Washburn County

Washburn County shut down county technology August 6 after detecting malicious cyber activity, disrupting phones and other internet-dependent services. Phones and email were restored by August 14, and every department was functional September 2, but some employees, printers and programs remained affected; the incident also prevented delivery of the weekly jail-booking report through September 1. Recovery remained active, while ransomware, data exposure and actor attribution were unresolved.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
A primary service, system, platform, or operational capability became entirely unavailable.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.
The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.
Services continued but with longer processing, response, delivery, or completion times.
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
Washburn County’s Aug. 6 statement described malicious cyber activity and a county technology shutdown. In a later official update, County Board Chair Lolita Olson said the incident remained under investigation and officials were still determining the nature and scope of the activity. DysruptionHub assesses with high confidence that a cyber incident caused material disruption to county government technology and services.
A Sept. 2 county press release published by DrydenWire said every department was fully functional and phones and email were working. The county also said not every employee, printer or program had returned and that work continued to get county services back to normal. The two statements describe substantial recovery with residual operational impairment, not full restoration.
The public evidence does not establish the initial access vector, exploited vulnerability, compromised account, malware or other technical mechanism. It also does not show whether the operational shutdown resulted directly from attacker action, the county’s containment decision or both. No reviewed source identified a threat actor, confirmed ransomware or encryption, disclosed a ransom demand, or established that information was accessed or acquired.
The county shut down technology Aug. 6 so personnel and incident-response specialists could assess affected systems. Its statements said staff and the public could experience disruptions to services that depended on internet access or county phone lines. The Washburn County Clerk of Circuit Court’s operational notice documented that court phone lines were down while the office remained open and email remained available as an alternate channel.
The disruption also affected publication of county records. DrydenWire said Sept. 1 that it had not received the county’s weekly jail-booking report because the cyber incident continued to affect county technology systems. The publisher carried similar notices Aug. 18 and Aug. 25, showing that the records-publication interruption persisted across multiple weekly cycles.
County offices and courts remained open, and 911 remained operational. The county directed calls through 911 until phone service was restored, but the evidence does not show that 911 or dispatch became unavailable. By Sept. 2, every department was functional and county phones and email worked, although some employees, printers and programs remained affected.
The incident is presumed active. A Sept. 10 local report recounting the county’s Sept. 8 meeting said information technology staff were still addressing lower-priority restoration work by department. No newer operational-impact observation or final all-clear was found through Sept. 22; 14 days without a newer observation no longer supports active status, while the documented residual work does not support resolved.
Confidence is high that the incident was cyber-related and operationally disruptive because the county explicitly confirmed both elements. Confidence is high that every department, phone service and email were operational by Sept. 2 because the county said so directly. Confidence is medium in the scope and severity of the remaining disruption because the county did not identify the affected employees, printers or programs or explain which resident services they supported.
The systems shutdown establishes a data-availability impact because authorized users lost normal access to county technology. The county’s statement that it would notify people if the investigation found personal information was affected is conditional; it does not establish either a confidentiality impact or the absence of one. Ransomware involvement and actor attribution remain unresolved, and no known extortion indicator is identified in the available evidence.
The public record does not establish when malicious access began, the initial access vector, compromised account or device, exploited vulnerability, malware family, affected-system inventory, encryption scope, dwell time, persistence method, exfiltration evidence, affected data categories, record count, ransom demand, payment activity, law-enforcement coordination or containment details. It also does not identify which employees, printers and programs remained affected Sept. 2, when weekly jail-booking reports will resume, or when every county service returned to normal.

The victim is the county government and the announced systems shutdown applied to the county jurisdiction.
Our reporting documented that Washburn County shut down county technology after announcing a cyberattack Aug. 6. It said 911 remained operational and court phone lines were down, while officials had not disclosed a restoration estimate, attack method, ransomware, data impact, ransom demand or threat actor.
The Washburn County Clerk of Circuit Court reported that court phone lines were down. The office remained open, and the clerk directed people to use email while telephone service was unavailable.
Washburn County announced Aug. 6 that malicious cyber activity led it to shut down all county systems while 911 remained operational. By Aug. 10, that alert was no longer displayed and the official site again presented normal public functions, but no incident-specific restoration date or technical all-clear.
Washburn County said on August 14 that its email and phone systems had returned to operation while work continued to safely restore other programs and services. The county said the incident remained under investigation and that it was still determining the nature and scope of the activity.
DrydenWire said it did not receive Washburn County’s weekly jail-booking report for Sept. 1 because the ongoing cyber incident affected county technology systems. It said the county continued to investigate the incident and restore affected services and that publication would resume when the report became available.
DrydenWire reproduced a Washburn County press release signed by County Board Chair Lolita Olson saying every department was fully functional Sept. 2 and phones and email were working, but not every employee, printer or program had returned. The county said work continued to get services back to normal.
The Spooner Advocate reported that, as of the county’s Sept. 8 meeting, IT staff were still addressing lower-priority restoration work by department.
As reviewed Aug. 31, the county contact directory displayed ordinary telephone and email contacts across departments and did not identify a continuing cyber-related communications workaround.
Signed-in members can report an error, update, or missing source.