The county discovered that one of their own email accounts was sending phishing emails to members of the public.

 

What happened

Aitkin County Health and Human Services (Aitkin HHS), which provides public health and social services in Minnesota, recently notified the public of a data breach connected to a phishing incident beginning in one of their employee’s email accounts.

According to the notice, beginning on June 17th, 2026, the county began sending notifications to impacted individuals. In their report to the US Department of Health and Human Services, Aitkin said 83,114 individuals were impacted.

 

Going deeper

The breach itself began on April 7th, 2026, and continued until the next day, April 8th. That same day, Aitkin HHS discovered that an employee’s email account was sending phishing emails. An investigation determined that three county email accounts had been accessed. During that access window, the threat actors were able to download the entire contents of at least one email account.

On May 13th, Aitkin HHS completed their review. They determined that one email in particular contained a report from the Minnesota Department of Human Services (DHS), which included information about those who applied for or are involved with MnCHOICES, a Minnesota program that assists those who are aging or living with disabilities. Additional information included names, addresses, dates of birth, Social Security numbers, dates of services, locations of services, case information, medical and health information, and additional healthcare related information.

 

Why it matters

Even though this breach only lasted one full day, it still allowed for almost 100,000 individuals to have their data accessed. While some breaches last weeks or even months, the majority are incredibly brief, with attackers quickly entering, downloading data, and leaving. In other cases, like is possible with this one, the attack is caught while it’s occurring, but not before damage is already done. In these cases, it’s possible that stopping the malicious actors from continuing access helped protect data of other individuals in the area.

According to IBM in their 2026 Cost of a Data Breach Report, the length of a data breach (how long it takes to identify and contain) is correlated with an increasing cost. The quicker an organization can identify an issue, the more money they’ll likely save in the long run.

 

The big picture

Many organizations work together to process data, especially when it comes to government or other social services. These organizations primarily communicate through email, and it’s clear that even one vulnerable account can cause problems across multiple organizations. While these partnerships aren’t exactly part of any one company’s supply chain, the attack functions in a similar way. Once one partner, like Aitkin’s HHS is breached, it’s easier for other organizations, like Minnesota’s DHS, to be attacked, creating a breach that not only affects more people, but can be more challenging to stop, especially if other individuals then fall prey to phishing messages. For an organization like DHS, it can be particularly troubling because this will be the second time they have been involved in a breach this year, with their first breach impacting over 300,000.

 

FAQs

Why do some investigations take longer than others?

Data breaches vary widely depending, and as a result, so do the investigations that follow. In many cases, it can be difficult to determine the initial access point or vector. In this case, it may have been relatively easy since the breached email account also began sending out phishing emails, making it clear where the breach began. In some cases, investigations are also drawn out if the FBi is involved or if the organization is in communication with the threat group.

 

Why would a breached email send phishing emails?

Once one account is breached, it becomes easier for additional email accounts to be breached. Now, an account that appears safe and normally is can target other individuals without them knowing. For employees, the take away is that even if the email address is completely normal, it’s important for individuals to stay vigilant. If a request seems odd, the writing is out of place, or anything else raises red flags, employees should verify the contents of an email through a different method, like a phone call or chat.