Winona County Paid $128,000 to Ransomware Hackers,  Eleven Weeks Later, a Different Gang Hit It Again

Winona County, Minnesota, did what a lot of security advisors tell victims not to do: it paid. In January, ransomware locked up the county government’s systems, and officials negotiated a $128,539.57 payment to get back online. Eleven weeks later, a second, unrelated gang broke in and stole more than two million files. The payment bought the county nothing but a shorter list of options the second time around.

What happened

County staff detected ransomware on Winona County’s network on January 22, 2026. The attack forced government offices back onto pen and paper while the county’s IT team, outside forensic investigators, and federal law enforcement worked the case. County Administrator Maureen Holte later said the decision to pay came “after careful consideration and also guidance from our cybersecurity team.” The county’s insurance carrier covered about $50,000 of the payment; the remaining roughly $78,000 came out of county levy funds, according to local reporting from MPR News and the Winona Post. The identity of the January attacker has never been publicly disclosed.

The breach exposed names, addresses, Social Security numbers, driver’s license numbers, medical details, law enforcement records, and financial and payment card information for an undisclosed number of residents and employees. Affected individuals were not notified until May 12, 2026, nearly four months after the intrusion was first detected.

Then, on April 7, a second ransomware attack hit the county, this one confirmed by officials to be the work of a different criminal group entirely. Minnesota Governor Tim Walz issued an executive order the next day authorizing the state’s National Guard to deploy a specialized cybersecurity and recovery team, saying the incident’s “scale and complexity” had exceeded both the county’s internal capacity and what commercial responders could handle. On April 29, the Interlock ransomware gang claimed credit on its dark-web leak site, posting sample documents and asserting it had taken more than two million files. Emergency services and 911 dispatch stayed operational through both attacks, but most other county functions were interrupted. It wasn’t until late August, seven months after the first breach, that the county’s actual ransom figure and the reasoning behind it became public.

Why this keeps happening

Interlock isn’t an obscure name. The FBI and the Cybersecurity and Infrastructure Security Agency named the group in a joint advisory in July 2025, warning that it was actively targeting critical infrastructure and healthcare organizations across North America and Europe using double-extortion tactics: encrypt the network, steal the data, then threaten to publish it unless paid. County officials said the security improvements made after the January attack helped them detect and contain the April intrusion faster. That’s a real, measurable benefit. It just wasn’t enough to stop a second group from getting in.

Paying a ransom buys a decryption key and, in theory, a promise the stolen data won’t be published. It does not buy immunity from the next attacker, and it does nothing to fix the underlying access gaps that let the first one in. CISA has said for years that payment doesn’t guarantee data will be deleted or systems fully restored, and that ransom payments fund the infrastructure behind future attacks. Winona County’s second breach is a fairly stark illustration of that argument: a completely separate criminal enterprise found the same target, months apart, and neither the payment nor the publicity around it appears to have deterred them.

Only two states, Florida and North Carolina, currently prohibit public entities from paying ransomware demands outright. Minnesota isn’t one of them, and Winona County’s insurance carrier had every financial incentive to help settle quickly rather than absorb a longer outage. Sophos’s 2026 State of Ransomware report found that 48% of organizations whose data was encrypted still chose to pay, roughly in line with the past four years. Paying remains the norm, not the exception, even as the evidence that it solves the underlying problem stays thin.

Context and Implications

My take is that Winona County’s real failure wasn’t the decision to pay in January. Faced with paralyzed government services and no guarantee that refusing would end better, that’s a defensible short-term call. The failure is that a rural county government was carrying the kind of exposed, under-segmented network that let two unrelated ransomware crews walk through the same door within three months, and that it took until late summer for residents to learn what happened and what it cost them. Insurance-backed ransom payments have become a substitute for the harder, more expensive work of network segmentation, credential hygiene, and faster breach disclosure, and smaller local governments are the ones paying the price for that shortcut, sometimes twice.

Local governments are not going to out-negotiate ransomware gangs, and no single county can outspend a criminal ecosystem that treats them as a repeatable business model. What they can control is how fast they detect an intrusion, how quickly they tell residents what was taken, and whether the next attacker finds the same open door.

The post Winona County Paid $128,000 to Ransomware Hackers,  Eleven Weeks Later, a Different Gang Hit It Again appeared first on DataFLOQ.

Leave a Reply

Your email address will not be published. Required fields are marked *

Subscribe to our Newsletter