa County

The county identifies itself as a southwestern Wisconsin county with Dodgeville as its seat and its principal offices at 222 N. Iowa St.

See something that needs correction?

Signed-in members can report an error, update, or missing source.