Cyber Incident Victim: Pennington County
Timeline
Summary
Pennington County experienced a debilitating cyberattack on its treasurer payment systems that disrupted services and is still being restored, while its communication systems were also compromised in a separate incident. Experts theorize that Iran‑backed hackers carried out these attacks, which also targeted the city of Mitchell’s email system and Rapid City’s sewer infrastructure, contributing to a broader wave of incidents across South Dakota’s local governments. In response, the state has funded cybersecurity programs such as SecureSD and Project Boundary Fence, which provide training, phishing simulations, and mitigation support to participating agencies.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 0 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In early July, Pennington County experienced a debilitating cyberattack that disrupted its public‑facing systems, notably the treasurer payment platforms, leaving them offline. The attack forced the county to take those systems offline while it worked to restore functionality. As of the August 17 report, the treasurer payment systems were still slowly coming online. The incident is described as part of a wave of recent high‑profile cyberattacks on local governments in South Dakota, which also affected Rapid City and Mitchell. Officials noted that the breach contributed to a broader pattern of over 1,000 reported online security breaches in the state over the previous five years, with 127 such incidents recorded in 2026 alone. The disruption hindered residents’ ability to make payments to the county treasurer through online channels.

Cybersecurity experts have theorized that the attack on Pennington County’s communication systems may be linked to Iran‑backed hackers who have been implicated in large‑scale cyber operations targeting government entities in the state and elsewhere. While the article does not detail the specific tactics used by the attackers, it notes that email systems are frequently the initial entry point for such intrusions. The attack on Pennington County followed a similar pattern seen in Mitchell, where a hack of the city’s email system in early August postponed meetings and left email unreliable. No ransom payment or data loss is mentioned for Pennington County in the source material.
In response to the growing threat landscape, South Dakota has funded the SecureSD and Project Boundary Fence programs, which aim to improve email and data security, conduct phishing simulations, and provide training and planning for participating government entities. The state legislature allocated $7 million to these initiatives in 2024, and additional funds have been directed toward the Governor’s Resilience and Infrastructure Task Force to bolster cybersecurity resilience. Despite these broader efforts, the article provides no further specifics on the containment, eradication, or recovery steps taken uniquely by Pennington County after the early July incident.
