Cyber & AI intelligence
Wasteland.
Briefs indexed2867
Issues29
Published Mondays07:30 CT
█ Ransomware PENNINGTON-COUNTY- 2026-09-25

Pennington County, South Dakota: Ransomware Attack Knocks County Systems Offline for Months

"Pennington County, South Dakota, has confirmed that the cybersecurity incident that began on July 4, 2026 was a ransomware attack. The county said unauthorized actors got into its systems and deployed ransomware, and IT…"

Pennington County, South Dakota, has confirmed that the cybersecurity incident that began on July 4, 2026 was a ransomware attack. The county said unauthorized actors got into its systems and deployed ransomware, and IT staff took servers offline to stop it spreading. The confirmation came in a September 24 update from Commission Chair Ron Weifenbach, which was reported by KOTA Radio, KOTA-TV and NewsCenter1. Nearly three months after the attack, every county department is working again, but some public-facing services are still limited. The county has not named a threat actor, said whether a ransom was demanded, or said whether any data was stolen. Pennington County includes Rapid City and runs courts, elections, the jail and public safety for one of South Dakota's largest population centers.

A note on sourcing: none of the sources available for this brief are primary documents. What the county said reaches us through local news outlets. We found no regulator filing, CISA advisory or public notice from the county.

What Happened

Initial response (July 4 to 6). The county found unauthorized activity on July 4. On July 5, the Pennington County State's Attorney's Office announced that most public-facing county offices would close the following Monday while officials worked out how big the incident was (DysruptionHub). At that point the county called it only a "cybersecurity incident affecting parts of the county network." It did not confirm what kind of attack it was.

Critical services kept running. The county said the following stayed operational throughout (DysruptionHub): - 911 dispatch - The Pennington County Jail - The Juvenile Services Center and Care Campus - Court operations and the 24/7 Program - Early voting - Online and kiosk vehicle registration

Gradual restoration. The Treasurer's Office restarted some services in stages (KOTA-TV, Aug. 20): - Motor vehicle transactions resumed on July 13. - Property tax payments resumed on August 12. - Residents who were given temporary paper registrations because of the outage had until August 31 to finish their transactions.

The Treasurer's satellite office in Wall stayed closed through September because network services had not been fully restored (Dakota News Network, Sept. 1).

Ransomware confirmed (September 24). In the county's update, Weifenbach said early details had been held back to protect the investigation. The county has now confirmed that threat actors deployed ransomware and that IT shut down servers "to contain the threat, protect County information, and begin evaluating the affected environment" (KOTA-TV, KOTA Radio, NewsCenter1).

Current status and restoration timeline. Accounts of the restoration timeline differ: - NewsCenter1 reports that property searches and some services used by title companies are still down. It says Weifenbach expects most services to be fully restored within one to two weeks. - KOTA-TV reports that officials "have not set a target date for full restoration yet."

These two reports may reflect different wording in the same briefing. Readers should treat the one-to-two-week estimate as a projection, not a firm commitment.

Partner agencies. Sources list different combinations of the agencies that helped with the response and recovery. Across all of them, the list is: - The FBI - CISA - The South Dakota National Guard Cyber Incident Response Team - The South Dakota Fusion Center

Unclear detail. NewsCenter1's subheadline says ransomware was "deployed on their website." No other source says this, and the county's own statement as quoted refers to "County systems" and servers. We treat the website claim as unconfirmed.

What Was Taken

No source reports that data was stolen, and the county has not confirmed or ruled it out. When DysruptionHub last updated its coverage, officials had not confirmed data theft, a ransom demand or a threat actor. The September 24 update, as reported, also does not mention exfiltration. It refers only to protecting "County information" and "public information."

Given what the county holds, that gap matters. County systems contain court, jail, election, property, tax and motor vehicle records. Most ransomware operations now steal data before encrypting it so they can pressure victims twice. Because the county has not addressed exfiltration, residents and defenders should watch for: - A listing on a leak site - A breach notification filed with the South Dakota Attorney General

South Dakota law bars the Attorney General's office from publicly saying which organisations reported a breach (SD News Watch). That makes independent verification harder.

Why It Matters

Long outages at local government are now normal. Critical life-safety services kept running, which shows that network segmentation or careful triage worked. Even so, property searches, title-company services and a satellite Treasurer's office were still affected almost three months later. For counties, the operational damage from ransomware lasts far longer than the containment phase.

A regional cluster. The attack is one of three South Dakota local-government incidents within a few weeks of each other: - The Rapid City water system was among the first of dozens of utilities targeted in a nationwide wave of attacks. City officials said the attackers did not get into the city's network. - The City of Mitchell suffered a breach that left city staff without computer access.

(Rapid City Post; SD News Watch.)

The sources do not tie these incidents together. Defenders should not assume they share an actor.

Funding gaps. South Dakota turned down federal State and Local Cybersecurity Grant Program money under the Infrastructure Investment and Jobs Act. Instead it funds SecureSD, a state program that runs out of Dakota State University. Accounts describe it as either "more than $7 million" in state funds (SD News Watch) or a "$7 million program" (Rapid City Post). The Rapid City Post reports that the program is running short of time and money.

The Rapid City Post also cites a 2025 MS-ISAC report finding that 68% of state, local, tribal and territorial governments lack the budget to address major cybersecurity priorities. The South Dakota Attorney General's office has received 1,062 breach reports over five years, including 127 so far in 2026 (SD News Watch). Those figures cover all sectors, not just government.

The Attack Technique

Unknown. No source describes how the attackers got in, what ransomware family was used, or who carried out the attack. The county has confirmed only three things: - Unauthorized actors gained access. - They deployed ransomware. - IT shut down servers to contain it.

The fixes the county is now making hint at weaknesses it saw in its own setup, although it has not said any of them was the entry point (NewsCenter1): - Moving to multifactor authentication. This suggests MFA was not applied across the whole environment before the attack. Stolen or brute-forced credentials on remote access are a common way ransomware operators get in. - Shifting to cloud-based systems. This reduces reliance on on-premises servers that can be encrypted. - Moving websites and email to .gov domains. This makes impersonation harder and gives the county access to the security services that come with .gov registration.

The county also mentions extra technology investment, employee training and "enhanced security measures" (KOTA Radio). These are the usual steps after a phishing or credential-based compromise, but the county has confirmed neither.

What Organizations Should Do

  1. Require phishing-resistant MFA everywhere, starting with remote access. Cover VPN, RDP gateways, email, and privileged or admin accounts. Pennington County is only adopting MFA now, after the incident. Close any remaining gaps before an attacker finds them.
  2. Segment life-safety systems from the rest of the network. Keep 911/CAD, jail management and court systems apart from general county IT so they can keep running while other servers are pulled offline. Test that separation during tabletop exercises.
  3. Keep offline, immutable backups and test full restores. Services took months to come back, which usually points to restores that had to be rebuilt from scratch. Measure how long it really takes to restore property, tax and records systems, not just whether the backups exist.
  4. Move to .gov and lock down email. Eligible US public bodies should register .gov domains through CISA. Enforce DMARC at p=reject to reduce spoofing of official communications during and after an incident.
  5. Plan manual fallbacks for public services. Pennington County issued temporary paper vehicle registrations to keep services going during the outage. Document manual workflows for revenue- and deadline-critical services ahead of time, including how records will be reconciled afterwards.
  6. Line up outside help before you need it. Establish contacts with state resources such as the National Guard cyber teams, fusion centers and state programs like SecureSD, as well as the FBI and CISA. Also check your eligibility for free CISA services, such as vulnerability scanning and the Known Exploited Vulnerabilities feed, so incident response doesn't start from a standing start.

Sources: Pennington County Provides New Details on July Ransomware Attack N... | Pennington County Commission provide updates in cybersecurity incid... | SD taxpayers spend millions on cyberattacks after grant rejected | Pennington County SD offices close amid cyber incident | South Dakota’s cybersecurity program is running out of time, money... | Pennington County Cyberattack: Aug. 31 Vehicle Registration Deadlin... | Pennington County Provides Update on July Cybersecurity Incident | Pennington County Treasurer's Satellite Office Remains Closed Due T...