MINNEAPOLIMEDIA NEWS | Winona County Paid $128,539 Ransom After Cyberattack, Then Was Attacked Again Three Months Later
About $78,000 of the January payment came from county levy money as Minnesota governments face increasingly sophisticated cyber threats
WINONA, MN (September 7, 2026). Winona County paid cybercriminals $128,539 after a January ransomware attack disrupted its computer systems, only to be struck by a different cyberattack approximately three months later.
The disclosures provide another example of the financial and operational risks facing Minnesota local governments as ransomware groups increasingly target public-sector networks.
Winona County Administrator Maureen Holte said the county negotiated the January payment after consulting cybersecurity professionals.
Approximately $50,000 of the ransom was covered by insurance.
The remaining roughly $78,000 came from county levy money, meaning local taxpayer-supported funds ultimately covered a substantial share of the payment.
County emergency services continued operating during both incidents, but other government functions were interrupted. Some employees temporarily returned to paper-based processes while technology systems were unavailable.
County officials said the January ransom was paid in an effort to restore services and protect personal information held by the county.
Then came another attack in April.
Officials believe different cybercriminals were responsible for the second incident.
The January attack remains part of an active criminal investigation. Winona County says people whose information was affected by that incident have been notified.
The April incident remains under review, and officials have not yet determined how many people may have been affected.
A GROWING MINNESOTA GOVERNMENT PROBLEM
The Winona attacks are not isolated.
Minnesota's 2025 Cybersecurity Incident Report recorded 269 reports of possible cybersecurity incidents involving public entities and government contractors.
Rochester Public Schools suffered a major cyberattack in 2023.
Saint Paul experienced a severe ransomware attack in 2025 that forced portions of the city's computer network offline and prompted state assistance, including involvement by the Minnesota National Guard.
The pattern illustrates why local government systems can be attractive targets.
Counties and cities hold large volumes of sensitive information while simultaneously operating systems that must remain accessible to employees, residents, outside agencies, vendors and contractors.
Minnesota Chief Information Officer John Israel has warned that attackers need to find only one exploitable weakness while government cybersecurity teams must defend every potential access point.
Cybercriminals have also changed tactics.
Older ransomware attacks often concentrated on encrypting computer systems and demanding payment for their release.
Increasingly, attackers first steal information and then encrypt systems, allowing them to threaten victims with both prolonged shutdowns and publication of sensitive data.
That approach is commonly described as double extortion.
WHY THE RANSOM PAYMENT MATTERS
Governments facing ransomware attacks confront an uncomfortable calculation.
Refusing to pay can extend disruptions, increase recovery costs and potentially expose stolen information.
Paying can restore operations more quickly in some cases, but it also directs public or insurance money to criminal organizations and cannot guarantee that stolen information will actually be destroyed.
In Winona County's case, the fact that another attack occurred only months later makes cybersecurity improvements and accountability especially important.
The second attack does not by itself prove that the county failed to correct the weakness used in January. Officials have said different cybercriminals were responsible, and the April investigation remains incomplete.
WHAT HAPPENS NEXT
Winona County says it is continuing to strengthen its defenses.
The January criminal investigation remains open.
Officials are still assessing the April attack, including the number of people whose information may have been exposed.
For taxpayers, the unanswered questions include the full cost of recovery beyond the ransom itself, whether additional insurance claims were made, what security improvements have been implemented and whether the county will face further costs related to notification, monitoring or system replacement.

STAY CONNECTED TO MINNEAPOLIMEDIA
Local stories matter. Subscribe free to MinneapoliMedia and receive independent news, community reporting and important updates from Minneapolis, the North Metro and communities across Minnesota.
SUBSCRIBE FREE: https://minneapolimedia.town.news/subscribe
MinneapoliMedia | Community. Culture. Civic Life