Skip to content

Washburn County government cyberattack

Summary

Washburn County logo

Washburn County shut down county technology August 6 after detecting malicious cyber activity, disrupting phones and other internet-dependent services. Phones and email were restored by August 14, and every department was functional September 2, but some employees, printers and programs remained affected; the incident also prevented delivery of the weekly jail-booking report through September 1. Recovery remained active, while ransomware, data exposure and actor attribution were unresolved.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Complete service outage

    A primary service, system, platform, or operational capability became entirely unavailable.

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

  • Email disruption

    Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.

  • Records processing disruption

    The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

Washburn County’s Aug. 6 statement described malicious cyber activity and a county technology shutdown. In a later official update, County Board Chair Lolita Olson said the incident remained under investigation and officials were still determining the nature and scope of the activity. DysruptionHub assesses with high confidence that a cyber incident caused material disruption to county government technology and services.

A Sept. 2 county press release published by DrydenWire said every department was fully functional and phones and email were working. The county also said not every employee, printer or program had returned and that work continued to get county services back to normal. The two statements describe substantial recovery with residual operational impairment, not full restoration.

The public evidence does not establish the initial access vector, exploited vulnerability, compromised account, malware or other technical mechanism. It also does not show whether the operational shutdown resulted directly from attacker action, the county’s containment decision or both. No reviewed source identified a threat actor, confirmed ransomware or encryption, disclosed a ransom demand, or established that information was accessed or acquired.

Operational significance

The county shut down technology Aug. 6 so personnel and incident-response specialists could assess affected systems. Its statements said staff and the public could experience disruptions to services that depended on internet access or county phone lines. The Washburn County Clerk of Circuit Court’s operational notice documented that court phone lines were down while the office remained open and email remained available as an alternate channel.

The disruption also affected publication of county records. DrydenWire said Sept. 1 that it had not received the county’s weekly jail-booking report because the cyber incident continued to affect county technology systems. The publisher carried similar notices Aug. 18 and Aug. 25, showing that the records-publication interruption persisted across multiple weekly cycles.

County offices and courts remained open, and 911 remained operational. The county directed calls through 911 until phone service was restored, but the evidence does not show that 911 or dispatch became unavailable. By Sept. 2, every department was functional and county phones and email worked, although some employees, printers and programs remained affected.

Current status

The incident is presumed active. A Sept. 10 local report recounting the county’s Sept. 8 meeting said information technology staff were still addressing lower-priority restoration work by department. No newer operational-impact observation or final all-clear was found through Sept. 22; 14 days without a newer observation no longer supports active status, while the documented residual work does not support resolved.

Confidence and uncertainty

Confidence is high that the incident was cyber-related and operationally disruptive because the county explicitly confirmed both elements. Confidence is high that every department, phone service and email were operational by Sept. 2 because the county said so directly. Confidence is medium in the scope and severity of the remaining disruption because the county did not identify the affected employees, printers or programs or explain which resident services they supported.

The systems shutdown establishes a data-availability impact because authorized users lost normal access to county technology. The county’s statement that it would notify people if the investigation found personal information was affected is conditional; it does not establish either a confidentiality impact or the absence of one. Ransomware involvement and actor attribution remain unresolved, and no known extortion indicator is identified in the available evidence.

Analytic gaps

The public record does not establish when malicious access began, the initial access vector, compromised account or device, exploited vulnerability, malware family, affected-system inventory, encryption scope, dwell time, persistence method, exfiltration evidence, affected data categories, record count, ransom demand, payment activity, law-enforcement coordination or containment details. It also does not identify which employees, printers and programs remained affected Sept. 2, when weekly jail-booking reports will resume, or when every county service returned to normal.

Organizations involved

Impacted locations

Sources

Washburn County, Wisconsin, shuts down systems after cyberattack

Our reporting documented that Washburn County shut down county technology after announcing a cyberattack Aug. 6. It said 911 remained operational and court phone lines were down, while officials had not disclosed a restoration estimate, attack method, ransomware, data impact, ransom demand or threat actor.

Washburn County Clerk of Circuit Court service notice

The Washburn County Clerk of Circuit Court reported that court phone lines were down. The office remained open, and the clerk directed people to use email while telephone service was unavailable.

Washburn County government cyberattack alert

Washburn County announced Aug. 6 that malicious cyber activity led it to shut down all county systems while 911 remained operational. By Aug. 10, that alert was no longer displayed and the official site again presented normal public functions, but no incident-specific restoration date or technical all-clear.

Update on Cyber Incident

Washburn County said on August 14 that its email and phone systems had returned to operation while work continued to safely restore other programs and services. The county said the incident remained under investigation and that it was still determining the nature and scope of the activity.

Washburn County Weekly Jail Bookings Report - Sep. 1, 2026

DrydenWire said it did not receive Washburn County’s weekly jail-booking report for Sept. 1 because the ongoing cyber incident affected county technology systems. It said the county continued to investigate the incident and restore affected services and that publication would resume when the report became available.

Washburn County Continues Recovery Nearly One Month After Cyber Attack

DrydenWire reproduced a Washburn County press release signed by County Board Chair Lolita Olson saying every department was fully functional Sept. 2 and phones and email were working, but not every employee, printer or program had returned. The county said work continued to get services back to normal.

Investigation for county cyber attack still ongoing

The Spooner Advocate reported that, as of the county’s Sept. 8 meeting, IT staff were still addressing lower-priority restoration work by department.

Washburn County contact directory

As reviewed Aug. 31, the county contact directory displayed ordinary telephone and email contacts across departments and did not identify a continuing cyber-related communications workaround.

See something that needs correction?

Signed-in members can report an error, update, or missing source.