Full Report
WINONA, Minn. (WXOW) — Winona County paid more than $128,000 to resolve a ransomware attack detected in January, and officials are now investigating a second, unrelated attack from April. The county detected ransomware on its computer network on Jan. 22. Officials took immediate action to investigate and engaged third-party forensic experts and federal law enforcement, according to a press release. On May 12, the county provided written notification to impacted individuals, as well as notification on its website and to the media regarding the January ransomware incident. After careful consideration and guidance from its cybersecurity team, Winona County negotiated and paid a fee of $128,539.57 with assistance from its insurance carrier. Officials said making the payment was a difficult choice but determined it was the necessary approach to best serve the interests of Winona County residents and employees.
Analysis Summary
# Incident Report: Winona County Ransomware Compromise
## Executive Summary
Winona County, Minnesota, experienced two separate, unrelated cyberattacks in early 2026. The first, a ransomware attack detected in January, resulted in a $128,539.57 payment to threat actors to restore operations and protect resident interests. Shortly after resolving the first incident, a second unrelated attack was detected in April, which remains under investigation.
## Incident Details
- **Discovery Date:** January 22, 2026 (Initial Incident); April 2026 (Second Incident)
- **Incident Date:** January 2026
- **Affected Organization:** Winona County
- **Sector:** Government / Public Sector
- **Geography:** Winona, Minnesota, USA
## Timeline of Events
### Initial Access
- **Date/Time:** Pre-January 22, 2026
- **Vector:** Not disclosed (Investigation ongoing)
- **Details:** Threat actors gained access to the county computer network, leading to the deployment of ransomware.
### Lateral Movement
- **Details:** Not explicitly disclosed in the public statement; however, the attack impacted the broader "computer network," suggesting movement from the initial entry point to central file servers or systems.
### Data Exfiltration/Impact
- **Impact:** Encryption of county files and systems. A notification issued on May 12 indicated that "impacted individuals" were notified, suggesting personal data (potentially Social Security numbers or employee records) was accessed or at risk.
### Detection & Response
- **January 22:** Ransomware detected on the network.
- **Immediate Post-Detection:** Engagement of third-party forensic experts and federal law enforcement.
- **Resolution Phase:** Negotiation with attackers; payment of $128,539.57 via an insurance carrier.
- **April 2026:** Detection of a second, unrelated attack.
- **May 12, 2026:** Public and individual notification provided to impacted parties.
## Attack Methodology
- **Initial Access:** [Unknown/Not Disclosed]
- **Persistence:** [Not Disclosed]
- **Privilege Escalation:** [Not Disclosed]
- **Defense Evasion:** [Not Disclosed]
- **Credential Access:** [Not Disclosed]
- **Discovery:** [Not Disclosed]
- **Lateral Movement:** [Not Disclosed]
- **Collection:** [Not Disclosed]
- **Exfiltration:** Likely (Based on notification to "impacted individuals")
- **Impact:** Data Encrypted for Impact; Financial loss via ransom payment.
## Impact Assessment
- **Financial:** $128,539.57 ransom payment plus undisclosed costs for third-party forensics and legal counsel.
- **Data Breach:** Compromise of personal information for residents and employees (scope and volume not finalized).
- **Operational:** Disruption of county services from January through the recovery period.
- **Reputational:** High public visibility due to back-to-back incidents and the use of taxpayer-funded resources for ransom.
## Indicators of Compromise
- **Network indicators:** None disclosed in the public report.
- **File indicators:** None disclosed; ransomware extensions were likely present on encrypted files.
- **Behavioral indicators:** Unusual network traffic patterns and mass file encryption detected on Jan 22.
## Response Actions
- **Containment:** Immediate isolation of affected systems upon detection.
- **Eradication:** Investigation by third-party forensic experts and law enforcement to identify the breach source.
- **Recovery:** Negotiation and payment of the ransom to obtain decryption keys and restore resident services.
## Lessons Learned
- **Redundancy of Attacks:** The occurrence of a second attack in April suggests that remediating one incident does not automatically close all vulnerabilities.
- **Insurance Role:** The insurance carrier was critical in facilitating the payment, highlighting the necessity of cyber insurance for municipalities.
- **Disclosure Lag:** There was a significant gap between the January detection and the May public notification, which can impact public trust.
## Recommendations
- **Network Segmentation:** Implement strict segmentation to prevent lateral movement between departments.
- **Enhanced Monitoring:** Deploy Endpoint Detection and Response (EDR) tools to identify unauthorized behavior before encryption occurs.
- **Vulnerability Assessment:** Conduct a comprehensive post-incident audit to identify why a second, "unrelated" attack was able to occur so soon after the first.
- **Backup Integrity:** Ensure immutable, off-site backups are maintained to avoid the necessity of future ransom payments.