Winona County, Minnesota Pays $128,539.57 Ransom After January 2026 Ransomware Attack With Data Theft
Winona County, Minnesota Pays $128,539.57 Ransom After (TL-2026-2229) is a high-severity ransomware operation, first published 2026-08-28. It is attributed to Interlock with low confidence, affects Winona County, Minnesota (local government) County government network, maps to 13 MITRE ATT&CK techniques (T1021.001, T1036.005, T1048), and is covered by 9 detection rules and 16 indicators of compromise.
Key facts for TL-2026-2229
- Threat ID
- TL-2026-2229
- Severity
- HIGH
- Status
- RESOLVED
- Category
- RANSOMWARE
- First published
- 2026-08-28
- Last reviewed
- 2026-08-28
- Attribution
- Interlock
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- government administration, state and local government, public sector
- Target regions
- North America, united states of america, Minnesota
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in Winona County, Minnesota Pays $128,539.57 Ransom After
Malware and tooling: AnyDesk, Berserk Stealer, Cobalt Strike, Lumma Stealer - S1213, NodeSnake RAT, SystemBC - S9001, interlock, AnyDesk, AzCopy, Azure Storage Explorer, Cobalt Strike, PuTTY
Winona County, Minnesota detected a ransomware attack on January 22, 2026, confirmed a four-day (January 18-22) data-theft window, and paid $128,539.57 to resolve it with insurance assistance; a second, separate ransomware attack hit the county's network on April 7, 2026, prompting a state of emergency and Minnesota National Guard cyber-response activation, and was later self-claimed by the Interlock ransomware group on its leak site.
How Winona County, Minnesota Pays $128,539.57 Ransom After works
On January 22, 2026, Winona County, Minnesota (population ~50,000) detected a ransomware intrusion on its government network. Third-party forensic investigators, engaged alongside the FBI and state agencies, determined that unauthorized actors had access to the network for a four-day window from January 18 to January 22, 2026, during which data was exfiltrated. After consulting its cybersecurity team, the county negotiated and paid a ransom of $128,539.57 (approximately $50,000 covered by its insurance carrier, the remainder paid directly by the county) to restore services and protect personal information. The forensic review was not completed until April 16, 2026, and the county did not begin mailing written breach notifications to affected individuals until May 12, 2026 -- nearly four months after detection. Compromised data categories confirmed in the county's official notice include full name, address, Social Security number, driver's license or state identification card number, medical information, information contained in law enforcement reports, financial account information, and a 'PMI Number'; for a limited subset of individuals, payment card data (including CVV/expiration) and online account credentials were also exposed. No ransomware group, malware family, initial-access vector, or technical indicator was ever attributed to this January intrusion in the sourced coverage, and the county has stated it was carried out by different cybercriminals than the group behind the April incident.
A second, separate ransomware attack struck Winona County's network on April 7, 2026 and continued into April 8, significantly impairing the county's ability to deliver municipal services (911, fire, and emergency medical response were not interrupted). The county took affected systems -- including vital statistics and Department of Motor Vehicles systems -- offline and declared a local state of emergency. On April 8, 2026, Minnesota Governor Tim Walz signed an executive order activating a Minnesota National Guard cyber protection team (reported at roughly 15 personnel) to assist recovery, citing an incident whose 'scale and complexity... exceeded both internal and commercial response capabilities.' The county coordinated with Minnesota IT Services, the Minnesota Bureau of Criminal Apprehension, the League of Minnesota Cities, and the FBI. Public-facing systems were restored in phases, reaching near-full operation by April 25, 2026. On April 29-30, 2026, the Interlock ransomware group posted Winona County to its Tor-based data-leak site, claiming to have stolen more than two million files -- described as resident records, tax and budget documents, police records, and data from other county-affiliated institutions -- and publishing sample document images as proof. Ransomware-tracking service ransomware.live logged the posting on May 1, 2026 (10:51 UTC). As of the August 28, 2026 public reporting that prompted this record, Winona County had not confirmed Interlock's specific claim and was still reviewing which individuals' data was affected by the April incident; a class-action investigation into the county's data-security practices was also opened by a plaintiffs' law firm following the January breach notifications.
Interlock is a double-extortion ransomware operation, active since approximately September 2024, that was the subject of a joint CISA/FBI/HHS/MS-ISAC #StopRansomware advisory (AA25-203A, July 22, 2025) covering its targeting of North American and European organizations, including government and healthcare-sector victims. Interlock's documented initial-access methods include drive-by compromise from compromised legitimate websites and malware disguised as browser or security-tool updates (e.g., filenames mimicking FortiClient, GlobalProtect, or Cisco Secure Client installers), as well as the ClickFix social-engineering technique -- a fake CAPTCHA that tricks a user into pasting a base64-encoded PowerShell command into the Windows Run dialog -- and a newer PHP-based FileFix variant. Because Winona County has not independently confirmed the Interlock claim for the April incident and no victim-specific technical indicators have been published, the MITRE ATT&CK techniques mapped below reflect Interlock's documented, advisory-confirmed operational playbook rather than forensic artifacts recovered from Winona County's own network.
MITRE ATT&CK techniques used in TL-2026-2229
Lateral Movement
T1021.001 Remote Services: Remote Desktop Protocol
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location; T1218.011 System Binary Proxy Execution: Rundll32
Exfiltration
T1048 Exfiltration Over Alternative Protocol; T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
Credential Access
T1056.001 Input Capture: Keylogging; T1555.003 Credentials from Web Browsers; T1558.003 Steal or Forge Kerberos Tickets: Kerberoasting
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1204.004 User Execution: Malicious Copy and Paste
Persistence
T1078 Valid Accounts; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Discovery
Affected products and versions in Winona County, Minnesota Pays $128,539.57 Ransom After
- Winona County, Minnesota (local government) — County government network, including vital statistics/records systems, Department of Motor Vehicles systems, law-enforcement records systems, and financial systems
Vulnerable versions: N/A - government IT infrastructure, not a versioned software product
Fixed in: N/A
Remediation for Winona County, Minnesota Pays $128,539.57 Ransom After
Patches
- No vendor patch applies -- Interlock's documented initial access (CISA AA25-203A) is social-engineering and drive-by based (ClickFix/FileFix), not tied to a specific CVE
Immediate actions
- Isolate and take affected network segments offline immediately upon detecting ransomware activity, as Winona County did for both the January and April incidents
- Engage third-party forensic incident responders and notify the FBI and state law enforcement immediately upon detection
- Reset domain and local credentials for any account with exposure to compromised hosts, given Interlock's documented browser-credential-theft and Kerberoasting techniques
- Request state or National Guard cyber-incident support when incident scale exceeds internal and commercial response capacity, as Winona County did via Governor Walz's April 8, 2026 executive order
Workarounds
- Disable or restrict the Windows Run dialog for standard users to blunt ClickFix-style code execution
- Apply Group Policy hardening to prevent unauthorized GPO pushes, which Interlock has used to deliver its ransom note
Longer-term hardening
- Deploy phishing-resistant MFA on all remote-access and domain accounts to blunt Valid Accounts (T1078) and RDP (T1021.001) abuse
- Restrict user-initiated Windows Run-dialog and PowerShell execution via application control and constrained language mode to mitigate ClickFix/FileFix-style initial access
- Restrict legitimate remote-access tools (AnyDesk, PuTTY) and cloud-sync utilities (AzCopy, WinSCP, Azure Storage Explorer) to authorized administrative use and alert on unexpected installs
- Maintain offline, immutable backups of vital records, DMV, and law-enforcement data stores to enable recovery without paying a ransom
- Segment county department networks (vital records, DMV, law enforcement, finance) to limit lateral spread of a single ransomware intrusion
Timeline of Winona County, Minnesota Pays $128,539.57 Ransom After
- Unauthorized actors gain access to Winona County's network, beginning a four-day intrusion and data-theft window later confirmed by third-party forensic investigators.
- Winona County detects the ransomware attack, ends the unauthorized-access window, and engages third-party forensic experts, the FBI, and state agencies; the county subsequently negotiates and pays a $128,539.57 ransom (about $50,000 covered by its insurance carrier) to restore services and protect personal information.
- A second, separate ransomware attack is detected on Winona County's network, taking vital statistics, DMV, and other public-facing systems offline and significantly impairing municipal services; the county declares a local state of emergency.
- Minnesota Governor Tim Walz signs an executive order activating a Minnesota National Guard cyber protection team (~15 personnel) to assist Winona County's recovery, citing incident scale and complexity that exceeded internal and commercial response capabilities.
- Winona County's forensic review of files affected by the January intrusion is completed, confirming the categories of compromised personal data.
- Winona County restores affected public-facing systems in phases, reaching near-full operations by April 25, 2026.
- The Interlock ransomware group posts Winona County to its Tor-based leak site, claiming theft of more than two million files (resident records, tax and budget documents, police records) and publishing sample document images as proof.
- Ransomware-tracking service ransomware.live logs the Interlock posting for Winona County; the county has not independently confirmed the group's specific claim.
- A plaintiffs' law firm (Dapeer Law) opens an investigation into a potential class action against Winona County on behalf of residents and employees whose personal information was exposed.
- Winona County begins mailing written breach-notification letters to individuals affected by the January incident, nearly four months after detection.
- DataBreaches.net and regional outlets report the $128,539.57 January ransom payment in detail; Winona County confirms its review of the April incident's affected individuals is still ongoing.
Sources cited for Winona County, Minnesota Pays $128,539.57 Ransom After
- Winona County paid more than $128K following January ransomware attack
- Winona County paid more than $128K following January ransomware attack
- Winona County paid hackers $128K after back-to-back ransomware attacks in 2026, Social Security numbers may be at risk
- Winona County says it paid $128K after January ransomware attack
- Winona County hit by second ransomware attack in three months
- Notice of Data Security Incident
- Winona County, insurer paid $128K in ransom in January cyberattack
- Winona County: Hackers released personal data
- Winona County suffers 2nd cyberattack; National Guard mobilized
- Cybercriminals say they hacked Winona County, MN (again)
- Interlock Ransomware Attack on Winona County
- Ransomware.live - Victim: Winona County
- #StopRansomware: Interlock (CISA AA25-203A)
- Interlock Ransomware Analysis, Simulation, and Mitigation - CISA Alert AA25-203A
- Minnesota governor sends national guard to county after cyberattack
More in ransomware
- Vexy Ransomware Claims Quy Nhon University (Vietnam) — New Group, 50GB Exfiltrated
- Ransomware Attack Disrupts IT Systems and Services in Ellis County, Kansas
- KRSID Ransomware Distributed via Fraudulent "UBP Asset" Home Trading System (HTS) Software
- Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observed
- Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker, Qilin, INC Ransom, Lynx) Abuse Dual-Use Tools and Exploit SonicWall, Gladinet CentreStack, and FortiGate Devices
Detection coverage for TL-2026-2229
As of 2026-08-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2229 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.