Skip to content

Winona County April 2026 Ransomware Attack

Summary

Winona County logo

Winona County detected a second, distinct 2026 ransomware attack on April 7 after malicious activity began April 6, prompting a local emergency declaration, system isolation and Minnesota National Guard cyber assistance. DMV and vital-statistics services remained offline on April 10, the county reported secure restoration of its network and critical public systems by April 24, and it later confirmed that attackers released information acquired from the network.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

Data impacts

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Records processing disruption

    The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.

  • Government services disrupted

    Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

  • Staff unable to work normally

    Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

Extortion indicators

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

Incident narrative

Analyst assessment

Our April 8 report documented the initial disruption, National Guard response and separation from Winona County’s January ransomware incident. Winona County said it detected ransomware on April 7, 2026, and took affected systems offline while investigators and recovery teams responded; Minnesota’s Emergency Executive Order 26-06 places the beginning of the cyberattack on April 6 and documents disruption to critical systems and digital services. The county’s April 9 release explicitly treated this as a second incident involving a different cybercriminal from the January attack. DysruptionHub assesses with high confidence that this separate April event was a confirmed ransomware attack against county-government systems.

The county later said criminals released information acquired from its network, as preserved in Comparitech’s April 30 report. Interlock publicly claimed the incident, but the county did not attribute the attack to Interlock and the outlet could not independently verify the group’s claim; the actor relationship is therefore recorded as a low-confidence claim rather than confirmed attribution.

Operational significance

The governor’s April 7 announcement said the attack significantly impaired Winona County’s ability to deliver vital emergency and municipal services and exceeded internal and commercial response capacity, leading the county to request Minnesota National Guard cyber support. County officials subsequently clarified that 911, fire and emergency response continued without interruption, while affected county systems were isolated and residents should expect service delays in the April 9 release.

By April 10, county officials reported that the main network, Department of Motor Vehicles and vital-statistics systems remained offline, residents needing DMV services were directed to neighboring counties, and some employees used paper-and-pen workarounds, according to the Minnesota Star Tribune and KTTC. These effects materially restricted public access to county records and transaction services without interrupting emergency response.

Disclosure posture

Winona County’s own April 9 release confirmed ransomware, system isolation, public-service delays and the local emergency declaration. That affected-organization statement supports organization-confirmed cyber transparency and organization-documented disruption; the state executive order independently corroborates the attack chronology and service impairment.

The county said its preliminary investigation indicated that a different cybercriminal was responsible for the April attack than for January. No later public evidence establishes a shared access path, actor or campaign, so the incidents remain analytically related by victim and chronology but technically distinct.

Current status

In an April 24 county administrator release reproduced by WEAU, Winona County said its network and critical public systems had been securely restored and that offices were returning to close to full operations, although a service-request backlog could still cause delays. The incident is therefore recorded as resolved on April 24, with that date also retained as the latest documented operational-impact milestone.

Confidence and uncertainty

Confidence is high in the incident, ransomware mechanism, disruption and restoration because the county and governor provided consistent direct statements. Data theft and public release are also supported by the county statement reported on April 30, but the affected data categories, volume and population were not yet established publicly.

Threat-actor confidence remains low. Comparitech documented Interlock’s claim and sample posting but stated that the county had not acknowledged the attribution and that the claim was not independently verified.

Analytic gaps

The public record reviewed does not establish the initial-access vector, compromised account or device, dwell time, exploited vulnerability, ransomware variant, encryption scope, ransom demand, payment status, full exfiltration volume, affected data categories, number of affected people or a county-confirmed responsible group. It also does not establish a shared technical pathway with the January incident. A separate April-incident breach notice or forensic report had not been located as of Aug. 12.

Threat actor and claim

Listed as: Winona County, MNSource: otherPublished:

Claim details

Interlock publicly claimed the April 2026 attack and posted purported samples, but Winona County did not name the group and the reporting outlet could not independently verify attribution or the claimed file volume.

Organizations involved

Impacted locations

Sources

Winona County, Minnesota, gets Guard cyber aid

DysruptionHub reported that an April 6 cyberattack disrupted Winona County systems into April 7 and led Governor Tim Walz to authorize Minnesota National Guard cyber assistance. The report distinguished this event from the county’s January ransomware incident and said the April mechanism, data impact and actor were not yet public at publication time.

Emergency Executive Order 26-06: Providing Assistance to Winona County

Emergency Executive Order 26-06 states that Winona County experienced a cyberattack beginning April 6 that targeted critical systems and digital services, persisted into April 7 and significantly disrupted vital emergency and critical services. It authorized Minnesota National Guard resources after the county requested support because the incident exceeded internal and commercial response capabilities.

Winona County ransomware incident news release

Winona County said it detected and responded to ransomware on April 7, took affected systems offline, warned of public-service delays and declared a local emergency. It said 911, fire and emergency resources were never interrupted and preliminarily assessed that a different cybercriminal was responsible than in the prior county incident.

It's pen and paper for some Winona County workers, as officials fend off 2nd cyberattack this year

The Minnesota Star Tribune reported that county officials identified the April event as ransomware and said some employees used paper and pen while systems were unavailable. Most departments were back online by April 10, but motor-vehicle and vital-statistics systems remained down; 911 service was not interrupted.

Winona County announces National Guard, BCA aid following cybersecurity attack

KTTC reported that Winona County identified the incident as ransomware and was restoring systems in phases after taking part of the network offline. The main network, DMV and vital-statistics systems remained down, and officials directed residents needing DMV services to neighboring counties.

Press release: Winona County gives cyber attack update

WEAU reproduced a Winona County administrator release stating that the county had securely restored its network and critical public systems after the April ransomware attack. County offices were returning to close to full operations on April 24, although a backlog could still cause processing delays.

Cybercriminals say they hacked Winona County, MN (again)

Comparitech reported that Winona County said the criminals responsible for the April ransomware attack released information acquired from the county network. Interlock claimed the attack and posted samples, but the county did not acknowledge the attribution and the outlet said it could not independently verify the group’s claim or claimed volume.

Winona County, Minnesota

Official profile information supporting the public description of Winona County.

Geographic profiles for selected U.S. locations

Official geographic reference used with local and state material to verify place names, jurisdiction types and location context for winona, winona.

See something that needs correction?

Signed-in members can report an error, update, or missing source.