Menu
Browse

Cyber Incident Victim: Kootenai County

Date

Mar 2026

Location

United States of America

Status

Unknown

Timeline
Occurred
Mar 2026
Discovered
Mar 2026
Disclosed
Jul 2026
Summary

Kootenai County detected a ransomware attack on its network and engaged third‑party cybersecurity experts to investigate. The investigation found that certain personal data had been extracted, and after reviewing the breach the county identified affected residents and began mailing notification letters. For those without on‑file contact information, notices were posted on the county’s website. The county also reported the incident to federal law enforcement and is working to improve its network security.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On March 30, 2026, Kootenai County detected a ransomware attack on its computer network. County officials immediately isolated affected systems and began efforts to secure the network and restore essential operations. The county engaged nationally recognized third‑party cybersecurity and data forensics consultants to assist with the investigation. Simultaneously, the incident was reported to federal law enforcement agencies as required by policy.

Cyber Incident Image

The consultants conducted a thorough forensic analysis to determine the scope of the breach and what data had been accessed. By July 2, 2026, the review was complete and county officials identified the specific categories of personal information that had been extracted. They also determined which residents were affected and where those individuals resided. This assessment formed the basis for the subsequent notification process.

Beginning July 22, 2026, the county started mailing written notification letters to all individuals whose personal information was confirmed to be compromised. For residents whose contact information was not on file, the county made the notice available on its official website. After the notification campaign, the county continued to work on improving its security posture by identifying potential vulnerabilities in its systems. The county has taken steps to strengthen its network security and is evaluating its IT security protocols to prevent similar incidents in the future.

Sources
Sources available to members
1 source