Skip to content

Winona County January 2026 ransomware incident

Summary

Winona County logo

Winona County’s January 2026 ransomware attack disrupted phones, internal systems, records access and county services. Recorder’s-office recovery work continued March 12. The county later confirmed data theft affecting 6,196 people and a $128,539.57 ransom payment; officials said insurance covered about $50,000 and the county levy about $78,000.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

Data impacts

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Event or activity cancellation

    Scheduled events, meetings, hearings, classes, procedures, programs, or other activities were canceled.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

Extortion indicators

  • Ransom demand

    The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.

  • Payment reported

    A source reported that the victim, insurer, intermediary, or another party made a ransom or extortion payment.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Winona County experienced a ransomware incident involving network disruption, unauthorized access, data theft and extortion in January 2026. The county’s initial statement said it had identified ransomware affecting its computer network and was testing systems with cybersecurity, forensics and law-enforcement assistance. Its later data-security notice established that unauthorized access occurred from Jan. 18 through Jan. 22, when the county detected the ransomware, and that the intruders took data from the network.

News 8 Now reported Aug. 27 that county commissioners disclosed a $128,539.57 payment connected to the January attack. Commissioners said the county decided to negotiate and pay with help from its insurance carrier to help fully restore county services and protect personal information. The disclosure confirms a ransom demand and payment but does not establish the responsible actor or the payment’s terms.

Operational significance

The incident affected the administration of a county government serving residents across Winona County. We reported Jan. 23 that many county phone lines and some internal networks were unavailable, a sheriff’s office media briefing and at least one virtual meeting were canceled, and deputies could not use police-records software. Emergency services, including 911 and fire response, remained operational, limiting the documented public-safety impact.

The county declared a local emergency and implemented business-continuity measures. A Feb. 12 update reported by KTTC said some systems remained offline and county services could be delayed while restoration continued. March 12 Port Authority meeting minutes, included in the city’s April 9 agenda packet, record County Recorder Bob Bambenek saying his office was a couple of days from catching up after the January shutdown. That documents continuing recovery work on March 12, not an exact date of full restoration. The later payment disclosures do not establish continuing operational disruption.

Extortion and payment

The commissioners’ disclosure establishes that the county negotiated and made a ransom payment of $128,539.57. MPR News reported Sept. 6 that County Administrator Maureen Holte said insurance covered about $50,000 and the county levy covered about $78,000. The Winona Post reported Sept. 23 that Commissioner Marcia Ward also put the insurance contribution at $50,000. Those rounded figures do not establish an exact allocation of the $128,539.57 payment or identify the insurer, reimbursement timing or who transmitted it. The public record also does not identify the original demand amount, payment date, recipient, currency, transaction identifier, negotiation channel, decryption arrangement or other conditions.

The stated purposes were to help fully restore county services and protect personal information. Those purposes do not establish whether restoration depended on a decryptor, whether the agreement included a promise not to publish stolen data or whether the payment achieved either objective.

Retrospective note

The county later said it securely restored the network and completed its review of affected information on April 16. It began mailing notices May 12. MPR News reported Sept. 6 that Holte said all affected people had been notified and the criminal investigation into the January incident remained open. A Maine Attorney General filing reports that 6,196 people were affected and offered 12 months of IDX monitoring, identity-restoration assistance and insurance.

The county expressly distinguished this event from a separate April 2026 ransomware attack. The two incidents affected the same government less than three months apart, but the county’s preliminary investigation said different cybercriminals were responsible, and no later public evidence establishes a shared access path, actor or campaign.

Confidence and uncertainty

Confidence is high that malicious cyber activity caused the disruption because Winona County directly identified ransomware and later confirmed unauthorized access and data removal. Confidence is also high that 6,196 people were affected, based on the regulatory filing submitted by county counsel. News 8 Now’s account of the commissioners’ disclosure provides high-confidence evidence of the payment amount and the county’s stated rationale.

The affected information varied by person and included names, addresses, Social Security numbers, driver’s license or state identification numbers, medical information, law-enforcement-report information, financial account information and PMI numbers. For a smaller group, payment-card details or online account credentials were also affected. The public record does not establish whether all categories were taken from a single system or how broadly each category was exposed.

Analytic gaps

The reviewed public sources do not establish the initial access vector, exploited vulnerability, compromised account or host, dwell time before Jan. 18, malware family, encryption scope, lateral movement, persistence, threat actor, exfiltration method, original demand, payment timing or terms, or exact date on which every county system and service returned to normal. They also do not establish a technical or organizational connection between the January and April attacks beyond the shared victim.

Organizations involved

Impacted locations

Sources

Winona County, Minnesota, investigates ransomware incident on network

We reported that many county phone lines and some internal networks were unavailable. A sheriff’s office media briefing and at least one virtual meeting were canceled, and deputies could not use police-records software, while emergency services remained operational.

Winona County Responds to Ransomware Incident

Winona County said it had identified ransomware affecting its computer network, was testing systems with outside experts and law enforcement, and had implemented business-continuity measures. It said 911, fire and emergency response operations remained operational and that the board chair declared a local emergency.

Winona County gives update on ransomware incident affecting computer network

KTTC reported that some county systems remained offline and certain services could be delayed while officials worked to restore systems with cybersecurity, data-forensics and federal law-enforcement assistance. At that time, effects on residents’ personal information were still unknown.

Winona Port Authority April 9, 2026 agenda packet: March 12 meeting minutes

The March 12 minutes in the April 9 agenda packet record County Recorder Bob Bambenek saying the recorder’s office was a couple of days from catching up after the January county shutdown. This documents March 12 recovery work, not a confirmed future completion date.

Notice of Data Security Incident

The county said unauthorized access occurred Jan. 18-22, ransomware was detected Jan. 22 and intruders took data. It said the network was securely restored, the information review finished April 16 and notices began May 12. Affected data included government, financial, medical and identity information.

Winona County says it paid $128K after January ransomware attack

News 8 Now reported that Winona County commissioners disclosed a $128,539.57 payment connected to the January ransomware attack. Commissioners said the county decided to negotiate and pay with help from its insurance carrier to help fully restore county services and protect personal information.

Winona County attacked again in cyberattack after paying $128K ransom

County Administrator Maureen Holte said insurance covered about $50,000 of the January ransom and the county levy about $78,000. The January criminal investigation remained open and affected people had been notified.

Candidates for county board field questions

Commissioner Marcia Ward said insurance covered $50,000 of the January ransom. The candidates’ forum reporting does not establish a new operational outage or independently confirm technical claims.

Data Breach Notices: Winona County

The regulatory filing submitted by Winona County counsel reports that 6,196 people were affected by the Jan. 18-22, 2026 external system breach. Written notification began May 12, and affected people were offered 12 months of IDX credit and CyberScan monitoring, identity-restoration assistance and insurance.

See something that needs correction?

Signed-in members can report an error, update, or missing source.