Cyber Incident Victim: Rapid City
Timeline
Summary
In Rapid City, a cyber incident affected a lift station of the wastewater system, prompting officials to isolate affected computers after employees noticed abnormal activity. The intrusion was part of a broader series of cyberattacks on water systems across multiple states that caused pressure drops and flooding at some facilities but did not compromise drinking water safety. Investigators have not confirmed responsibility, though Iran is considered a suspect, and the events have prompted federal and state efforts to improve cyber defenses for water utilities.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 0 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In Rapid City, South Dakota, officials announced on July 31 that a cyber incident had affected one of the lift stations serving the city’s wastewater system. The announcement came after city employees observed abnormal behavior on the lift station’s computer systems and promptly isolated those systems from the internet to prevent further intrusion. Mike Theis, Rapid City’s public works director, noted that he could not recall a previous cyberattack of this nature occurring in the city and expressed that the city was not surprised by the possibility of being targeted by a foreign adversary during wartime. He credited the swift detection and isolation efforts of the staff as the key response that limited the incident’s impact.

The Rapid City lift station intrusion is situated within a broader pattern of cyber intrusions that have struck water and wastewater facilities in a dozen states ranging from South Dakota to Georgia, occurring amid a scorching heat wave. According to the FBI, similar intrusions in other jurisdictions have led to water pressure drops and flooding at facilities, although state and local officials have confirmed that the safety of drinking water was not compromised in those cases. While the article does not specify whether pressure changes or flooding occurred at the Rapid City lift station, it places the event within the same series of attacks that have prompted federal and state officials to examine the vulnerability of under‑resourced water infrastructure. The incident has contributed to ongoing discussions about the need for improved cyber defenses, including proposed grant programs and legislative measures aimed at strengthening the cybersecurity posture of water systems nationwide.
In response to the detected anomaly, Rapid City’s workforce followed established incident‑response procedures by identifying the irregular activity, disconnecting the affected lift station’s computers from external networks, and initiating an investigation into the source and scope of the intrusion. The public works director emphasized that the employees’ quick recognition of the abnormal behavior and their immediate isolation actions were critical in containing the cyber incident. No further details regarding the duration of the disruption, any service interruptions, or subsequent restoration efforts were provided in the source material. The announcement on July 31 marked the official acknowledgment of the event, and city officials indicated that they would continue to monitor the situation and cooperate with any broader investigative efforts related to the multi‑state cyber campaign.
