Ransomware hackers relaunch attacks within Three Months

Winona County in Minnesota has fallen victim to two separate ransomware attacks within just three months, raising serious concerns about the county’s cybersecurity preparedness and the growing persistence of ransomware groups. More concerning is the possibility that criminals received ransom payments following both incidents—an outcome that could potentially encourage attackers to target the county or other public-sector organizations again.

The county, located in Minnesota, has managed to recover from both cyber incidents and restore its essential digital services. However, the repeated attacks demonstrate that recovering from a ransomware incident is not enough. Organizations must also identify and eliminate the vulnerabilities that allowed attackers to gain access in the first place. Otherwise, the same weaknesses can become an open door for future attacks.

The first ransomware incident was detected in January 2026, when county officials noticed unusual activity across the network along with disruptions to several systems. After investigating the incident and consulting cybersecurity experts, the county negotiated with the ransomware group. Its insurance carrier was also involved in the response process. Ultimately, county officials reportedly paid $128,539.57 in Bitcoin to the attackers to help restore access to affected systems.

While paying a ransom can sometimes help organizations regain access to critical systems more quickly, it does not guarantee that attackers will stay away. In fact, it can make an organization appear to be a profitable target.

That concern became reality on April 6, 2026, when Winona County was reportedly hit by another ransomware attack, possibly involving a different cybercriminal group. The second incident caused significant disruption to digital services and resulted in the compromise of a portion of the county’s data. The severity of the disruption prompted Minnesota Governor Tim Walz to issue an emergency declaration as officials worked to contain the incident and restore services.

One of the biggest questions surrounding the second attack is whether the vulnerabilities exploited during the January incident were properly addressed. If security weaknesses identified during the first attack were left unpatched or inadequately secured, attackers may have had an opportunity to exploit the same or related vulnerabilities again. Reports suggesting that the two criminal groups may have been connected make the situation even more concerning.

The Winona County incidents highlight an important lesson for governments and other organizations:

1.) Cybersecurity cannot stop once systems are restored.

2.) Following a ransomware attack, organizations need to conduct a thorough forensic investigation, patch vulnerabilities, strengthen access controls, reset compromised credentials, improve network monitoring, and continuously test their defenses.

The threat is not limited to county governments. Critical infrastructure has also increasingly become a target for sophisticated cybercriminals and state-linked actors. Nearly 40 servers associated with Minnesota water systems were reportedly targeted in attacks linked to Iran. Had officials failed to detect and respond to the activity in time, the consequences could have been far more serious.

These incidents demonstrate how ransomware and other cyberattacks can quickly move beyond financial losses and become threats to essential public services. For government agencies, the priority should therefore be not only recovering from an attack but ensuring that the same attackers—or others using the same weaknesses—cannot simply return.

Join our LinkedIn group Information Security Community!

Naveen Goud
Naveen Goud is a writer at Cybersecurity Insiders covering topics such as Mergers & Acquisitions, Startups, Cyber Attacks, Cloud Security and Mobile Security

No posts to display