Winona County paid $128K ransom after cyberattack; then was attacked again

Go Deeper.
Create an account or log in to save stories.
Like this?
Thanks for liking this story! We have added it to a list of your favorite stories.
Winona County negotiated and paid a $128,539 ransom following a January cyberattack on its IT network, mere months before they were attacked yet again in April by different cybercriminals.
Though emergency services were never paused, Winona County administrator Maureen Holte said that both ransomware incidents forced the county to pause some of its operations, and they had to, in some situations, go back to the old-fashioned way of doing things: pen and paper.
After the January attack, Holte said the county agreed to pay the ransom amount to ensure all county services could resume and that the personal information of those in town would be protected.
“It was after careful consideration and also guidance from our cybersecurity team,” Holte said. “Winona County negotiated and paid a fee of approximately $128,000. About $50,000 was covered by insurance, and about 78,000 was out of county levy money.”
Turn Up Your Support
MPR News helps you turn down the noise and build shared understanding. Turn up your support for this public resource and keep trusted journalism accessible to all.
According to the state’s 2025 Cybersecurity Incident Report, attacks against federal, state, and local governments are rising in frequency and sophistication. The report indicates that 269 public entities and government contractors in Minnesota reported possible cybersecurity incidents last year.
Rochester Public Schools was targeted by a cyberattack in 2023, and just last summer, the city of St. Paul experienced a massive ransomware incident that, like Winona County, required assistance from National Guard deployment and forced the city to shutter parts of its network.
Government entities aren’t the only ones experiencing these incidents, but Israel said state and local governments have become lucrative targets. And they tend to be more vulnerable because government entities’ systems often are connected to outside partners and contractors, and they’re focused on being open and accessible to the public to provide essential services, leaving more cracks and openings for cybercriminals to exploit.
“This just comes with the nature of government,” said John Israel, the state of Minnesota’s chief information officer. “Threat actors are really good about finding those holes and finding those ways in. [Governments have] got to be right 100 percent of the time, whereas bad actors really have to just be right one time to get in and cause impact.”

Israel said that, in the past, criminal agents were more focused on breaking into an organization's system, locking it down, and charging ransoms to unlock the files. But as more organizations have gotten better at backing up their systems, cyber attackers have evolved.
Now, they are not only encrypting and locking down systems, they’re also extracting and stealing data first that they can hold hostage — threatening to release it if the organization doesn’t pay the ransom.
“We call it kind of a double extortion event,” Israel said.
Israel explained that the cybercriminals who launch these attacks are primarily financially motivated and rarely local. The perpetrators are often part of overseas groups that have made a business out of extorting entities like Winona County.
What is the status of the Winona attacks currently?
Holte said the county is still in the midst of an active, open criminal investigation in regards to the January incident, but at this point the county has given notice to all affected individuals.
The April attack is still under review, and Holte said it’s not yet clear how many people were impacted.
“Winona County remains committed to strengthening our systems to ensure that our cyber defenses are the best that they can be, so that we don't have future incidents,” Holte said.
