What's Happening?
Winona County, Minnesota, negotiated and paid a ransom of $128,539 following a cyberattack on its IT network in January. The payment was made to restore county services and protect personal information, with approximately $50,000 covered by insurance
and the remaining $78,000 from county levy money. Despite these efforts, the county was attacked again in April by different cybercriminals. Both ransomware incidents forced Winona County to temporarily halt some operations, resorting to manual processes. According to the state’s 2025 Cybersecurity Incident Report, attacks against government entities in Minnesota are increasing in frequency and sophistication, with 269 public entities reporting possible cybersecurity incidents last year.
Why It's Important?
This incident highlights the growing vulnerability of local government entities to sophisticated cyberattacks and the difficult decisions they face when confronted with ransomware. Paying a ransom, even partially covered by insurance, diverts public funds and may inadvertently encourage further attacks. The fact that Winona County was attacked a second time by different actors underscores the persistent threat and the potential for entities to be targeted repeatedly. Such attacks disrupt essential public services, compromise sensitive data, and erode public trust. The rising trend of cyberattacks on government infrastructure across Minnesota indicates a systemic challenge that requires robust cybersecurity investments and strategies to protect critical public services and citizen data.
What's Next?
Winona County is currently engaged in an active criminal investigation regarding the January cyberattack and has notified all affected individuals. The April attack is still under review, with the full extent of its impact yet to be determined. The county remains committed to strengthening its cyber defenses to prevent future incidents. State and local governments across Minnesota will likely continue to assess and enhance their cybersecurity measures, potentially leading to increased funding for IT security, improved employee training, and more resilient backup systems. Collaboration with state cybersecurity agencies and federal partners will be crucial in combating these evolving threats.
Beyond the Headlines
The double cyberattack on Winona County reveals a critical shift in cybercriminal tactics, moving beyond simple encryption to 'double extortion' where data is also stolen and threatened with release. This evolution makes ransomware attacks even more damaging and complex to resolve. The perpetrators are often financially motivated, overseas groups, indicating a global dimension to these local threats. The vulnerability of government systems, often connected to external partners and designed for public accessibility, creates numerous entry points for attackers. This situation underscores the urgent need for a comprehensive national strategy to protect critical infrastructure, including local government networks, from increasingly sophisticated and persistent cyber threats.











