Iowa County

A ransomware attack detected April 28, 2025, deleted a significant portion of Iowa County, Wisconsin’s network, disrupting land records, deed processing, tax operations and other county services. The county later said an unauthorized party accessed or acquired limited personal information, and it rebuilt the searchable land-record index by Aug. 20, 2026. No attacker has been publicly identified, and the county said it did not pay a ransom.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
Unauthorized access to systems, accounts, networks, or data.
An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
Data was intentionally deleted, wiped, destroyed, or made permanently unrecoverable.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
Backup data or backup systems were accessed, encrypted, deleted, altered, disabled, or otherwise compromised.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
Internal or external network connectivity was unavailable or materially impaired.
A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
The organization could not process, receive, issue, reconcile, or record payments normally.
Business, financial, customer, administrative, or operational transactions could not be completed normally.
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
Services continued but with longer processing, response, delivery, or completion times.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
An authoritative source stated that no ransom or extortion payment was made.
Iowa County, Wisconsin, detected unauthorized activity in its computer network on April 28, 2025, and later confirmed that the incident was ransomware. The county said the attacker intentionally deleted a significant portion of its network, including backups for some systems, leaving some data unrecoverable and requiring a lengthy reconstruction effort.
DysruptionHub assesses with high confidence that ransomware caused a material county-government disruption. The county’s own updates establish unauthorized access, destructive activity, backup compromise and service effects. The public record does not identify the attacker, and mandatory searches found no stable public victim claim that would support attribution to Qilin or another named group.
The attack disrupted real estate transactions, land-record searches, deed services, tax-office operations and public access to records. County staff used phased restoration, vendor assistance, public-access computers, manual receipts and alternative payment arrangements while rebuilding affected systems. Phone and email remained operational, vital-record services were functional by May 2, 2025, document recording resumed May 14, and online tax payment later returned.
The land-record impact persisted far beyond the initial outage. Iowa County restored searchable years in stages through 2026 and announced a complete searchable grantor/grantee index from 1835 to the present on Aug. 20, 2026. The prolonged loss of normal search and retrieval capability affected residents, lenders, title companies, businesses and professionals handling property transactions.
Our May 1 report documented the county’s initial response and warning that nonemergency services could be delayed while emergency functions remained available. The county subsequently confirmed ransomware, described deleted network data and backups, and on Aug. 8, 2025, said an unauthorized party accessed or acquired a limited amount of personal information. The affected information could include names, birthdates, addresses, government identifiers, financial details and limited medical information.
The county’s Aug. 20, 2026, index-rebuild notice is the strongest public restoration signal. Because the county has not issued a broader final all-clear for every affected system, the incident is assessed as presumed resolved rather than resolved. A Sept. 17, 2026, report described continuing financial uncertainty related to recovery but did not identify a county service that remained unavailable; the county administrator said no ransom was paid.
Confidence is high that the ransomware attack occurred and materially disrupted county operations because Iowa County directly confirmed the attack, documented the deleted network and backups, and maintained detailed restoration updates. Confidence is also high that some personal information was accessed or acquired because the county issued notices after completing its investigation and data review.
Threat-actor attribution remains unresolved. The existing public evidence does not identify a ransomware group, and searches of the county name and its current and legacy domains found no stable actor claim. Ransomware confirmation does not by itself establish the strain, affiliate, initial access method, encryption scope or extortion process.
The public record does not establish the initial access vector, exploited vulnerability, ransomware family or variant, whether or how broadly systems were encrypted, whether the county received a ransom demand, the amount of any demand, the total number of affected individuals, or the exact number of records accessed or acquired. It also does not provide a countywide final technical report or all-clear covering every affected system.

Dodgeville is the county seat and physical administrative anchor for Iowa County government. This relationship does not assert a documented outage at every facility or for every resident in Dodgeville.
Iowa County is the affected county government’s service area. The overlay models the victim’s physical remit and does not imply that every county service or resident experienced a documented outage.
We reported that Iowa County detected suspicious network activity and took systems offline while warning of possible nonemergency-service delays.
The county confirmed ransomware, destructive network and backup deletion, prolonged service disruption, personal-data impact and phased restoration.
The county administrator said Iowa County did not pay a ransom and declined to characterize the attack’s outstanding effects.
The county identifies itself as a southwestern Wisconsin county with Dodgeville as its seat and its principal offices at 222 N. Iowa St.
Signed-in members can report an error, update, or missing source.