Skip to content

Kittson County cyber report limited DMV services

Summary

Kittson County reported a cyber incident involving its emergency-services network, prompting Minnesota IT Services to block the county’s access to state motor-vehicle systems as a precaution. Full DMV services were temporarily unavailable while limited tab payments and Department of Natural Resources transactions continued; emergency services remained operational, and ransomware, data theft and NightSpire attribution were unconfirmed.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Incident characteristics

Assessments

Incident confidence:
High
Ransomware:
Unresolved
Attribution:
Low

DD-CIT classification

OC-ODOfficial cyberOfficial disruptionAbout the DD-CIT methodology

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Third-party service disruption

    The incident materially affected services delivered by or through a vendor, managed service provider, contractor, partner, or other third party.

  • Application unavailable

    A specific application or software platform became unavailable or unusable.

  • Transaction processing disruption

    Business, financial, customer, administrative, or operational transactions could not be completed normally.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Records processing disruption

    The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

  • Staff unable to work normally

    Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

Extortion indicators

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

  • Unknown extortion indicators

    The incident may involve extortion, but available evidence does not establish which extortion indicators were present.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Kittson County experienced a cyber incident that triggered a precautionary state access block and disrupted local driver’s-license and motor-vehicle services. The county’s June 11 DMV closure update said it had reported a cyber incident involving its emergency-services network to Minnesota IT Services. MNIT then blocked the county’s access to state motor-vehicle systems as a precaution.

The public record does not establish that the county’s DMV network was compromised. County officials said the emergency-services network was separate from the DMV network and remained operational. The documented DMV disruption therefore resulted from a defensive access-control decision by the state following the reported cyber incident, rather than from a confirmed compromise of the DMV environment itself.

Operational significance

Kittson County first told residents on June 4 that its driver’s-license and motor-vehicle office was temporarily closed until further notice and advised people to call before visiting. The June 11 memo said full DMV services were unavailable because MNIT had blocked access to state systems. The disruption affected license services, vehicle registrations, title transfers and other state-connected transactions.

The office remained open for limited functions. It could accept payments for vehicle tabs to be mailed later and continue Department of Natural Resources license transactions. Those workarounds reduced the impact but did not restore normal service, and the county said there was no estimated timeline for full DMV access.

Disclosure posture

The county directly acknowledged a cyber incident involving its emergency-services network on June 11 and explained the resulting state access block. It did not identify the affected systems, incident start date, initial access vector, malware family, data impact, law-enforcement involvement or whether 911, dispatch or sheriff’s-office systems were targeted. The disclosure confirmed a cyber event and operational consequence but not its technical scope.

Current status

The last direct evidence of operational impact is the county’s June 11 memo. Searches through July 26 found no newer report showing that the DMV restrictions continued and no authoritative notice confirming restoration. With 45 days since the last observation, the incident is presumed resolved rather than active, but the final access-restoration date and investigative outcome remain unknown. The county’s current DMV page lists normal transaction types and office hours while still advising residents to call ahead for availability; because that page is undated, it does not establish a restoration date.

Confidence and uncertainty

Confidence is high that a cyber incident was reported and that Minnesota’s precautionary access block caused a material service disruption because the county described both facts publicly. Data availability was affected because authorized county staff could not access state motor-vehicle systems and records needed for normal transactions. Whether any county or state data was accessed, copied, altered or encrypted remains unknown.

Confidence is low that NightSpire was responsible. DysruptionHub’s published report described an obfuscated May 29 NightSpire listing that appeared consistent with Kittson County and included a countdown timer, but the county did not confirm the group, ransomware, data theft or a ransom demand. The listing remains an actor claim, not confirmed attribution, and does not establish that data was copied, encrypted or published.

Analytic gaps

The public record does not identify when the cyber incident began, how access was obtained, which emergency-services systems were involved, whether any county network was compromised, whether data was accessed or removed, or whether the county received an extortion demand. It also does not establish when full DMV services resumed, whether additional county functions were affected or whether MNIT completed a final security review.

Threat actor and claim

Listed as: Kittson County, MinnesotaSource: ransomware.livePublished: Discovered:

Claim details

An unconfirmed ransomware claim is associated with the incident. A NightSpire leak-site listing posted on 29 May 2026 displayed an obfuscated victim name (`K****** County, Mi**e**ta`) that appears consistent with Kittson County, Minnesota. The listing included a countdown timer before an apparent data-release deadline but did not initially publish any data. Kittson County has not publicly confirmed ransomware, data theft, a ransom demand or any connection to the NightSpire listing. Based on the available public evidence, there is low-to-medium confidence that the listing refers to Kittson County, but there is insufficient evidence to confirm the threat actor’s involvement or that the listing is related to the county’s reported cyber incident.

Screenshot documenting NightSpire claim

Organizations involved

Impacted locations

Sources

Kittson County DMV limited after cyber report
DysruptionHubBy DysruptionHub StaffPublished: Retrieved:
  • Type: News Report
  • Stance: Report
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

DysruptionHub reported that Kittson County disclosed a cyber incident involving its emergency-services network and that Minnesota IT Services blocked the county’s access to state motor-vehicle systems as a precaution. Full DMV services were unavailable, while emergency services remained operational and NightSpire’s apparent claim remained unverified.

Kittson County cyber incident and DMV service notice
Kittson CountyPublished: Retrieved:
  • Type: Official Statement
  • Stance: Confirm
  • Platform: Social Platform
  • Medium: Web Page
  • Confidence: High

County administrator Aimee Sugden said Kittson County reported a cyber incident involving its emergency-services network to Minnesota IT Services. MNIT then blocked county access to state motor-vehicle systems as a precaution, making full DMV services temporarily unavailable while emergency services remained operational.

Kittson County
Kittson CountyRetrieved:
  • Type: Public Record
  • Stance: Report
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

Kittson County’s official website identifies the county government and its driver’s-license, motor-vehicle, emergency-management and related public-service departments from the county courthouse in Hallock, Minnesota.

Update on Temporary DMV Closure, 6/11/26
Kittson CountyBy Aimee SugdenPublished: Retrieved:
  • Type: Official Statement
  • Stance: Confirm
  • Platform: Website
  • Medium: Web Page
  • Confidence: High

County Administrator Aimee Sugden said Kittson County reported a cyber incident involving its emergency-services network to Minnesota IT Services. MNIT blocked county access to state DMV services as a precaution, leaving full DMV services temporarily unavailable. The office could accept tab payments for later mailing and continue DNR transactions, while staff worked with state partners without an estimated full-restoration timeline.