2026 Kootenai County (ID) — ransomware Mar 30; resident notices (SSNs, cards, some biometrics)
Data compromised
Per county notification: name, address, DOB, SSN, ITIN, driver’s license/state ID, medical information, health insurance ID, financial account/payment card information; biometric identifiers (e.g. fingerprints) for a small number of individuals. Aggregate victim count not published.
Technical writeup
Verified county disclosure — ransomware detected March 30, 2026; resident notifications reported July 22, 2026. Kootenai County, Idaho, said it detected ransomware on its computer network, secured systems, restored operations, engaged third-party forensics, and notified federal law enforcement. Investigation found cyber criminals extracted certain data. The county’s notice lists names, addresses, dates of birth, Social Security numbers, ITINs, driver’s license/state ID numbers, medical and health-insurance identifiers, and financial account/payment card information; a small number of individuals had biometric identifiers such as fingerprints. No ransomware brand was named in the public notice. BreachHistory retains recordsAffected 0 pending an attested headcount.
Root cause
Ransomware detected on county computer network March 30, 2026; cyber criminals took certain data from the network (extortion group not named in county notice)
References
- https://www.kcgov.us/CivicAlerts.aspx?AID=724
- https://databreaches.net/2026/07/22/id-kootenai-county-notifies-residents-of-data-breach/
- https://www.spokesman.com/stories/2026/jul/22/data-security-breach-in-kootenai-county/
- https://www.kxly.com/news/kootenai-county-notifies-residents-of-data-breach/article_db1bc5e9-176a-4e3a-ae3e-5e4f59f33992.html