Aitkin County Health & Human Services in Minnesota disclosed a cyber incident after attackers compromised a county employee email account and used it to send phishing messages. Investigators found unauthorized access to three county email accounts between April 7 and April 8, 2026, and determined that cybercriminals downloaded data from the County HHS mailbox. The exposed information included Social Security numbers, medical information, insurance identifiers, and MnCHOICES-related records, affecting at least 83,114 individuals.
The agency reported the breach to the U.S. Department of Health and Human Services, where it appears alongside a broader stream of healthcare-sector disclosures dominated by Hacking/IT Incident reports involving network servers and email systems. Federal breach listings show sustained impact across providers, health plans, and business associates, with other large incidents affecting organizations such as TriZetto Provider Solutions, QualDerm Partners, ApolloMD Business Services, and the Illinois and Minnesota Departments of Human Services. Aitkin County said it also notified law enforcement and urged affected individuals to monitor credit reports, financial accounts, and benefit statements; no threat actor had claimed responsibility at the time of disclosure.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
Aitkin County Health & Human Services disclosed the incident, reported it to the U.S. Department of Health and Human Services, and said at least 83,114 individuals were affected. The agency also notified law enforcement and advised affected individuals to monitor credit reports, accounts, and benefit statements.
Aitkin County Health & Human Services said unauthorized access to three county email accounts occurred between April 7 and April 8, 2026. Investigators determined that cybercriminals downloaded the contents of the County HHS email account and used a compromised employee account to send phishing emails.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.