Winona County, Minnesota, detected ransomware on its IT network on January 22, 2026, engaged third-party forensic specialists, notified federal law enforcement, and negotiated with the attackers. With support from its cyber insurer, the county paid $128,539.57 in ransom; it sent written notifications to affected individuals and made public disclosures on May 12.
The county subsequently detected a second, apparently unrelated ransomware incident in April. That intrusion remained under investigation, underscoring that the county experienced two distinct ransomware attacks against its environment in 2026.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
Winona County sent written notifications to affected individuals concerning the January ransomware incident and publicly communicated the incident through its website and the media.
Winona County detected a second ransomware attack, described as unrelated to the January incident. The second incident remained under investigation at the time of reporting.
Winona County, Minnesota, detected a ransomware attack against its information-technology network. The county retained third-party forensic specialists, notified federal law enforcement, and later negotiated a ransom payment with support from its cyber insurer.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.