Rapid City Cyberattack is a National Wake-Up Call: What to know

Rapid City Cyberattack Is a National Wake-Up Call: Water Systems and County Networks Affected 

Why Rapid City is a Cyber Wake-Up Call (4)

Within a matter of weeks this summer, both Pennington County and the City of Rapid City found themselves responding to significant cybersecurity incidents. One impacted county government operations, while another involved an attempted intrusion into local wastewater infrastructure.  

Together, they paint a clear picture: cybercriminals are no longer focusing solely on large, high-profile targets. They’re increasingly looking for opportunities in communities just like Rapid City. One thing is for sure: the Rapid City cyberattack is a national wake-up call. 

A Summer of Cybersecurity Challenges in Rapid City 

The most disruptive incident occurred in July when Pennington County experienced a cyberattack that forced IT staff to take servers offline to contain the threat. County officials have since stated they believe the attack was a ransomware incident. Although county departments have largely returned to normal operations, some online services remain limited months later. 

That detail is important. 

Many people picture a cyberattack as a brief interruption. In reality, even organizations that successfully contain an attack can spend months restoring systems, validating data, rebuilding infrastructure, and ensuring attackers no longer have access. The attack itself may last days, but recovery often lasts much longer. 

For residents, the disruption may simply mean an online service isn’t available. For the organization behind the scenes, it can mean hundreds of hours spent restoring systems and investigating what happened. 

The Attack That Hit Critical Infrastructure 

While the county was dealing with its own cybersecurity challenges, Rapid City announced that one of its wastewater lift stations had also experienced a cyber incident. City officials reported they detected the attempt quickly, acted immediately, and confirmed the city’s water and wastewater systems were never placed in danger. The city also worked with the Cybersecurity and Infrastructure Security Agency (CISA) and other federal partners during the investigation. 

Cybercriminals are increasingly exploring opportunities beyond traditional office networks. Water systems, utility infrastructure, industrial controls, and other operational technologies have become attractive targets because they support functions that communities depend on every day.  

Cybersecurity Is Becoming a National Issue 

Rapid City and Pennington County are not alone. 

Recent months have seen multiple South Dakota government entities dealing with cybersecurity incidents. The city of Mitchell, SD experienced its own cybersecurity breach, while state leaders continue evaluating how to strengthen protections for counties, cities, and critical infrastructure across South Dakota.  

Minnesota was also hit by a coordinated cyberattack targeting more than 30 municipal water systems. Several communities experienced operational disruptions after attackers interfered with computerized control systems used to manage water infrastructure.   

South Dakota’s response has included programs like SecureSD, a cybersecurity initiative administered through the South Dakota Attorney General’s Office and Dakota State University. The program helps local governments improve cybersecurity defenses, modernize email systems, identify vulnerabilities, and receive technical guidance. 

However, with SecureSD funding currently scheduled to expire in 2028, state leaders are already discussing how local governments will continue improving cybersecurity protections in the years ahead. 

A Warning Sign for the Black Hills Region 

The most notable aspect of these incidents isn’t necessarily the damage they caused. 

It’s where they happened. 

When cyber incidents affect organizations in places like New York, Los Angeles, or Chicago, it’s easy to view them as distant news stories. When they affect county government offices and public infrastructure in Rapid City, the threat suddenly becomes much more tangible. 

For local businesses, the takeaway is simple: cybercriminals are already here. The organizations that invest in security before an incident occurs will be in a much better position than those forced to react after one. 

The best thing you can do right now to prevent a cyber incident is follow these five IT safety tips: 

  • Think before you click. If an email seems unexpected, urgent, or comes from someone you don’t recognize, verify it before opening links or attachments. Double-check sender addresses. Cybercriminals often use email addresses that look similar to legitimate companies, vendors, or coworkers. 
  • Be suspicious of phone calls. Criminals can call you from a number you recognize and trust. Never give out passwords or bank information over the phone without verifying first by hanging up and calling the official number directly. 
  • Use strong passwords and MFA. A unique password combined with multi-factor authentication is one of the best defenses against account compromise. 
  • Keep software updated. Regular updates and security patches help close vulnerabilities attackers commonly exploit. 
  • Report suspicious activity immediately. If something doesn’t look right, notify your IT team right away. Early reporting can prevent a small issue from becoming a major incident. 

Looking for some guidance? Consider a free consultation from Catalyst IT 

The recent cyberattacks across South Dakota and Minnesota serve as a reminder that cyber threats are not distant possibilities. They’re affecting organizations throughout our region right now.  

At Catalyst IT, we help businesses identify vulnerabilities, strengthen defenses, and build practical cybersecurity strategies before an incident occurs. Because when it comes to cybersecurity, preparation is always less costly than recovery.  

Click here to request a free consultation.