# Kootenai County, Idaho Ransomware Attack Exposes Resident Personal Information

> Kootenai County, Idaho detected a ransomware attack on its computer network on March 30, 2026. Third-party cybersecurity and forensics consultants confirmed cyber criminals extracted personal data before the county began mailing breach-notification letters to residents on July 22, 2026. No ransomware group has publicly claimed the attack and the data types and victim count remain undisclosed.

- **Published:** 2026-07-22T00:00:00Z
- **Last reviewed:** 2026-07-22T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1640
- **ID:** TL-2026-1640
- **Severity:** MEDIUM
- **Category:** DATA_BREACH
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On March 30, 2026, Kootenai County, Idaho detected a ransomware intrusion on its government computer network. The county states it immediately secured the network, restored operations, notified federal law enforcement, and engaged nationally recognized third-party cybersecurity and digital-forensics consultants to investigate. County commissioners discussed the incident in a closed executive session on May 19, 2026, and the forensic review determined by late June 2026 that cyber criminals had extracted certain data constituting an 'unauthorized acquisition of personal information' under Idaho Code § 28-51-105. Idaho's breach-notification statute requires government agencies to notify the state Attorney General's office within 24 hours of discovery, one of the shortest mandatory reporting windows in the United States. Beginning July 22, 2026, the county started mailing written notification letters to affected residents and is offering free credit monitoring to eligible victims; residents without on-file contact information can find notice details on the county website. As of the notification date no ransomware group had publicly claimed responsibility on a leak site, and the county has not disclosed the initial access vector, the specific categories of exposed data, or the number of affected individuals. The incident is one of several ransomware-driven data breaches confirmed at Idaho county and municipal governments in the 2025-2026 timeframe (including Gooding County, Twin Falls County, Nampa, Jerome City/County, and Jefferson County), consistent with the broader nationwide pattern of ransomware-as-a-service (RaaS) affiliates and initial-access brokers targeting under-resourced state, local, tribal, and territorial (SLTT) government networks for double-extortion data theft. CISA/FBI/MS-ISAC joint advisories on SLTT-focused ransomware families (e.g., Phobos, AA24-060A) document a common kill chain of RDP brute-forcing or phishing for initial access, credential dumping, discovery, archival staging, exfiltration over alternative protocols, and encryption for impact; that documented pattern is included here as sector/technique context only and is NOT a confirmed attribution for the Kootenai County intrusion, which remains unclaimed and unattributed. This record should be distinguished from the unrelated 2024 Kootenai Health (medical center) ransomware breach attributed to the 3AM ransomware gang, which affected roughly 464,000 patients and involved a different victim organization and a different Idaho county-region entity.

## MITRE ATT&CK

- T1133 External Remote Services
- T1566 Phishing
- T1078 Valid Accounts
- T1574 Hijack Execution Flow
- T1218 System Binary Proxy Execution
- T1547 Boot or Logon Autostart Execution
- T1134 Access Token Manipulation
- T1546 Event Triggered Execution
- T1685 Disable or Modify Tools
- T1548 Abuse Elevation Control Mechanism
- T1070 Indicator Removal
- T1003 OS Credential Dumping
- T1082 System Information Discovery
- T1057 Process Discovery
- T1083 File and Directory Discovery
- T1560 Archive Collected Data
- T1105 Ingress Tool Transfer
- T1048 Exfiltration Over Alternative Protocol
- T1490 Inhibit System Recovery
- T1486 Data Encrypted for Impact

## Sources

- [ID: Kootenai County notifies residents of data breach](https://databreaches.net/2026/07/22/id-kootenai-county-notifies-residents-of-data-breach/)
- [Kootenai County notifies residents of data breach](https://www.kxly.com/news/kootenai-county-notifies-residents-of-data-breach/article_db1bc5e9-176a-4e3a-ae3e-5e4f59f33992.html)
- [Kootenai County notifies residents after March ransomware breach exposed data](https://www.prismnews.com/local/kootenai-id/kootenai-county-notifies-residents-after-march-ransomware)
- [Idaho Code § 28-51-105 - Disclosure of Breach of Security of Computerized Personal Information](https://legislature.idaho.gov/statutesrules/idstat/title28/t28ch51/sect28-51-105/)
- [#StopRansomware: Phobos Ransomware (AA24-060A)](https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060a)
- [Response to CISA Advisory (AA24-060A) - Phobos Ransomware MITRE ATT&CK Mapping](https://www.attackiq.com/2024/03/01/response-to-cisa-advisory-aa24-060a/)
- [Idaho county government hacked by ransomware, personal info breached (Gooding County)](https://www.comparitech.com/news/idaho-county-government-hacked-by-ransomware-personal-info-breached/)
- [Twin Falls County, Idaho, Confirms Ransomware Attack](https://www.govtech.com/security/twin-falls-county-idaho-confirms-ransomware-attack)
- [3AM ransomware stole data of 464,000 Kootenai Health patients (unrelated 2024 incident, distinct entity)](https://www.bleepingcomputer.com/news/security/3am-ransomware-stole-data-of-464-000-kootenai-health-patients/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1640
