Winona County

Winona County’s January 2026 ransomware attack disrupted phones, internal systems, records access and county services. Recorder’s-office recovery work continued March 12. The county later confirmed data theft affecting 6,196 people and a $128,539.57 ransom payment; officials said insurance covered about $50,000 and the county levy about $78,000.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
Unauthorized access to systems, accounts, networks, or data.
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
Internal or external network connectivity was unavailable or materially impaired.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
Scheduled events, meetings, hearings, classes, procedures, programs, or other activities were canceled.
Services continued but with longer processing, response, delivery, or completion times.
The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.
A source reported that the victim, insurer, intermediary, or another party made a ransom or extortion payment.
DysruptionHub assesses with high confidence that Winona County experienced a ransomware incident involving network disruption, unauthorized access, data theft and extortion in January 2026. The county’s initial statement said it had identified ransomware affecting its computer network and was testing systems with cybersecurity, forensics and law-enforcement assistance. Its later data-security notice established that unauthorized access occurred from Jan. 18 through Jan. 22, when the county detected the ransomware, and that the intruders took data from the network.
News 8 Now reported Aug. 27 that county commissioners disclosed a $128,539.57 payment connected to the January attack. Commissioners said the county decided to negotiate and pay with help from its insurance carrier to help fully restore county services and protect personal information. The disclosure confirms a ransom demand and payment but does not establish the responsible actor or the payment’s terms.
The incident affected the administration of a county government serving residents across Winona County. We reported Jan. 23 that many county phone lines and some internal networks were unavailable, a sheriff’s office media briefing and at least one virtual meeting were canceled, and deputies could not use police-records software. Emergency services, including 911 and fire response, remained operational, limiting the documented public-safety impact.
The county declared a local emergency and implemented business-continuity measures. A Feb. 12 update reported by KTTC said some systems remained offline and county services could be delayed while restoration continued. March 12 Port Authority meeting minutes, included in the city’s April 9 agenda packet, record County Recorder Bob Bambenek saying his office was a couple of days from catching up after the January shutdown. That documents continuing recovery work on March 12, not an exact date of full restoration. The later payment disclosures do not establish continuing operational disruption.
The commissioners’ disclosure establishes that the county negotiated and made a ransom payment of $128,539.57. MPR News reported Sept. 6 that County Administrator Maureen Holte said insurance covered about $50,000 and the county levy covered about $78,000. The Winona Post reported Sept. 23 that Commissioner Marcia Ward also put the insurance contribution at $50,000. Those rounded figures do not establish an exact allocation of the $128,539.57 payment or identify the insurer, reimbursement timing or who transmitted it. The public record also does not identify the original demand amount, payment date, recipient, currency, transaction identifier, negotiation channel, decryption arrangement or other conditions.
The stated purposes were to help fully restore county services and protect personal information. Those purposes do not establish whether restoration depended on a decryptor, whether the agreement included a promise not to publish stolen data or whether the payment achieved either objective.
The county later said it securely restored the network and completed its review of affected information on April 16. It began mailing notices May 12. MPR News reported Sept. 6 that Holte said all affected people had been notified and the criminal investigation into the January incident remained open. A Maine Attorney General filing reports that 6,196 people were affected and offered 12 months of IDX monitoring, identity-restoration assistance and insurance.
The county expressly distinguished this event from a separate April 2026 ransomware attack. The two incidents affected the same government less than three months apart, but the county’s preliminary investigation said different cybercriminals were responsible, and no later public evidence establishes a shared access path, actor or campaign.
Confidence is high that malicious cyber activity caused the disruption because Winona County directly identified ransomware and later confirmed unauthorized access and data removal. Confidence is also high that 6,196 people were affected, based on the regulatory filing submitted by county counsel. News 8 Now’s account of the commissioners’ disclosure provides high-confidence evidence of the payment amount and the county’s stated rationale.
The affected information varied by person and included names, addresses, Social Security numbers, driver’s license or state identification numbers, medical information, law-enforcement-report information, financial account information and PMI numbers. For a smaller group, payment-card details or online account credentials were also affected. The public record does not establish whether all categories were taken from a single system or how broadly each category was exposed.
The reviewed public sources do not establish the initial access vector, exploited vulnerability, compromised account or host, dwell time before Jan. 18, malware family, encryption scope, lateral movement, persistence, threat actor, exfiltration method, original demand, payment timing or terms, or exact date on which every county system and service returned to normal. They also do not establish a technical or organizational connection between the January and April attacks beyond the shared victim.

We reported that many county phone lines and some internal networks were unavailable. A sheriff’s office media briefing and at least one virtual meeting were canceled, and deputies could not use police-records software, while emergency services remained operational.
Winona County said it had identified ransomware affecting its computer network, was testing systems with outside experts and law enforcement, and had implemented business-continuity measures. It said 911, fire and emergency response operations remained operational and that the board chair declared a local emergency.
KTTC reported that some county systems remained offline and certain services could be delayed while officials worked to restore systems with cybersecurity, data-forensics and federal law-enforcement assistance. At that time, effects on residents’ personal information were still unknown.
The March 12 minutes in the April 9 agenda packet record County Recorder Bob Bambenek saying the recorder’s office was a couple of days from catching up after the January county shutdown. This documents March 12 recovery work, not a confirmed future completion date.
The county said unauthorized access occurred Jan. 18-22, ransomware was detected Jan. 22 and intruders took data. It said the network was securely restored, the information review finished April 16 and notices began May 12. Affected data included government, financial, medical and identity information.
News 8 Now reported that Winona County commissioners disclosed a $128,539.57 payment connected to the January ransomware attack. Commissioners said the county decided to negotiate and pay with help from its insurance carrier to help fully restore county services and protect personal information.
County Administrator Maureen Holte said insurance covered about $50,000 of the January ransom and the county levy about $78,000. The January criminal investigation remained open and affected people had been notified.
Commissioner Marcia Ward said insurance covered $50,000 of the January ransom. The candidates’ forum reporting does not establish a new operational outage or independently confirm technical claims.
The regulatory filing submitted by Winona County counsel reports that 6,196 people were affected by the Jan. 18-22, 2026 external system breach. Written notification began May 12, and affected people were offered 12 months of IDX credit and CyberScan monitoring, identity-restoration assistance and insurance.
Signed-in members can report an error, update, or missing source.