Winona County

Winona County detected ransomware on January 22, 2026, after unauthorized network access that began January 18, disrupting phone lines, internal systems, records access and other county services. The county later confirmed data theft, reported 6,196 affected people to regulators, securely restored the network and began notifications with 12 months of identity-protection services in May.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
Unauthorized access to systems, accounts, networks, or data.
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
Internal or external network connectivity was unavailable or materially impaired.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
Scheduled events, meetings, hearings, classes, procedures, programs, or other activities were canceled.
Services continued but with longer processing, response, delivery, or completion times.
The incident may involve extortion, but available evidence does not establish which extortion indicators were present.
DysruptionHub assesses with high confidence that Winona County experienced a ransomware incident involving network disruption, unauthorized access and data theft in January 2026. The county’s initial statement said it had identified ransomware affecting its computer network and was testing systems with cybersecurity, forensics and law-enforcement assistance. Its later data-security notice established that unauthorized access occurred from Jan. 18 through Jan. 22, when the county detected the ransomware, and that the intruders took data from the network.
Ransomware involvement and data theft are confirmed by the affected organization rather than inferred from the outage pattern. Our reporting and the county’s disclosures provide the evidence base; this record’s assessment is a separate CTI judgment. The public record does not identify the ransomware family, initial access vector, threat actor, ransom demand, payment status or the method used to remove data.
The incident affected the administration of a county government serving residents across Winona County. DysruptionHub’s Jan. 23 report said many county phone lines and some internal networks were unavailable, a sheriff’s office media briefing and at least one virtual meeting were canceled, and deputies could not use police-records software. Emergency services, including 911 and fire response, remained operational, limiting the documented public-safety impact.
The county declared a local emergency and implemented business-continuity measures. A Feb. 12 update reported by KTTC said some systems remained offline and county services could be delayed while restoration continued.
The county later said it securely restored the network and completed its review of affected information on April 16. It began mailing notices May 12. A Maine Attorney General filing reports that 6,196 people were affected and offered 12 months of IDX monitoring, identity-restoration assistance and insurance.
The county expressly distinguished this event from a separate April 2026 ransomware attack. The two incidents affected the same government less than three months apart, but the county’s preliminary investigation said different cybercriminals were responsible, and no later public evidence establishes a shared access path, actor or campaign.
Confidence is high that malicious cyber activity caused the disruption because Winona County directly identified ransomware and later confirmed unauthorized access and data removal. Confidence is also high that 6,196 people were affected, based on the regulatory filing submitted by county counsel.
The affected information varied by person and included names, addresses, Social Security numbers, driver’s license or state identification numbers, medical information, law-enforcement-report information, financial account information and PMI numbers. For a smaller group, payment-card details or online account credentials were also affected. The public record does not establish whether all categories were taken from a single system or how broadly each category was exposed.
The reviewed public sources do not establish the initial access vector, exploited vulnerability, compromised account or host, dwell time before Jan. 18, malware family, encryption scope, lateral movement, persistence, ransom demand, payment, threat actor, exfiltration method or exact date on which every county system and service returned to normal. They also do not establish a technical or organizational connection between the January and April attacks beyond the shared victim.

DysruptionHub reported that many county phone lines and some internal networks were unavailable. It also reported a canceled sheriff’s briefing, a canceled virtual meeting and unavailable police-records software, while emergency services remained operational.
Winona County said it had identified ransomware affecting its computer network, was testing systems with outside experts and law enforcement, and had implemented business-continuity measures. It said 911, fire and emergency response operations remained operational and that the board chair declared a local emergency.
KTTC reported that some county systems remained offline and certain services could be delayed while officials worked to restore systems with cybersecurity, data-forensics and federal law-enforcement assistance. At that time, effects on residents’ personal information were still unknown.
The county said unauthorized access occurred Jan. 18-22, ransomware was detected Jan. 22 and intruders took data. It said the network was securely restored, the information review finished April 16 and notices began May 12. Affected data included government, financial, medical and identity information.
The regulatory filing submitted by Winona County counsel reports that 6,196 people were affected by the Jan. 18-22, 2026 external system breach. Written notification began May 12, and affected people were offered 12 months of IDX credit and CyberScan monitoring, identity-restoration assistance and insurance.
Signed-in members can report an error, update, or missing source.