Otter Tail County, Minnesota Data Breach

Alleged

Ransomware claim involving Otter Tail County, Minnesota.

Published: Aug 17, 2026 INC Ransom
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Otter Tail County, Minnesota
Industry
Government & Defense
Threat Actor
INC Ransom
Date of Incident
Aug 17, 2026

Executive Summary

On August 17, 2026, Otter Tail County, Minnesota, a governmental entity serving approximately 60,000 residents in west-central Minnesota, was listed on the dark web portal of the INC Ransom ransomware group. This listing was identified through SOCRadar’s Dark Web Monitoring service. The county is responsible for crucial public services including public health, social services, law enforcement support, and infrastructure administration, making it a potentially valuable target for ransomware operators seeking to leverage the disruption of essential services. In the 60 days preceding this listing, INC Ransom claimed 37 other victims, indicating a high operational tempo. The group predominantly targets sectors such as Professional Services, Healthcare, and Government & Defense, with a strong focus on victims located in the United States, Canada, and Australia. Previous victims include Lansing Urgent Care, Stuart & Associates Commercial Flooring Inc., Diabetes and Metabolism Specialists, and Greater Austin Merchants Cooperative Association. County governments, by their nature, manage sensitive resident data and maintain continuity obligations for public services, providing ransomware groups like INC Ransom with significant leverage for negotiations.

Technical Analysis

SOCRadar’s telemetry returned no stealer-log records specifically for the domain ottertailcounty[.]gov. However, it is important to note that government entities often utilize complex, multi-domain architectures and shared identity infrastructure. Therefore, the absence of records for this specific domain does not definitively rule out the compromise of credentials. Exposed credentials may exist within adjacent data slices, associated with alternate government domains, or linked to employee personal email aliases. The INC Ransom group is known to obtain initial access through infostealer logs and by leveraging initial access brokers (IABs) who validate credentials against government portals and VPN gateways before deploying ransomware. Consequently, a critical step for Otter Tail County would be to audit authentication logs for all external-facing portals and VPN gateways. Particular attention should be paid to anomalous access activity occurring from mid-2026. Additionally, proactive credential resets for any accounts with publicly exposed email addresses are recommended.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.