Threat reportData BreachTL-2026-1640

Kootenai County, Idaho Ransomware Attack Exposes Resident Personal Information

mediumACTIVE

Kootenai County, Idaho Ransomware Attack Exposes Resident (TL-2026-1640) is a medium-severity data breach, first published 2026-07-22. It has no confirmed attribution, affects Kootenai County, Idaho County government computer network, maps to 20 MITRE ATT&CK techniques (T1003, T1048, T1057), and is covered by 9 detection rules and 15 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
20MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
15Indicators of compromise

Key facts for TL-2026-1640

Threat ID
TL-2026-1640
Severity
MEDIUM
Status
ACTIVE
Category
DATA_BREACH
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
government administration, public-sector, local-government
Target regions
North America, united states of america, Idaho
Detection rules
9
Indicators of compromise
15

Malware and tooling in Kootenai County, Idaho Ransomware Attack Exposes Resident

Malware and tooling: 3AM ransomware, BloodHound - S0521, Cobalt Strike, Mimikatz, Smoke Loader

How Kootenai County, Idaho Ransomware Attack Exposes Resident works

Kootenai County, Idaho detected a ransomware attack on its computer network on March 30, 2026. Third-party cybersecurity and forensics consultants confirmed cyber criminals extracted personal data before the county began mailing breach-notification letters to residents on July 22, 2026. No ransomware group has publicly claimed the attack and the data types and victim count remain undisclosed.

On March 30, 2026, Kootenai County, Idaho detected a ransomware intrusion on its government computer network. The county states it immediately secured the network, restored operations, notified federal law enforcement, and engaged nationally recognized third-party cybersecurity and digital-forensics consultants to investigate. County commissioners discussed the incident in a closed executive session on May 19, 2026, and the forensic review determined by late June 2026 that cyber criminals had extracted certain data constituting an 'unauthorized acquisition of personal information' under Idaho Code § 28-51-105. Idaho's breach-notification statute requires government agencies to notify the state Attorney General's office within 24 hours of discovery, one of the shortest mandatory reporting windows in the United States. Beginning July 22, 2026, the county started mailing written notification letters to affected residents and is offering free credit monitoring to eligible victims; residents without on-file contact information can find notice details on the county website. As of the notification date no ransomware group had publicly claimed responsibility on a leak site, and the county has not disclosed the initial access vector, the specific categories of exposed data, or the number of affected individuals. The incident is one of several ransomware-driven data breaches confirmed at Idaho county and municipal governments in the 2025-2026 timeframe (including Gooding County, Twin Falls County, Nampa, Jerome City/County, and Jefferson County), consistent with the broader nationwide pattern of ransomware-as-a-service (RaaS) affiliates and initial-access brokers targeting under-resourced state, local, tribal, and territorial (SLTT) government networks for double-extortion data theft. CISA/FBI/MS-ISAC joint advisories on SLTT-focused ransomware families (e.g., Phobos, AA24-060A) document a common kill chain of RDP brute-forcing or phishing for initial access, credential dumping, discovery, archival staging, exfiltration over alternative protocols, and encryption for impact; that documented pattern is included here as sector/technique context only and is NOT a confirmed attribution for the Kootenai County intrusion, which remains unclaimed and unattributed. This record should be distinguished from the unrelated 2024 Kootenai Health (medical center) ransomware breach attributed to the 3AM ransomware gang, which affected roughly 464,000 patients and involved a different victim organization and a different Idaho county-region entity.

MITRE ATT&CK techniques used in TL-2026-1640

Credential Access

T1003 OS Credential Dumping

Exfiltration

T1048 Exfiltration Over Alternative Protocol

Discovery

T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery

Defense Evasion

T1070 Indicator Removal

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1566 Phishing

Command and Control

T1105 Ingress Tool Transfer

Privilege Escalation

T1134 Access Token Manipulation; T1546 Event Triggered Execution

stealth

T1218 System Binary Proxy Execution

Impact

T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery

Persistence

T1547 Boot or Logon Autostart Execution

privilege-escalation

T1548 Abuse Elevation Control Mechanism

Collection

T1560 Archive Collected Data

Execution

T1574 Hijack Execution Flow

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Kootenai County, Idaho Ransomware Attack Exposes Resident

  • Kootenai County, Idaho — County government computer network
    Vulnerable versions: Not disclosed
    Fixed in: Not applicable - no vendor patch identified

Remediation for Kootenai County, Idaho Ransomware Attack Exposes Resident

Patches

  • No specific CVE or vulnerable product has been publicly disclosed for this incident; apply standard OS/RDP/VPN patching cadence pending forensic disclosure

Immediate actions

  • Complete resident breach-notification mailing and website notice per Idaho Code § 28-51-105
  • Offer and enroll eligible affected residents in free credit monitoring and identity-theft protection
  • Confirm eradication of attacker persistence mechanisms and rotate all privileged and service-account credentials network-wide
  • Verify Idaho Attorney General and federal law enforcement notification records are complete

Workarounds

  • Restrict or disable exposed RDP; require VPN + MFA for any remote administrative access
  • Enforce account lockout/rate limiting on all internet-facing authentication services to blunt brute-force initial access

Longer-term hardening

  • Deploy EDR/XDR with behavioral ransomware and credential-dumping detection across county endpoints and servers
  • Segment county government network zones (finance, elections, public safety, general administration) to limit lateral movement blast radius
  • Implement centralized, tamper-resistant logging (forward Windows Event Logs off-host) to defeat log-clearing anti-forensics
  • Adopt phishing-resistant MFA for all remote access and privileged accounts
  • Establish immutable, tested offline backups and a documented ransomware incident-response/tabletop program

Timeline of Kootenai County, Idaho Ransomware Attack Exposes Resident

  • County notifies federal law enforcement of the intrusion, per county public statement.
  • Kootenai County detects a ransomware attack on its government computer network and immediately begins securing and restoring operations.
  • Idaho Code § 28-51-105 requires government agencies to notify the Idaho Attorney General's office within 24 hours of discovering a breach of computerized personal information.
  • Kootenai County commissioners discuss the breach in a closed executive session.
  • Third-party cybersecurity and digital-forensics investigation concludes that cyber criminals extracted data constituting an unauthorized acquisition of personal information under Idaho law; some local reporting places the finalized scope determination as late as July 2, 2026.
  • Local outlet PrismNews first publicly reports the breach determination and executive-session discussion, nearly a month ahead of the county's formal resident notification mailing.
  • As of the notification date, no ransomware group has publicly claimed responsibility for the attack on a leak site or elsewhere; data categories and victim count remain undisclosed.
  • Kootenai County begins mailing written breach-notification letters to affected residents and posts notice on the county website; free credit monitoring offered to eligible victims.

Sources cited for Kootenai County, Idaho Ransomware Attack Exposes Resident

Detection coverage for TL-2026-1640

As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1640 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
15 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats