Kootenai County, Idaho Data Breach Notice (Washington Attorney General): What Was Exposed & What To Do
Kootenai County, Idaho has disclosed a data breach affecting 746 individuals, with personal details including names, Social Security numbers, driver’s license or Washington ID card numbers, full dates of birth, and health-insurance policy or ID numbers made public. Washington Attorney General’s notice dated July 22, 2026 advises anyone potentially impacted to review the county’s statement and consider protective steps such as credit monitoring or fraud alerts.
A data breach notice filed with the Washington State Attorney General shows that personal information belonging to 746 people was exposed in an incident involving Kootenai County, Idaho. For those individuals, the practical stakes are immediate: the notice lists highly sensitive identifiers that can be used for identity theft, financial fraud, and long-term impersonation.
The filing, reported on July 22, 2026, was directed at Washington residents whose data was involved. Public detail beyond the notice itself remains limited, yet the categories of information named make clear why affected people need concrete steps to protect themselves.
What happened
Kootenai County, Idaho notified Washington residents of a data breach in a filing reported to the Washington State Attorney General on July 22, 2026. According to that notice, 746 people were affected. The filing lists the following categories of information as exposed: name, Social Security number, driver’s license or Washington ID card number, full date of birth, health insurance policy or ID number, medical information, and biometric data.
The notice does not publicly detail how the incident occurred, when it began or was discovered, what systems were involved, or whether the data was encrypted, exfiltrated, or otherwise accessed. Those operational specifics are undisclosed in the available record. What is established is the county’s formal notification to the Washington Attorney General and the data types and headcount it reported.
How a breach like this happens
Incidents that lead to notices of this kind commonly begin with unauthorized access to systems that store resident or employee records. Typical pathways include compromised credentials, phishing that yields remote access, unpatched software vulnerabilities, or misconfigured remote services. Once inside a network, an attacker may move laterally to databases, document repositories, or backup systems that hold identity and health-related files.
In many cases the goal is to copy large volumes of structured personal data rather than to disrupt operations. Organizations that handle government, health, or licensing records often maintain centralized databases linking names to Social Security numbers, dates of birth, identification numbers, and medical or insurance details. When those repositories are reached without adequate segmentation or monitoring, the result can be a single incident that exposes multiple sensitive fields at once. No specific method or threat group is attributed in the Kootenai County notice, so the precise pathway in this case remains unconfirmed.
Who is Kootenai County, Idaho?
Kootenai County is a county government in northern Idaho. Like other county governments, it administers local services that routinely require collection and retention of personal information: property and tax records, court and justice-system files, public-health and human-services programs, licensing, elections administration, and employee or contractor records. Counties also interact with state and regional partners, which can mean that data about residents of other states—here, Washington—ends up in county systems.
A breach at this level is consequential because county governments sit at the intersection of identity verification, benefits administration, and public records. The data they hold is often richer and more durable than what a single retailer or website might collect. When Social Security numbers, government ID numbers, dates of birth, medical information, insurance identifiers, and biometric data appear together, the combination can support sophisticated identity fraud that is difficult for individuals to unwind.
What was likely exposed
The Washington Attorney General filing explicitly names the following as exposed: name, Social Security number, driver’s license or Washington ID card number, full date of birth, health insurance policy or ID number, medical information, and biometric data. Those categories come directly from the notice; nothing beyond them is confirmed in the public summary.
Organizations of this type typically also hold addresses, contact details, case or account numbers, and employment or benefits data, but the filing does not state that those additional fields were involved. Readers should treat only the listed categories as confirmed by the disclosure. The exact format of the biometric data, the nature of the medical information, and whether full files or partial records were taken are not described in the available notice.
The real-world impact
For the 746 people named in the count, the combination of Social Security number, full date of birth, and government ID number creates a durable identity package. Criminals can use that package to open credit accounts, file fraudulent tax returns, obtain medical services under another person’s identity, or attempt to pass identity verification checks at banks and government agencies. Health insurance policy numbers and medical information raise the additional risk of medical identity theft, which can produce incorrect entries in health records and disputed bills.
Biometric data, once exposed, cannot be changed the way a password can. Its long-term misuse potential depends on how the data was stored and what systems accept it, details that are not provided here. For the county itself, the incident carries notification costs, possible regulatory follow-up, and the operational burden of supporting affected residents. No dollar figures, ransom demands, or findings of fault are stated in the public filing, so those aspects remain outside what can be reported as fact.
What to do if you're exposed
If you believe you are among the 746 people covered by the notice, start by placing a free fraud alert or credit freeze with the major credit bureaus and monitor credit reports for new accounts you did not open. Review explanation-of-benefits statements and medical bills for services you did not receive. Consider requesting a replacement driver’s license or state ID if that number was involved, and keep records of any correspondence from the county or the Washington Attorney General’s office.
Watch for phishing that references the breach; scammers often exploit public notices. You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach datasets, then use that result to prioritize password changes and ongoing monitoring. If you receive a formal notification letter, follow the specific instructions and any credit-monitoring offer it contains, and retain the letter for your records.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Chelan County, WA Data Breach Notice (Washington Attorney General)Kovack Financial, LLC Data Breach Notice (Washington Attorney General)Golden Opportunities And Local Support, LLC Data Breach Notice (Washington Attorney General)American Addiction Centers Data Breach Notice (Washington Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.