CSIDB logo
Incident

Winona County

Incident posture

Attack window
Jan 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-03 00:24

Linked entities

Victim
Winona County
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Jan 2026
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Winona County experienced a ransomware attack that disrupted its network and critical public systems, prompting officials to pull parts of the infrastructure offline to limit the threat. Emergency services remained operational while the county’s vital statistics and Department of Motor Vehicles systems were taken offline, and the Minnesota National Guard was brought in to assist with response and recovery. Public‑facing systems were restored in phases, with close to full office operations expected to resume shortly, although a backlog of work may cause some delays for residents seeking in‑person assistance. This incident marked the second ransomware attack against the county this year, following an earlier event attributed to a different cyber actor, and a local state of emergency was declared for both occurrences.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In January 2026 Winona County experienced its first ransomware attack of the year, which was publicly announced at that time. A second ransomware attack occurred earlier in April 2026, prompting the county to pull parts of its network offline to limit the threat. The isolated segments included the vital statistics system and the Department of Motor Vehicles system, while emergency services remained unaffected. To address the incident the county requested and received assistance from the Minnesota National Guard. A local state of emergency was declared for both the January and April attacks.

Following the containment efforts the county began restoring its public‑facing systems in phases, with officials stating on Thursday that close to full office operations were expected to resume the following Friday. Residents were warned that some delays might persist as backlogs were processed and were advised to call ahead before visiting a county office to confirm staff availability. The county emphasized its commitment to minimizing the impact on residents conducting business and expressed gratitude for the community’s patience during the recovery. The county stated, "We remain committed to minimizing the impact on residents doing business with the county," and added, "We are incredibly grateful for our community’s patience as we work to recover from this incident." Preliminary investigation into the second attack indicated that the incident is believed to have been done by a different cyber criminal than the one responsible for the January attack.

Sources

Sources available to members: 2 sources.

CSIDB