Winona County, Minnesota is recovering from two ransomware attacks that struck county systems just months apart, with the second incident arriving after officials paid roughly $128,539 to resolve the first case.

County officials said the later attack took place in April 2026 and involved a different criminal group than the one behind the January breach. The county is still reviewing that second incident while working with the FBI.

January intrusion led to ransom payment

According to the county, unauthorized access during the first incident lasted from January 18 through January 22, 2026, when ransomware was detected. County administrator Maureen Holte said the decision to pay was made after what she described as careful consideration and guidance from the county’s cybersecurity team.

Holte said Winona County negotiated and paid about $128,000 to end the January attack. She said roughly $50,000 of that amount was covered by insurance, while about $78,000 came from county levy funds. The reported total payment was $128,539.

Sensitive data was exposed in the first breach

The county said the January breach affected a wide range of personal and sensitive information. Exposed data included names, addresses, Social Security numbers, driver’s license information, medical details, law enforcement reports and financial information.

For some people, payment card data was also involved. The scope of the affected records means the incident reached across multiple categories of county-held information rather than a single database or service.

Essential services remained online

Winona County said emergency services stayed operational during both ransomware incidents. Even so, some county offices had to fall back on manual processes, including pen-and-paper work, while systems were disrupted.

That distinction is significant because it shows the attacks interfered with normal administration without taking emergency functions offline, at least based on the county’s account of both events.

April attack remains under review

Officials said the second ransomware attack occurred in April 2026 and was carried out by different cybercriminals than those involved in the January case. The county has not released a ransom figure tied to the later incident.

The April breach is still under review, and Winona County said a separate notice is planned. In the meantime, the county has already begun mailing notifications related to the January incident, with those notices starting on May 12, 2026.

Next steps for the county

Winona County said it is working with the FBI as it responds to the incidents. The county also says it is strengthening its defenses in an effort to prevent future attacks.

For now, the clearest confirmed next step is further disclosure around the April case once the review is complete. That notice is expected to provide more detail on what happened and whether any additional information was compromised.

Source: dailyhodl.com