Winona County

Winona County detected ransomware on January 22, 2026, after unauthorized network access began January 18, disrupting phone lines, internal systems, records access and other county services. Some systems remained offline on February 12. The county later confirmed data theft affecting 6,196 people and disclosed a negotiated $128,539.57 payment, made with assistance from its insurer to restore services and protect personal information.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
Unauthorized access to systems, accounts, networks, or data.
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
Internal or external network connectivity was unavailable or materially impaired.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
Scheduled events, meetings, hearings, classes, procedures, programs, or other activities were canceled.
Services continued but with longer processing, response, delivery, or completion times.
The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.
A source reported that the victim, insurer, intermediary, or another party made a ransom or extortion payment.
DysruptionHub assesses with high confidence that Winona County experienced a ransomware incident involving network disruption, unauthorized access, data theft and extortion in January 2026. The county’s initial statement said it had identified ransomware affecting its computer network and was testing systems with cybersecurity, forensics and law-enforcement assistance. Its later data-security notice established that unauthorized access occurred from Jan. 18 through Jan. 22, when the county detected the ransomware, and that the intruders took data from the network.
News 8 Now reported Aug. 27 that county commissioners disclosed a $128,539.57 payment connected to the January attack. Commissioners said the county decided to negotiate and pay with help from its insurance carrier to help fully restore county services and protect personal information. The disclosure confirms a ransom demand and payment but does not establish the responsible actor or the payment’s terms.
The incident affected the administration of a county government serving residents across Winona County. We reported Jan. 23 that many county phone lines and some internal networks were unavailable, a sheriff’s office media briefing and at least one virtual meeting were canceled, and deputies could not use police-records software. Emergency services, including 911 and fire response, remained operational, limiting the documented public-safety impact.
The county declared a local emergency and implemented business-continuity measures. A Feb. 12 update reported by KTTC said some systems remained offline and county services could be delayed while restoration continued. No later source reviewed documents continuing operational disruption, and the Aug. 27 payment disclosure does not advance the last-impact date.
The commissioners’ disclosure establishes that the county negotiated and made a ransom payment of $128,539.57. It says the county acted with help from its insurance carrier, but it does not establish whether the insurer funded, reimbursed or transmitted any portion of the payment. The public record also does not identify the original demand amount, payment date, recipient, currency, transaction identifier, negotiation channel, decryption arrangement or other conditions.
The stated purposes were to help fully restore county services and protect personal information. Those purposes do not establish whether restoration depended on a decryptor, whether the agreement included a promise not to publish stolen data or whether the payment achieved either objective.
The county later said it securely restored the network and completed its review of affected information on April 16. It began mailing notices May 12. A Maine Attorney General filing reports that 6,196 people were affected and offered 12 months of IDX monitoring, identity-restoration assistance and insurance.
The county expressly distinguished this event from a separate April 2026 ransomware attack. The two incidents affected the same government less than three months apart, but the county’s preliminary investigation said different cybercriminals were responsible, and no later public evidence establishes a shared access path, actor or campaign.
Confidence is high that malicious cyber activity caused the disruption because Winona County directly identified ransomware and later confirmed unauthorized access and data removal. Confidence is also high that 6,196 people were affected, based on the regulatory filing submitted by county counsel. News 8 Now’s account of the commissioners’ disclosure provides high-confidence evidence of the payment amount and the county’s stated rationale.
The affected information varied by person and included names, addresses, Social Security numbers, driver’s license or state identification numbers, medical information, law-enforcement-report information, financial account information and PMI numbers. For a smaller group, payment-card details or online account credentials were also affected. The public record does not establish whether all categories were taken from a single system or how broadly each category was exposed.
The reviewed public sources do not establish the initial access vector, exploited vulnerability, compromised account or host, dwell time before Jan. 18, malware family, encryption scope, lateral movement, persistence, threat actor, exfiltration method, original demand, payment timing or terms, or exact date on which every county system and service returned to normal. They also do not establish a technical or organizational connection between the January and April attacks beyond the shared victim.

We reported that many county phone lines and some internal networks were unavailable. A sheriff’s office media briefing and at least one virtual meeting were canceled, and deputies could not use police-records software, while emergency services remained operational.
Winona County said it had identified ransomware affecting its computer network, was testing systems with outside experts and law enforcement, and had implemented business-continuity measures. It said 911, fire and emergency response operations remained operational and that the board chair declared a local emergency.
KTTC reported that some county systems remained offline and certain services could be delayed while officials worked to restore systems with cybersecurity, data-forensics and federal law-enforcement assistance. At that time, effects on residents’ personal information were still unknown.
The county said unauthorized access occurred Jan. 18-22, ransomware was detected Jan. 22 and intruders took data. It said the network was securely restored, the information review finished April 16 and notices began May 12. Affected data included government, financial, medical and identity information.
News 8 Now reported that Winona County commissioners disclosed a $128,539.57 payment connected to the January ransomware attack. Commissioners said the county decided to negotiate and pay with help from its insurance carrier to help fully restore county services and protect personal information.
The regulatory filing submitted by Winona County counsel reports that 6,196 people were affected by the Jan. 18-22, 2026 external system breach. Written notification began May 12, and affected people were offered 12 months of IDX credit and CyberScan monitoring, identity-restoration assistance and insurance.
Signed-in members can report an error, update, or missing source.