Threat reportData BreachTL-2026-1640
Kootenai County, Idaho Ransomware Attack Exposes Resident Personal Information
Kootenai County, Idaho Ransomware Attack Exposes Resident (TL-2026-1640) is a medium-severity data breach, first published 2026-07-22. It has no confirmed attribution, affects Kootenai County, Idaho County government computer network, maps to 20 MITRE ATT&CK techniques (T1003, T1048, T1057), and is covered by 9 detection rules and 15 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 20MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-1640
- Threat ID
- TL-2026-1640
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- government administration, public-sector, local-government
- Target regions
- North America, united states of america, Idaho
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in Kootenai County, Idaho Ransomware Attack Exposes Resident
Malware and tooling: 3AM ransomware, BloodHound - S0521, Cobalt Strike, Mimikatz, Smoke Loader
How Kootenai County, Idaho Ransomware Attack Exposes Resident works
Kootenai County, Idaho detected a ransomware attack on its computer network on March 30, 2026. Third-party cybersecurity and forensics consultants confirmed cyber criminals extracted personal data before the county began mailing breach-notification letters to residents on July 22, 2026. No ransomware group has publicly claimed the attack and the data types and victim count remain undisclosed.
On March 30, 2026, Kootenai County, Idaho detected a ransomware intrusion on its government computer network. The county states it immediately secured the network, restored operations, notified federal law enforcement, and engaged nationally recognized third-party cybersecurity and digital-forensics consultants to investigate. County commissioners discussed the incident in a closed executive session on May 19, 2026, and the forensic review determined by late June 2026 that cyber criminals had extracted certain data constituting an 'unauthorized acquisition of personal information' under Idaho Code § 28-51-105. Idaho's breach-notification statute requires government agencies to notify the state Attorney General's office within 24 hours of discovery, one of the shortest mandatory reporting windows in the United States. Beginning July 22, 2026, the county started mailing written notification letters to affected residents and is offering free credit monitoring to eligible victims; residents without on-file contact information can find notice details on the county website. As of the notification date no ransomware group had publicly claimed responsibility on a leak site, and the county has not disclosed the initial access vector, the specific categories of exposed data, or the number of affected individuals. The incident is one of several ransomware-driven data breaches confirmed at Idaho county and municipal governments in the 2025-2026 timeframe (including Gooding County, Twin Falls County, Nampa, Jerome City/County, and Jefferson County), consistent with the broader nationwide pattern of ransomware-as-a-service (RaaS) affiliates and initial-access brokers targeting under-resourced state, local, tribal, and territorial (SLTT) government networks for double-extortion data theft. CISA/FBI/MS-ISAC joint advisories on SLTT-focused ransomware families (e.g., Phobos, AA24-060A) document a common kill chain of RDP brute-forcing or phishing for initial access, credential dumping, discovery, archival staging, exfiltration over alternative protocols, and encryption for impact; that documented pattern is included here as sector/technique context only and is NOT a confirmed attribution for the Kootenai County intrusion, which remains unclaimed and unattributed. This record should be distinguished from the unrelated 2024 Kootenai Health (medical center) ransomware breach attributed to the 3AM ransomware gang, which affected roughly 464,000 patients and involved a different victim organization and a different Idaho county-region entity.
MITRE ATT&CK techniques used in TL-2026-1640
Credential Access
Exfiltration
T1048 Exfiltration Over Alternative Protocol
Discovery
T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery
Defense Evasion
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1566 Phishing
Command and Control
Privilege Escalation
T1134 Access Token Manipulation; T1546 Event Triggered Execution
stealth
T1218 System Binary Proxy Execution
Impact
T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery
Persistence
T1547 Boot or Logon Autostart Execution
privilege-escalation
T1548 Abuse Elevation Control Mechanism
Collection
Execution
defense-impairment
Affected products and versions in Kootenai County, Idaho Ransomware Attack Exposes Resident
- Kootenai County, Idaho — County government computer network
Vulnerable versions: Not disclosed
Fixed in: Not applicable - no vendor patch identified
Remediation for Kootenai County, Idaho Ransomware Attack Exposes Resident
Patches
- No specific CVE or vulnerable product has been publicly disclosed for this incident; apply standard OS/RDP/VPN patching cadence pending forensic disclosure
Immediate actions
- Complete resident breach-notification mailing and website notice per Idaho Code § 28-51-105
- Offer and enroll eligible affected residents in free credit monitoring and identity-theft protection
- Confirm eradication of attacker persistence mechanisms and rotate all privileged and service-account credentials network-wide
- Verify Idaho Attorney General and federal law enforcement notification records are complete
Workarounds
- Restrict or disable exposed RDP; require VPN + MFA for any remote administrative access
- Enforce account lockout/rate limiting on all internet-facing authentication services to blunt brute-force initial access
Longer-term hardening
- Deploy EDR/XDR with behavioral ransomware and credential-dumping detection across county endpoints and servers
- Segment county government network zones (finance, elections, public safety, general administration) to limit lateral movement blast radius
- Implement centralized, tamper-resistant logging (forward Windows Event Logs off-host) to defeat log-clearing anti-forensics
- Adopt phishing-resistant MFA for all remote access and privileged accounts
- Establish immutable, tested offline backups and a documented ransomware incident-response/tabletop program
Timeline of Kootenai County, Idaho Ransomware Attack Exposes Resident
- County notifies federal law enforcement of the intrusion, per county public statement.
- Kootenai County detects a ransomware attack on its government computer network and immediately begins securing and restoring operations.
- Idaho Code § 28-51-105 requires government agencies to notify the Idaho Attorney General's office within 24 hours of discovering a breach of computerized personal information.
- Kootenai County commissioners discuss the breach in a closed executive session.
- Third-party cybersecurity and digital-forensics investigation concludes that cyber criminals extracted data constituting an unauthorized acquisition of personal information under Idaho law; some local reporting places the finalized scope determination as late as July 2, 2026.
- Local outlet PrismNews first publicly reports the breach determination and executive-session discussion, nearly a month ahead of the county's formal resident notification mailing.
- As of the notification date, no ransomware group has publicly claimed responsibility for the attack on a leak site or elsewhere; data categories and victim count remain undisclosed.
- Kootenai County begins mailing written breach-notification letters to affected residents and posts notice on the county website; free credit monitoring offered to eligible victims.
Sources cited for Kootenai County, Idaho Ransomware Attack Exposes Resident
- ID: Kootenai County notifies residents of data breach
- Kootenai County notifies residents of data breach
- Kootenai County notifies residents after March ransomware breach exposed data
- Idaho Code § 28-51-105 - Disclosure of Breach of Security of Computerized Personal Information
- #StopRansomware: Phobos Ransomware (AA24-060A)
- Response to CISA Advisory (AA24-060A) - Phobos Ransomware MITRE ATT&CK Mapping
- Idaho county government hacked by ransomware, personal info breached (Gooding County)
- Twin Falls County, Idaho, Confirms Ransomware Attack
- 3AM ransomware stole data of 464,000 Kootenai Health patients (unrelated 2024 incident, distinct entity)
Detection coverage for TL-2026-1640
As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1640 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.