MalwareRansomwareData ExfiltratedData EncryptedRansom DemandedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumActive
Winona County
bd_d0844e449554c09f · schema v1 · pii pii-v1
Full breach record for Winona County →Winona County, Minnesota, notified the New Hampshire Attorney General of a ransomware incident. Unauthorized access occurred between January 18 and January 22, 2026. The attack resulted in the exfiltration of names and Social Security numbers of one New Hampshire resident. The County detected the ransomware on January 22, 2026, engaged forensic consultants, notified the FBI, and restored its network. Notification to the affected individual was sent on May 12, 2026.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_b4a4ad03d964689fLeak Siteinterlockfiled 2026-05-01(17d gap)Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/winona-county-minnesota-20260518.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 18, 2026
- Raw hash
- 4f9707209ee47dffe5b2147776c365c6e87af448e739f11fb86c3c8bf3a38e1b
Reporting entity
- Name
- Winona Countynorm: winona county
- Domain
- winonacounty.gov
Victim entity
- Name
- Winona Countynorm: winona county
- Domain
- winonacounty.gov
Incident
- Discovered
- Jan 22, 2026
- Materiality determined
- —
- Notification sent
- May 12, 2026
- Affected individuals
- 1
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- notified the FBI and appropriate Minnesota state agenciesproviding notice to all appropriate state regulators regarding this incident
Compliance
- Time to disclose
- 17 weeks(116 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.