Minnesota Governor Tim Walz issued an emergency executive order authorizing the Minnesota National Guard to help Winona County respond to a cyberattack that disrupted the county’s critical systems and digital services. County officials discovered the incident on Monday and said the attack significantly impaired delivery of emergency and municipal services, with some police department phone transfer functions reportedly unavailable. The county has been coordinating with the FBI, the Minnesota Bureau of Criminal Apprehension, the state IT agency, a cybersecurity vendor, and the League of Minnesota Cities.
State officials said the scale and complexity of the intrusion exceeded the county’s internal and contracted response capabilities, prompting emergency state support. The incident marks the second successful cyberattack reported against Winona County in the same year, following an earlier breach that knocked out systems used for real-estate transactions and police file access before service was restored.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
By April 10, 2026, Winona County officials said preliminary investigation indicated the ransomware attack discovered that week was likely carried out by a different threat actor than the one behind the county's January 2024 cyberattack. The statement marked an early attribution update as response and recovery efforts continued.
On April 7, 2026, Governor Tim Walz issued an emergency executive order authorizing the Minnesota National Guard to assist Winona County. State officials said the scale and complexity of the incident exceeded the county's internal and commercial response capabilities and was impairing vital emergency and municipal services.
Winona County discovered a new cyberattack on Monday that disrupted critical systems and digital services. The county began responding with support from the FBI, a cybersecurity vendor, Minnesota IT Services, the Minnesota Bureau of Criminal Apprehension, and the League of Minnesota Cities.
In January 2024, Winona County suffered a successful cyberattack that disrupted systems used for real-estate transactions and police file access. Recovery from that incident was completed in February.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
5 references tracked. Mallory keeps watching after this page renders.
cbsnews.com
Open sourcescworld.com
Open sourcetherecord.media
Open sourcestatescoop.com
Open sourcenews8000.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.