Winona County paid more than $128,000 after two ransomware attacks earlier this year.
A statement from the county with an update on the ransomware incidents was released on Thursday.
It said that, although it was a difficult choice, the county paid $128.539, “to best serve the interests of Winona County residents and employees.”
The first attack occurred on January 22. The county brought in third-party cybersecurity experts, state agencies, and federal law enforcement to assist with the investigation. They discovered that there was a period of four days where data was taken from the county’s network.
The data, according to the county, included social security numbers, driver’s license or state ID numbers, medical information, and financial information.
In May, the county started notifying people who may have been affected by the data breach.
On April 7, Winona County had a second, unrelated ransomware attack on its network.
Their investigation into a second ransomware attack in April continues, according to the county. It involves work similar to what happened with the January attack and with the same types of organizations.
The statement said that “The Commissioners assure the citizens of Winona County that aggressive measures have been and will continue to be taken to minimize the risk of a similar event occurring again in Winona County.”
For people whose data was compromised in that attack, the county said each person’s notification letter would contain an offer of complimentary credit monitoring and related services.
The Winona County website provides information on what the public can do to monitor their data for identity theft.
RELATED: National Guard helping Winona County after cyberattack
Click Here For The Original Source.
