CSIDB logo
Incident

Kootenai County

Incident posture

Attack window
Mar 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-28 00:51

Linked entities

Victim
Kootenai County
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2026
Discovered
Mar 2026
Disclosed
Jul 2026
Resolved
Pending

Summary

A ransomware attack was discovered on the county's computer network, prompting officials to isolate the system and restore operations while engaging third‑party cybersecurity and forensics experts to investigate the breach. The investigation determined that certain personal data had been extracted, identified the affected residents, and established where they lived. Notification letters were mailed to those individuals, and for residents without contact information on file, details were posted on the county's website. The county also reported the incident to federal law enforcement and is reviewing its IT security practices to address vulnerabilities.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On March 30, 2026, Kootenai County detected a ransomware attack on its computer network. Upon discovery, county officials immediately took action to secure the network and restore county operations. The county engaged nationally recognized third‑party cybersecurity and data forensics consultants to investigate the breach. Federal law enforcement was notified of the incident as part of the response. These steps were outlined in a Kootenai County press release issued after the detection.

Following a thorough review completed on July 2, 2026, investigators determined what information had been compromised, which residents were affected, and where those individuals resided. The investigation revealed that cyber criminals had successfully extracted certain data from the county's network. Beginning July 22, 2026, the county started mailing written notification letters to impacted individuals whose contact information was on file. For residents whose contact information the county did not have on file, notification was made available on the county's website. The notification letters directed recipients to review their account statements and obtain free credit reports to identify any unauthorized or suspicious activity.

The county also urged residents to report any unusual activity to law enforcement immediately. Additional steps residents could take to help protect their information following the breach were posted on the county's website. As cyber threats continue to evolve, Kootenai County is working to identify and mitigate potential vulnerabilities in its systems. The county has taken steps to strengthen its network security and is evaluating its IT security protocols to prevent similar incidents in the future.

Sources

Sources available to members: 1 source.

CSIDB