Minn. (KTTC) – Winona County officials confirm they negotiated and paid a $128,539.57 ransom following a cyberattack earlier this year, even as they continue to investigate a second, unrelated ransomware incident that struck just months later
In a joint update, the Winona County Board of Commissioners detailed their ongoing response to the two separate cybersecurity breaches, which occurred in January and April of 2026.
The first breach was detected on January 22, 2026. As KTTC previously reported in February, the initial attack forced several county computer networks offline and caused widespread delays for municipal services.
To ensure the resumption of vital public services and protect personal data, county leaders ultimately decided to pay the threat actors.
“Winona County negotiated and paid a fee [of $128,539.57] with assistance from our insurance carrier,” the commissioners said in a statement. “Although making the payment in connection with the January incident was a difficult choice, we determined it was the necessary approach to best serve the interests of Winona County residents and employees.”
Impacted individuals were formally notified of the breach on May 12, 2026, following a thorough review of the compromised data.
Less than three months after the initial attack, a second ransomware strain was detected on the county’s network on April 7, 2026. Officials emphasized that this breach was entirely separate and unrelated to the January incident.
KTTC reported in April that the second attack significantly impaired the county’s ability to deliver emergency and municipal services, keeping vital systems like the Department of Motor Vehicles (DMV) and vital statistics offline for days. The severity of the incident prompted Minnesota Gov. Tim Walz to authorize the Minnesota National Guard and the Bureau of Criminal Apprehension (BCA) to step in and assist with emergency operations and network hardening.
Winona County is currently conducting a comprehensive review of the data targeted in the April attack to determine what specific information was accessed and who was affected.
Officials say that once the April data review is complete, notification letters will be mailed to affected individuals.
For those whose Social Security numbers or driver’s license numbers were compromised in the April attack, the county will offer complimentary credit monitoring and identity protection services.
Acknowledging the persistent threat of sophisticated cybercriminals, the commissioners expressed gratitude to the community for their patience and promised that aggressive upgrades to the county’s digital infrastructure are underway.
“The commissioners assure the citizens of Winona County that aggressive measures have been and will continue to be taken to minimize the risk of a similar event occurring again,” the statement concluded.
Find stories like this and more, in our apps.
Copyright 2026 KTTC. All rights reserved.
