On January 28, 2026, Seward County, Kansas, experienced a data breach when its systems were encrypted by Sinobi ransomware. The county confirmed the theft of data and posted a statement on its official website on February 10, 2026. This incident led to a regulatory investigation by the Kansas Attorney General, who filed a notice on March 15, 2026.
Confirmed data types include names, addresses, dates of birth, Social Security numbers (SSNs), driver's license numbers, financial account details, medical records, and employee payroll data. Approximately 45,000 individuals are estimated to have been affected, based on county population estimates. SSNs for about 35,000 residents and medical data for approximately 5,000 individuals through county clinic records were exposed. Seward County mailed notifications to all affected residents on March 25, 2026.
It is important to note that further details regarding this incident may emerge. Official notices may also be sent out in the coming weeks or months.