Winona County in Minnesota has been hit by two ransomware attacks months apart, with the second incident occurring in April after county officials paid a ransom to recover from the first attack.
The initial breach occurred between January 18 and January 22, 2026, with ransomware detected on January 22. Following the first attack, Maureen Holte, Winona County administrator, said the decision to pay the ransom came "after careful consideration and also guidance from our cybersecurity team."
County officials negotiated and paid a fee of approximately $128,539. Insurance covered about $50,000 of the total, while roughly $78,000 came from county levy money.
The January breach compromised sensitive personal information including names, addresses, Social Security numbers, driver's licenses, medical details, law enforcement reports, financial information, and payment card data for some individuals.
Emergency services remained operational during both attacks, though some county offices temporarily reverted to manual pen-and-paper operations. Victim notifications began mailing on May 12, 2026.
According to reports, the second ransomware attack in April involved different cybercriminals. No ransom figure has been disclosed for the April incident, and a separate notice is planned once the investigation concludes.
Winona County is collaborating with the FBI on both incidents and says it is implementing stronger defenses to prevent future attacks.


