Winona County, Minnesota Pays $128,539.57 Ransom After January 2026 Ransomware Attack With Data Theft

Winona County, Minnesota Pays $128,539.57 Ransom After (TL-2026-2229) is a high-severity ransomware operation, first published 2026-08-28. It is attributed to Interlock with low confidence, affects Winona County, Minnesota (local government) County government network, maps to 13 MITRE ATT&CK techniques (T1021.001, T1036.005, T1048), and is covered by 9 detection rules and 16 indicators of compromise.

Key facts for TL-2026-2229

Threat ID
TL-2026-2229
Severity
HIGH
Status
RESOLVED
Category
RANSOMWARE
First published
2026-08-28
Last reviewed
2026-08-28
Attribution
Interlock
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
government administration, state and local government, public sector
Target regions
North America, united states of america, Minnesota
Detection rules
9
Indicators of compromise
16

Malware and tooling in Winona County, Minnesota Pays $128,539.57 Ransom After

Malware and tooling: AnyDesk, Berserk Stealer, Cobalt Strike, Lumma Stealer - S1213, NodeSnake RAT, SystemBC - S9001, interlock, AnyDesk, AzCopy, Azure Storage Explorer, Cobalt Strike, PuTTY

Winona County, Minnesota detected a ransomware attack on January 22, 2026, confirmed a four-day (January 18-22) data-theft window, and paid $128,539.57 to resolve it with insurance assistance; a second, separate ransomware attack hit the county's network on April 7, 2026, prompting a state of emergency and Minnesota National Guard cyber-response activation, and was later self-claimed by the Interlock ransomware group on its leak site.

How Winona County, Minnesota Pays $128,539.57 Ransom After works

On January 22, 2026, Winona County, Minnesota (population ~50,000) detected a ransomware intrusion on its government network. Third-party forensic investigators, engaged alongside the FBI and state agencies, determined that unauthorized actors had access to the network for a four-day window from January 18 to January 22, 2026, during which data was exfiltrated. After consulting its cybersecurity team, the county negotiated and paid a ransom of $128,539.57 (approximately $50,000 covered by its insurance carrier, the remainder paid directly by the county) to restore services and protect personal information. The forensic review was not completed until April 16, 2026, and the county did not begin mailing written breach notifications to affected individuals until May 12, 2026 -- nearly four months after detection. Compromised data categories confirmed in the county's official notice include full name, address, Social Security number, driver's license or state identification card number, medical information, information contained in law enforcement reports, financial account information, and a 'PMI Number'; for a limited subset of individuals, payment card data (including CVV/expiration) and online account credentials were also exposed. No ransomware group, malware family, initial-access vector, or technical indicator was ever attributed to this January intrusion in the sourced coverage, and the county has stated it was carried out by different cybercriminals than the group behind the April incident.

A second, separate ransomware attack struck Winona County's network on April 7, 2026 and continued into April 8, significantly impairing the county's ability to deliver municipal services (911, fire, and emergency medical response were not interrupted). The county took affected systems -- including vital statistics and Department of Motor Vehicles systems -- offline and declared a local state of emergency. On April 8, 2026, Minnesota Governor Tim Walz signed an executive order activating a Minnesota National Guard cyber protection team (reported at roughly 15 personnel) to assist recovery, citing an incident whose 'scale and complexity... exceeded both internal and commercial response capabilities.' The county coordinated with Minnesota IT Services, the Minnesota Bureau of Criminal Apprehension, the League of Minnesota Cities, and the FBI. Public-facing systems were restored in phases, reaching near-full operation by April 25, 2026. On April 29-30, 2026, the Interlock ransomware group posted Winona County to its Tor-based data-leak site, claiming to have stolen more than two million files -- described as resident records, tax and budget documents, police records, and data from other county-affiliated institutions -- and publishing sample document images as proof. Ransomware-tracking service ransomware.live logged the posting on May 1, 2026 (10:51 UTC). As of the August 28, 2026 public reporting that prompted this record, Winona County had not confirmed Interlock's specific claim and was still reviewing which individuals' data was affected by the April incident; a class-action investigation into the county's data-security practices was also opened by a plaintiffs' law firm following the January breach notifications.

Interlock is a double-extortion ransomware operation, active since approximately September 2024, that was the subject of a joint CISA/FBI/HHS/MS-ISAC #StopRansomware advisory (AA25-203A, July 22, 2025) covering its targeting of North American and European organizations, including government and healthcare-sector victims. Interlock's documented initial-access methods include drive-by compromise from compromised legitimate websites and malware disguised as browser or security-tool updates (e.g., filenames mimicking FortiClient, GlobalProtect, or Cisco Secure Client installers), as well as the ClickFix social-engineering technique -- a fake CAPTCHA that tricks a user into pasting a base64-encoded PowerShell command into the Windows Run dialog -- and a newer PHP-based FileFix variant. Because Winona County has not independently confirmed the Interlock claim for the April incident and no victim-specific technical indicators have been published, the MITRE ATT&CK techniques mapped below reflect Interlock's documented, advisory-confirmed operational playbook rather than forensic artifacts recovered from Winona County's own network.

MITRE ATT&CK techniques used in TL-2026-2229

Lateral Movement

T1021.001 Remote Services: Remote Desktop Protocol

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location; T1218.011 System Binary Proxy Execution: Rundll32

Exfiltration

T1048 Exfiltration Over Alternative Protocol; T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage

Credential Access

T1056.001 Input Capture: Keylogging; T1555.003 Credentials from Web Browsers; T1558.003 Steal or Forge Kerberos Tickets: Kerberoasting

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1204.004 User Execution: Malicious Copy and Paste

Persistence

T1078 Valid Accounts; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Discovery

T1082 System Information Discovery

Affected products and versions in Winona County, Minnesota Pays $128,539.57 Ransom After

  • Winona County, Minnesota (local government) — County government network, including vital statistics/records systems, Department of Motor Vehicles systems, law-enforcement records systems, and financial systems
    Vulnerable versions: N/A - government IT infrastructure, not a versioned software product
    Fixed in: N/A

Remediation for Winona County, Minnesota Pays $128,539.57 Ransom After

Patches

  • No vendor patch applies -- Interlock's documented initial access (CISA AA25-203A) is social-engineering and drive-by based (ClickFix/FileFix), not tied to a specific CVE

Immediate actions

  • Isolate and take affected network segments offline immediately upon detecting ransomware activity, as Winona County did for both the January and April incidents
  • Engage third-party forensic incident responders and notify the FBI and state law enforcement immediately upon detection
  • Reset domain and local credentials for any account with exposure to compromised hosts, given Interlock's documented browser-credential-theft and Kerberoasting techniques
  • Request state or National Guard cyber-incident support when incident scale exceeds internal and commercial response capacity, as Winona County did via Governor Walz's April 8, 2026 executive order

Workarounds

  • Disable or restrict the Windows Run dialog for standard users to blunt ClickFix-style code execution
  • Apply Group Policy hardening to prevent unauthorized GPO pushes, which Interlock has used to deliver its ransom note

Longer-term hardening

  • Deploy phishing-resistant MFA on all remote-access and domain accounts to blunt Valid Accounts (T1078) and RDP (T1021.001) abuse
  • Restrict user-initiated Windows Run-dialog and PowerShell execution via application control and constrained language mode to mitigate ClickFix/FileFix-style initial access
  • Restrict legitimate remote-access tools (AnyDesk, PuTTY) and cloud-sync utilities (AzCopy, WinSCP, Azure Storage Explorer) to authorized administrative use and alert on unexpected installs
  • Maintain offline, immutable backups of vital records, DMV, and law-enforcement data stores to enable recovery without paying a ransom
  • Segment county department networks (vital records, DMV, law enforcement, finance) to limit lateral spread of a single ransomware intrusion

Timeline of Winona County, Minnesota Pays $128,539.57 Ransom After

  • Unauthorized actors gain access to Winona County's network, beginning a four-day intrusion and data-theft window later confirmed by third-party forensic investigators.
  • Winona County detects the ransomware attack, ends the unauthorized-access window, and engages third-party forensic experts, the FBI, and state agencies; the county subsequently negotiates and pays a $128,539.57 ransom (about $50,000 covered by its insurance carrier) to restore services and protect personal information.
  • A second, separate ransomware attack is detected on Winona County's network, taking vital statistics, DMV, and other public-facing systems offline and significantly impairing municipal services; the county declares a local state of emergency.
  • Minnesota Governor Tim Walz signs an executive order activating a Minnesota National Guard cyber protection team (~15 personnel) to assist Winona County's recovery, citing incident scale and complexity that exceeded internal and commercial response capabilities.
  • Winona County's forensic review of files affected by the January intrusion is completed, confirming the categories of compromised personal data.
  • Winona County restores affected public-facing systems in phases, reaching near-full operations by April 25, 2026.
  • The Interlock ransomware group posts Winona County to its Tor-based leak site, claiming theft of more than two million files (resident records, tax and budget documents, police records) and publishing sample document images as proof.
  • Ransomware-tracking service ransomware.live logs the Interlock posting for Winona County; the county has not independently confirmed the group's specific claim.
  • A plaintiffs' law firm (Dapeer Law) opens an investigation into a potential class action against Winona County on behalf of residents and employees whose personal information was exposed.
  • Winona County begins mailing written breach-notification letters to individuals affected by the January incident, nearly four months after detection.
  • DataBreaches.net and regional outlets report the $128,539.57 January ransom payment in detail; Winona County confirms its review of the April incident's affected individuals is still ongoing.

Sources cited for Winona County, Minnesota Pays $128,539.57 Ransom After

More in ransomware

Detection coverage for TL-2026-2229

As of 2026-08-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2229 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats