Skip to content

Winona County January 2026 ransomware incident

Summary

Winona County logo

Winona County detected ransomware on January 22, 2026, after unauthorized network access that began January 18, disrupting phone lines, internal systems, records access and other county services. The county later confirmed data theft, reported 6,196 affected people to regulators, securely restored the network and began notifications with 12 months of identity-protection services in May.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

Data impacts

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Event or activity cancellation

    Scheduled events, meetings, hearings, classes, procedures, programs, or other activities were canceled.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

Extortion indicators

  • Unknown extortion indicators

    The incident may involve extortion, but available evidence does not establish which extortion indicators were present.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Winona County experienced a ransomware incident involving network disruption, unauthorized access and data theft in January 2026. The county’s initial statement said it had identified ransomware affecting its computer network and was testing systems with cybersecurity, forensics and law-enforcement assistance. Its later data-security notice established that unauthorized access occurred from Jan. 18 through Jan. 22, when the county detected the ransomware, and that the intruders took data from the network.

Ransomware involvement and data theft are confirmed by the affected organization rather than inferred from the outage pattern. Our reporting and the county’s disclosures provide the evidence base; this record’s assessment is a separate CTI judgment. The public record does not identify the ransomware family, initial access vector, threat actor, ransom demand, payment status or the method used to remove data.

Operational significance

The incident affected the administration of a county government serving residents across Winona County. DysruptionHub’s Jan. 23 report said many county phone lines and some internal networks were unavailable, a sheriff’s office media briefing and at least one virtual meeting were canceled, and deputies could not use police-records software. Emergency services, including 911 and fire response, remained operational, limiting the documented public-safety impact.

The county declared a local emergency and implemented business-continuity measures. A Feb. 12 update reported by KTTC said some systems remained offline and county services could be delayed while restoration continued.

Retrospective note

The county later said it securely restored the network and completed its review of affected information on April 16. It began mailing notices May 12. A Maine Attorney General filing reports that 6,196 people were affected and offered 12 months of IDX monitoring, identity-restoration assistance and insurance.

The county expressly distinguished this event from a separate April 2026 ransomware attack. The two incidents affected the same government less than three months apart, but the county’s preliminary investigation said different cybercriminals were responsible, and no later public evidence establishes a shared access path, actor or campaign.

Confidence and uncertainty

Confidence is high that malicious cyber activity caused the disruption because Winona County directly identified ransomware and later confirmed unauthorized access and data removal. Confidence is also high that 6,196 people were affected, based on the regulatory filing submitted by county counsel.

The affected information varied by person and included names, addresses, Social Security numbers, driver’s license or state identification numbers, medical information, law-enforcement-report information, financial account information and PMI numbers. For a smaller group, payment-card details or online account credentials were also affected. The public record does not establish whether all categories were taken from a single system or how broadly each category was exposed.

Analytic gaps

The reviewed public sources do not establish the initial access vector, exploited vulnerability, compromised account or host, dwell time before Jan. 18, malware family, encryption scope, lateral movement, persistence, ransom demand, payment, threat actor, exfiltration method or exact date on which every county system and service returned to normal. They also do not establish a technical or organizational connection between the January and April attacks beyond the shared victim.

Organizations involved

Impacted locations

Sources

Winona County, Minnesota, investigates ransomware incident on network

DysruptionHub reported that many county phone lines and some internal networks were unavailable. It also reported a canceled sheriff’s briefing, a canceled virtual meeting and unavailable police-records software, while emergency services remained operational.

Winona County Responds to Ransomware Incident

Winona County said it had identified ransomware affecting its computer network, was testing systems with outside experts and law enforcement, and had implemented business-continuity measures. It said 911, fire and emergency response operations remained operational and that the board chair declared a local emergency.

Winona County gives update on ransomware incident affecting computer network

KTTC reported that some county systems remained offline and certain services could be delayed while officials worked to restore systems with cybersecurity, data-forensics and federal law-enforcement assistance. At that time, effects on residents’ personal information were still unknown.

Notice of Data Security Incident

The county said unauthorized access occurred Jan. 18-22, ransomware was detected Jan. 22 and intruders took data. It said the network was securely restored, the information review finished April 16 and notices began May 12. Affected data included government, financial, medical and identity information.

Data Breach Notices: Winona County

The regulatory filing submitted by Winona County counsel reports that 6,196 people were affected by the Jan. 18-22, 2026 external system breach. Written notification began May 12, and affected people were offered 12 months of IDX credit and CyberScan monitoring, identity-restoration assistance and insurance.

See something that needs correction?

Signed-in members can report an error, update, or missing source.