Claim details
Interlock publicly claimed the April 2026 attack and posted purported samples, but Winona County did not name the group and the reporting outlet could not independently verify attribution or the claimed file volume.
Winona County detected a second, distinct 2026 ransomware attack on April 7 after malicious activity began April 6, prompting a local emergency declaration, system isolation and Minnesota National Guard cyber assistance. DMV and vital-statistics services remained offline on April 10, the county reported secure restoration of its network and critical public systems by April 24, and it later confirmed that attackers released information acquired from the network.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
Internal or external network connectivity was unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
Services continued but with longer processing, response, delivery, or completion times.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.
Our April 8 report documented the initial disruption, National Guard response and separation from Winona County’s January ransomware incident. Winona County said it detected ransomware on April 7, 2026, and took affected systems offline while investigators and recovery teams responded; Minnesota’s Emergency Executive Order 26-06 places the beginning of the cyberattack on April 6 and documents disruption to critical systems and digital services. The county’s April 9 release explicitly treated this as a second incident involving a different cybercriminal from the January attack. DysruptionHub assesses with high confidence that this separate April event was a confirmed ransomware attack against county-government systems.
The county later said criminals released information acquired from its network, as preserved in Comparitech’s April 30 report. Interlock publicly claimed the incident, but the county did not attribute the attack to Interlock and the outlet could not independently verify the group’s claim; the actor relationship is therefore recorded as a low-confidence claim rather than confirmed attribution.
The governor’s April 7 announcement said the attack significantly impaired Winona County’s ability to deliver vital emergency and municipal services and exceeded internal and commercial response capacity, leading the county to request Minnesota National Guard cyber support. County officials subsequently clarified that 911, fire and emergency response continued without interruption, while affected county systems were isolated and residents should expect service delays in the April 9 release.
By April 10, county officials reported that the main network, Department of Motor Vehicles and vital-statistics systems remained offline, residents needing DMV services were directed to neighboring counties, and some employees used paper-and-pen workarounds, according to the Minnesota Star Tribune and KTTC. These effects materially restricted public access to county records and transaction services without interrupting emergency response.
Winona County’s own April 9 release confirmed ransomware, system isolation, public-service delays and the local emergency declaration. That affected-organization statement supports organization-confirmed cyber transparency and organization-documented disruption; the state executive order independently corroborates the attack chronology and service impairment.
The county said its preliminary investigation indicated that a different cybercriminal was responsible for the April attack than for January. No later public evidence establishes a shared access path, actor or campaign, so the incidents remain analytically related by victim and chronology but technically distinct.
In an April 24 county administrator release reproduced by WEAU, Winona County said its network and critical public systems had been securely restored and that offices were returning to close to full operations, although a service-request backlog could still cause delays. The incident is therefore recorded as resolved on April 24, with that date also retained as the latest documented operational-impact milestone.
Confidence is high in the incident, ransomware mechanism, disruption and restoration because the county and governor provided consistent direct statements. Data theft and public release are also supported by the county statement reported on April 30, but the affected data categories, volume and population were not yet established publicly.
Threat-actor confidence remains low. Comparitech documented Interlock’s claim and sample posting but stated that the county had not acknowledged the attribution and that the claim was not independently verified.
The public record reviewed does not establish the initial-access vector, compromised account or device, dwell time, exploited vulnerability, ransomware variant, encryption scope, ransom demand, payment status, full exfiltration volume, affected data categories, number of affected people or a county-confirmed responsible group. It also does not establish a shared technical pathway with the January incident. A separate April-incident breach notice or forensic report had not been located as of Aug. 12.
Interlock publicly claimed the April 2026 attack and posted purported samples, but Winona County did not name the group and the reporting outlet could not independently verify attribution or the claimed file volume.

The victim is the county government and the disruption affected county-administered services.
DysruptionHub reported that an April 6 cyberattack disrupted Winona County systems into April 7 and led Governor Tim Walz to authorize Minnesota National Guard cyber assistance. The report distinguished this event from the county’s January ransomware incident and said the April mechanism, data impact and actor were not yet public at publication time.
Emergency Executive Order 26-06 states that Winona County experienced a cyberattack beginning April 6 that targeted critical systems and digital services, persisted into April 7 and significantly disrupted vital emergency and critical services. It authorized Minnesota National Guard resources after the county requested support because the incident exceeded internal and commercial response capabilities.
Winona County said it detected and responded to ransomware on April 7, took affected systems offline, warned of public-service delays and declared a local emergency. It said 911, fire and emergency resources were never interrupted and preliminarily assessed that a different cybercriminal was responsible than in the prior county incident.
The Minnesota Star Tribune reported that county officials identified the April event as ransomware and said some employees used paper and pen while systems were unavailable. Most departments were back online by April 10, but motor-vehicle and vital-statistics systems remained down; 911 service was not interrupted.
KTTC reported that Winona County identified the incident as ransomware and was restoring systems in phases after taking part of the network offline. The main network, DMV and vital-statistics systems remained down, and officials directed residents needing DMV services to neighboring counties.
WEAU reproduced a Winona County administrator release stating that the county had securely restored its network and critical public systems after the April ransomware attack. County offices were returning to close to full operations on April 24, although a backlog could still cause processing delays.
Comparitech reported that Winona County said the criminals responsible for the April ransomware attack released information acquired from the county network. Interlock claimed the attack and posted samples, but the county did not acknowledge the attribution and the outlet said it could not independently verify the group’s claim or claimed volume.
Official profile information supporting the public description of Winona County.
Official geographic reference used with local and state material to verify place names, jurisdiction types and location context for winona, winona.
Signed-in members can report an error, update, or missing source.