Winona County Hit by Second Ransomware Attack After Paying $128,000 First Time

Daily Feed
Winona County Hit by Second Ransomware Attack After Paying $128,000 First Time

Winona County, Minnesota, says it was hit by a second ransomware attack just months after paying roughly $128, 000 to deal with the first one. The ugly lesson is simple: paying criminals may buy time, but it does not buy immunity.

  • Two attacks: Winona County faced ransomware incidents in January and again in April.
  • First payment: The county paid about $128, 539 to resolve the January incident.
  • Data exposed: Personal, financial, medical, and law-enforcement-related records were taken.
  • Current response: The county is notifying affected people, working with the FBI, and tightening defenses.

According to Winona County and reporting from MPR News, unauthorized access ran from January 18 to January 22, 2026, with ransomware detected on January 22. The county later negotiated and paid about $128, 539 to resolve that first incident.

County administrator Maureen Holte said the payment was made after careful consideration and with guidance from the county’s cybersecurity team. She added that about $50, 000 was covered by insurance and about $78, 000 came out of county levy money, local taxpayer-funded revenue.

“It was after careful consideration and also guidance from our cybersecurity team. Winona County negotiated and paid a fee of approximately $128, 000. About $50, 000 was covered by insurance, and about 78, 000 was out of county levy money.”

That payment did not close the book. MPR News reported that the county was attacked again in April by different cybercriminals. The second incident is still under review, and no ransom figure has been publicly released for it.

That’s the part that should make every public official, taxpayer, and cybersecurity manager wince. A ransom payment is not a force field. It can restore access in one incident, but it does not erase stolen data, fix the underlying weakness, or stop the next crew from trying their luck.

What the January breach exposed

This was not just a “files locked, pay up, move on” mess. Winona County says attackers got into its network and took certain data.

The exposed information included names, addresses, Social Security numbers, driver’s license or state ID numbers, medical information, law-enforcement report information, financial account information, and, for a small number of people, payment card data and online account name and password information.

That matters because a ransomware event like this is really two problems at once. One is operational: systems get disrupted and staff are forced to improvise. The other is privacy-related: once personal data is copied out, the damage can linger for years in the form of identity theft, fraud risk, and ongoing monitoring headaches.

The county says it completed its review on April 16, 2026 and began mailing notices on May 12, 2026. It is also working with the FBI and has brought in outside cybersecurity and forensic help. The county’s Notice of Data Security Incident lays out the basics for affected residents, while the federal Please provide the HTML content for me to process and poster and the StopRansomware Guide remain the sort of unsexy but useful material too many organizations ignore until the wheels are already coming off.

Why counties keep getting hammered

Local governments are a favorite target for ransomware crews because they sit on a nasty mix of conditions: essential services, limited budgets, older systems, and a lot of third-party connections. Attackers only need one opening. Governments have to be right all the time.

Minnesota chief information officer John Israel told MPR News that government systems must stay open and accessible, which creates an obvious attack surface. He also said cybercriminals have become more aggressive and more sophisticated, with many using double extortion.

Double extortion means attackers do more than encrypt systems and demand payment for restoration. They also steal data and threaten to leak it unless they’re paid. It is ransomware with a blackmail upgrade, and it’s become a favorite business model for digital parasites with no shame and a very loose relationship with ethics.

That pattern is not unique to one Minnesota county. Winona County cyberattack is part of a trend as local governments across the country keep getting squeezed by crews that know public agencies can’t just shut the doors and go offline when things get ugly.

Emergency services stayed up, but the disruption was still real

One important bit of context: emergency services were not taken offline. That matters. Public safety stayed online even as the county dealt with the fallout.

But not everything kept humming. Some offices had to fall back to pen and paper, which is a polite way of saying the digital workflow was broken enough that staff had to do things manually. That keeps services moving, but it slows everything down, increases the chance of mistakes, and shows just how fragile modern public administration can be when systems get hit.

What the ransom payment really means

There is a practical reason officials sometimes pay: downtime can cripple services, and rebuilding everything from scratch can take longer than a cash settlement. That is the uncomfortable reality, especially for local governments that are already stretched thin.

But payment is not a clean fix. It does not undo the breach. It does not guarantee stolen data won’t be abused later. And it certainly does not guarantee the same organization won’t be targeted again. Winona County’s second attack is a blunt reminder of that.

That does not mean every decision not to pay is simple or heroic. It isn’t. Officials are often choosing between bad options while trying to keep courts, records, public services, and emergency systems functioning. Still, pretending a ransom is a magic off-switch is nonsense.

The bigger lesson is less glamorous and more expensive: underdefended systems tend to get paid for in one form or another, ransom, downtime, insurance claims, taxpayer money, or long-tail identity theft cleanup.

It also helps to remember how these crews operate. Some attacks are tied to broad criminal infrastructure, like the dark-web market shutdown in FBI Shuts Down RAMP: Dark Web Cybercrime Hub Linked to, where bitcoin and other tools help grease the wheels of organized extortion. Others are driven by automation and scale, like the pressure behind the CrowdStrike Warns of AI-Driven Ransomware Surge in Europe warning, which is a nice reminder that the bad guys are not sitting around twiddling their thumbs in a basement forever.

And yes, cybercrime and crypto fraud often overlap in the same underworld soup. The FBI Busts $265M Crypto Scam: New Zealand Man Among 13 case is another reminder that criminals will use whatever railroads the financial system gives them, whether that’s ransomware, phishing, or straight-up investment fraud dressed up as innovation.

Key questions and takeaways

  • Was Winona County hit more than once?
    Yes. The county says it faced a ransomware incident in January and another in April, with the second one still under review.
  • How much did the county pay after the first incident?
    MPR News reported about $128, 539. Roughly $50, 000 was covered by insurance and about $78, 000 came from county levy money.
  • What kind of data was exposed?
    Personal, financial, medical, and law-enforcement-related records were exposed, including names, addresses, Social Security numbers, driver’s license or state ID numbers, and some payment card details.
  • Did paying the ransom stop another attack?
    No evidence suggests it did. The county says it was hit again in April, which is about as clear a warning as anyone needs.
  • Were emergency services shut down?
    No. Emergency services stayed operational, though some county offices had to switch to manual work.
  • What is the county doing now?
    It is notifying affected people, working with the FBI, and strengthening network security after both incidents.

Winona County’s double hit is a reminder that ransomware is not just a tech problem. It is a governance problem, a budget problem, and a data-protection problem all at once. And when public systems are underfunded or underprepared, the bill shows up somewhere, often with taxpayers left holding it.

Further Reading

One more local angle for readers tracking the fallout and the bigger ransomware pattern around it:

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog