Winona County, Minnesota Pays $128,539.57 Ransom After January 2026 Ransomware Attack With Data Theft — Threadlinqs Intelligence
As of 2026-08-29, Winona County, Minnesota Pays $128,539.57 Ransom After January 2026 Ransomware Attack With Data Theft is a high-severity ransomware threat attributed to Interlock (self-claimed for the April 2026 wave only, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 16 indicators of compromise.
Threat ID: TL-2026-2229 · Severity: HIGH · Status: RESOLVED · Category: RANSOMWARE
Attribution: Interlock (self-claimed for the April 2026 wave only · FINANCIAL
Winona County, Minnesota detected a ransomware attack on January 22, 2026, confirmed a four-day (January 18-22) data-theft window, and paid $128,539.57 to resolve it with insurance assistance; a
On January 22, 2026, Winona County, Minnesota (population ~50,000) detected a ransomware intrusion on its government network. Third-party forensic investigators, engaged alongside the FBI and state agencies, determined that unauthorized actors had access to the network for a four-day window from January 18 to January 22, 2026, during which data was exfiltrated. After consulting its cybersecurity team, the county negotiated and paid a ransom of $128,539.57 (approximately $50,000 covered by its insurance carrier, the remainder paid directly by the county) to restore services and protect personal information. The forensic review was not completed until April 16, 2026, and the county did not begin mailing written breach notifications to affected individuals until May 12, 2026 -- nearly four months after detection. Compromised data categories confirmed in the county's official notice include full name, address, Social Security number, driver's license or state identification card number, medical information, information contained in law enforcement reports, financial account information, and a 'PMI Number'; for a limited subset of individuals, payment card data (including CVV/expiration) and online account credentials were also exposed. No ransomware group, malware family, initial-access vector, or technical indicator was ever attributed to this January intrusion in the sourced coverage, and the county has stated it was carried out by different cybercriminals than the group behind the April incident.
A second, separate ransomware attack struck Winona County's network on April 7, 2026 and continued into April 8, significantly impairing the county's ability to deliver municipal services (911, fire, and emergency medical response were not interrupted). The county took affected systems -- including vital statistics and Department of Motor Vehicles systems -- offline and declared a local state of emergency. On April 8, 2026, Minnesota Governor Tim Walz signed an executive order activating a Minnesota National Guard cyber protection team (reported at roughly 15 personnel) to assist recovery, citing an incident whose 'scale and complexity... exceeded both internal and commercial response capabilities.' The county coordinated with Minnesota IT Services, the Minnesota Bureau of Criminal Apprehension, the League of Minnesota Cities, and the FBI. Public-facing systems were restored in phases, reaching near-full operation by April 25, 2026. On April 29-30, 2026, the Interlock ransomware group posted Winona County to its Tor-based data-leak site, claiming to have stolen more than two million files -- described as resident records, tax and budget documents, police records, and data from other county-affiliated institutions -- and publishing sample document images as proof. Ransomware-tracking service ransomware.live logged the posting on May 1, 2026 (10:51 UTC). As of the August 28, 2026 public reporting that prompted this record, Winona County had not confirmed Interlock's specific claim and was still reviewing which individuals' data was affected by the April incident; a class-action investigation into the county's data-security practices was also opened by a plaintiffs' law firm following the January breach notifications.
Interlock is a double-extortion ransomware operation, active since approximately September 2024, that was the subject of a joint CISA/FBI/HHS/MS-ISAC #StopRansomware advisory (AA25-203A, July 22, 2025) covering its targeting of North American and European organizations, including government and healthcare-sector victims. Interlock's documented initial-access methods include drive-by compromise from compromised legitimate websites and malware disguised as browser or security-tool updates (e.g., filenames mimicking FortiClient, GlobalProtect, or Cisco Secure Client installers), as well as the ClickFix social-engineering technique -- a fake CAPTCHA that tricks a user into pasting a base64-encoded PowerShell command into the W
Target sectors: government administration, state and local government, public sector
Target regions: North America, united states of america, Minnesota
Timeline
- Unauthorized actors gain access to Winona County's network, beginning a four-day intrusion and data-theft window later confirmed by third-party forensic investigators.
- Winona County detects the ransomware attack, ends the unauthorized-access window, and engages third-party forensic experts, the FBI, and state agencies; the county subsequently negotiates and pays a $128,539.57 ransom (about $50,000 covered by its insurance carrier) to restore services and protect personal information.
- A second, separate ransomware attack is detected on Winona County's network, taking vital statistics, DMV, and other public-facing systems offline and significantly impairing municipal services; the county declares a local state of emergency.
- Minnesota Governor Tim Walz signs an executive order activating a Minnesota National Guard cyber protection team (~15 personnel) to assist Winona County's recovery, citing incident scale and complexity that exceeded internal and commercial response capabilities.
- Winona County's forensic review of files affected by the January intrusion is completed, confirming the categories of compromised personal data.
- Winona County restores affected public-facing systems in phases, reaching near-full operations by April 25, 2026.
- The Interlock ransomware group posts Winona County to its Tor-based leak site, claiming theft of more than two million files (resident records, tax and budget documents, police records) and publishing sample document images as proof.
- Ransomware-tracking service ransomware.live logs the Interlock posting for Winona County; the county has not independently confirmed the group's specific claim.
- Winona County begins mailing written breach-notification letters to individuals affected by the January incident, nearly four months after detection.
- A plaintiffs' law firm (Dapeer Law) opens an investigation into a potential class action against Winona County on behalf of residents and employees whose personal information was exposed.
- DataBreaches.net and regional outlets report the $128,539.57 January ransom payment in detail; Winona County confirms its review of the April incident's affected individuals is still ongoing.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 16 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1204.004, T1059.001, T1547.001, T1078, T1036.005, T1218.011, T1555.003, T1558.003, T1056.001, T1082