Recent South Dakota and Minnesota Cyberattacks Prove Cyber Threats are Close to Home

Imagine a cyberattack aimed at the systems that keep your community running. Your water utility, county government, or local infrastructure suddenly can’t operate normally.
It sounds exaggerated until you realize it has already happened across South Dakota and Minnesota.
Over the past few months, organizations in South Dakota and Minnesota have experienced cybersecurity incidents that have disrupted government services, targeted utility systems, and raised concerns about the security of critical infrastructure.
At Catalyst IT, we often remind clients that cyber threats aren’t reserved for large cities or Fortune 500 companies. Recent events in our own backyard prove that cyberattacks are getting closer to home, and no organization is too small to become a target.
South Dakota Has Already Felt the Impact
In July 2026, Pennington County suffered a cybersecurity incident that disrupted county computer systems and affected public services. While critical functions such as 911, courts, and law enforcement remained operational, many technology-dependent services were impacted as officials worked to contain and investigate the attack.
Just weeks later, cybersecurity concerns spread beyond county-level government. Rapid City’s water system was among dozens of utilities nationwide targeted during a wave of cyber incidents, while the city of Mitchell dealt with its own breach that disrupted normal computer operations.
These events highlight how vulnerable even local organizations can be when attackers identify weaknesses in technology infrastructure.
Why Are Local Organizations Being Targeted?
Many local governments and businesses operate with limited IT staff, tight budgets, and aging systems, making them attractive targets for cybercriminals.
According to reporting from South Dakota Searchlight, 68% of state and local government organizations report lacking the resources needed to address major cybersecurity priorities. Rural communities can face even greater challenges.
In response, South Dakota created the SecureSD program to help local governments improve email security, identify vulnerabilities, and strengthen cybersecurity defenses.
The Threat Extends Beyond South Dakota
The concern isn’t limited to South Dakota.
Around the same time as the Pennington County incident, officials in neighboring Minnesota announced a coordinated cyberattack targeting more than 30 municipal water systems. Several communities experienced operational disruptions after attackers interfered with computerized control systems used to manage water infrastructure.
Federal cybersecurity agencies have repeatedly warned that critical infrastructure systems, including water and wastewater facilities, face growing threats from foreign adversaries and sophisticated cybercriminal groups. Recent advisories from the Cybersecurity and Infrastructure Security Agency (CISA) highlighted increasing concerns surrounding attacks on internet-connected operational technology.
While Nebraska and Iowa have experienced isolated local-government cybersecurity incidents in recent years, South Dakota and Minnesota have recently become some of the most visible examples of how cyber threats are increasingly impacting communities throughout the Upper Midwest.
Email Remains a Favorite Entry Point
Many cyberattacks still begin with something deceptively simple: an email.
Attackers frequently use phishing campaigns, spoofed email addresses, fake invoices, and fraudulent login pages to gain access to credentials or deploy malicious software. Once inside a network, they often attempt to expand access, gather information, encrypt data, or disrupt operations.
Cybersecurity experts involved with South Dakota’s SecureSD program have prioritized moving organizations toward professionally managed email environments with stronger security controls and modern authentication standards.
At Catalyst IT, we help businesses stay ahead of evolving threats with solutions like Huntress Endpoint Detection and Response (EDR), a service that continuously monitors desktops, laptops, and other endpoints to identify and stop suspicious activity before it becomes a major security incident. Huntress also offers Identity Threat Detection and Response (ITDR) because attackers often target logins and permissions more than endpoints or firewalls now. ITDR detects and stops these identity-based threats in real time.
Try our own free phishing game here:

Security awareness is just as important as technology. That’s why Huntress also includes monthly cybersecurity training that helps employees recognize phishing attempts, social engineering tactics, and other common threats through short, engaging lessons designed to strengthen your organization’s security posture.

What Local Businesses Should Learn from These Incidents
These incidents may have involved government entities, but the lessons apply to every organization.
Many successful attacks still begin with stolen credentials, phishing emails, weak passwords, or unpatched software. That’s why the basics remain so important:
- Multi-factor authentication (MFA)
- Employee security training
- Advanced email protection
- Regular system updates to network and firewalls
- Secure backups
- Endpoint monitoring
- An incident response plan
Looking for some guidance? Consider a free consultation from Catalyst IT
The recent cyberattacks across South Dakota and Minnesota serve as a reminder that cyber threats are not distant possibilities and that they are getting closer to home. They’re affecting organizations throughout our region right now.
At Catalyst IT, we help businesses identify vulnerabilities, strengthen defenses, and build practical cybersecurity strategies before an incident occurs. Because when it comes to cybersecurity, preparation is always less costly than recovery.


Request a Free Consultation
Click here to request a free meeting with Catalyst IT Experts!