Rapid City
Incident posture
Linked entities
- Victim
- Rapid City
- Threat actors
- 0 actors
- Sources
- 3 sources
Timeline
Summary
Rapid City’s wastewater system experienced an attempted cyber intrusion targeting a lift station, which was detected by employees who observed abnormal activity and isolated the affected components from the network. The prompt response prevented any disruption to sewer services, and officials confirmed that no operational impact resulted from the incident.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In mid‑July the Rapid City sewer system experienced an attempted cyberattack that did not interrupt services. On July 31 officials announced that a cyber incident had hit one of the lift stations that serves the city’s wastewater system. Mike Theis, Rapid City’s public works director, said they were not surprised by the incident and could not recall a time when Rapid City had experienced a similar cyberattack. Theis credited the quick action of employees who noticed abnormal behavior on computer systems and isolated them from the internet.
The Rapid City incident occurred alongside other recent high‑profile cyberattacks on government operations in Pennington County and Mitchell. Over the past five years the South Dakota Attorney General’s Consumer Affairs Division has recorded more than 1,000 online security breaches, including 127 so far in 2026. State law prevents the public release of where or upon whom those breaches took place. Experts theorize that Iran‑backed hackers are responsible for large‑scale cyberattacks on communication systems in Pennington County and the city of Mitchell as well as breaches into water systems in Minnesota and possibly up to a dozen more states. In Pennington County public‑facing systems such as treasurer payment systems were still slowly coming online after a debilitating cyberattack that took place in early July. In Mitchell a hack of the city’s email system in early August caused some city meetings to be postponed and left email systems unreliable.
South Dakota rejected federal cybersecurity grants and instead allocated more than $7 million in state taxpayer funds to cybersecurity prevention efforts. The Legislature approved funding for the SecureSD and Project Boundary Fence programs in 2024 at $7 million. Gov. Larry Rhoden appropriated $500,000 in Future Fund money to the South Dakota Department of the Military to boost the Governor’s Resilience and Infrastructure Task Force, of which cybersecurity is one objective. SecureSD provides training and support in email and data security, enhancement of security and mitigation efforts, and cybersecurity training and planning for participating public entities. Project Boundary Fence includes sending bogus phishing emails to employees; if a fake link is opened the employee and the state receive notice, additional security training is provided, and email passwords, system firewalls, and security procedures are reviewed; any deficiencies found are corrected by independent IT contractors paid by the state. The program also provides cybersecurity training and planning to participating managers and employees to reduce the risk of an attack. More than 100 government agencies have participated in the programs, including about 54 of South Dakota’s 66 counties. Local resistance to funding cybersecurity often stems from staff shortages, a belief that attacks will happen to someone else, and a lack of public support for prevention spending.
Sources
Sources available to members: 3 sources.