Skip to content

Mitchell South Dakota Cybersecurity Incident

Summary

City of Mitchell logo

Mitchell, South Dakota, shut down a limited network segment August 6, 2026, while investigating a potential cybersecurity incident; critical and emergency services remained operational. The mayor said the city and its online systems were fully operational by August 12. Storm later claimed the city on a leak site, but Mitchell has not confirmed ransomware, data theft or actor responsibility.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

External sources identified the event as cyber-related before the organization publicly confirmed it. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Unknown data impact

    The incident is cyber-related, but available evidence does not establish whether or how data was affected.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Network outage

    Internal or external network connectivity was unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

Extortion indicators

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Mitchell shut down a limited portion of its municipal network while responding to concrete cyber-specific warning signs. Mayor Jordan Hanson told the Mitchell Republic that the city was investigating a potential cybersecurity incident, had shut down the affected environment as a precaution and had engaged forensic experts. That qualified affected-organization wording confirms cyber involvement, although it does not establish unauthorized access or a specific malicious mechanism.

A ransomware.live record preserves a Storm leak-site claim naming the City of Mitchell and its cityofmitchellsd.gov domain. The captured actor page says the listing was posted Aug. 23, showed a pending status and an Aug. 28 deadline, displayed no uploaded file list, and presented 20 image thumbnails as proof. The listing establishes that Storm made a claim; it does not authenticate the images, prove that the material was obtained from Mitchell, or establish Storm’s responsibility, ransomware, encryption, data theft or a ransom demand.

Operational significance

The city shut down computers and a limited network environment Aug. 6 and began forensic review and remediation. Our reporting documented the precautionary shutdown and restoration work while noting that the affected systems were not identified. Access to the city’s meeting-agenda platform was limited, establishing a public-facing effect in addition to the broader internal shutdown.

Mitchell said critical and emergency services were unaffected and fully operational. The city and Davison County websites remained accessible. The available evidence does not establish interruption to 911, public safety, utilities, payments, permitting, records access or other specific resident-facing services beyond the meeting-agenda limitation.

Disclosure posture

The documented sequence began with a Davison County warning that described city email service as hacked and was followed by the mayor’s affected-organization acknowledgement in reporting published Aug. 7. The county used definitive language about a hack and city email, while Mitchell used qualified cybersecurity wording and said it had no indication email was affected. The difference may reflect a precautionary county response, but the public record does not resolve the warning’s technical basis.

Storm’s Aug. 23 claim occurred after both the county warning and Mitchell’s cybersecurity acknowledgement. It therefore does not alter the existing external-first, then organization-confirmed disclosure sequence.

Current status

The operational disruption is resolved. In an Aug. 12 written statement quoted by Government Technology, Hanson said the city was fully operational and all online systems were operating as expected. City staff could again post City Council agenda materials that day. Aug. 12 is the latest documented impact and recovery date; the later Storm claim does not extend the operational clock.

Confidence and uncertainty

Confidence is high that Mitchell shut down part of its network and restored operations because the mayor directly described those actions. Confidence is also high that concrete cyber evidence exists because the mayor publicly described a potential cybersecurity incident.

Ransomware involvement and Storm attribution are assessed with low confidence. The stable listing supports recording the claim and a leak-site indicator, but Mitchell, law enforcement, a regulator and independent technical evidence have not corroborated Storm’s responsibility. Data impact remains unknown. The visible thumbnails and the actor’s proof label do not establish whether the pictured documents were nonpublic, authentic, obtained from city systems or connected to this incident.

The name Storm is treated as the label used by the claimant’s leak site. The public evidence does not establish the operation’s identity, lineage, affiliate model or relationship to other unrelated threat-actor labels that use the word storm.

Analytic gaps

The public record does not identify the triggering detection, affected network segment, initial access vector, compromised account or host, exploited vulnerability, malware, persistence, dwell time, encryption, data access or exfiltration, affected data categories, threat actor identity, ransom demand or payment activity. It also does not establish whether any city email account or message was compromised, how many systems were isolated, what the Storm thumbnails depict, or whether the actor communicated directly with Mitchell.

Threat actor and claim

Listed as: City of MitchellSource: ransomware.livePublished: Discovered:

Claim details

Storm’s leak-site listing names the City of Mitchell and its cityofmitchellsd.gov domain. The captured page shows an August 23 posting date, pending status, August 28 deadline, no uploaded file list and 20 image thumbnails presented by the actor as proof. Mitchell has not attributed the incident to Storm or confirmed ransomware, encryption, a ransom demand or data theft, and the listing does not authenticate the images or establish actor responsibility.

Organizations involved

Impacted location

Sources

Mitchell, South Dakota, shuts part of network during cybersecurity probe

Our reporting found that Mitchell shut down a limited network segment while investigating a potential cybersecurity incident and restoring operations with forensic experts. Critical and emergency services remained operational, while the affected systems, unauthorized access, attack type, data impact, ransom demand and actor were not disclosed.

City of Mitchell email services hacked, officials say they're investigating potential cybersecurity incident

The Mitchell Republic reported a Davison County directive telling employees not to open city emails after a county official described the city’s service as hacked. Mayor Jordan Hanson said Mitchell was investigating a potential cybersecurity incident, shut down a limited network environment, engaged forensic experts and had no indication city email was affected. A TechSolutions manager said he was unaware of any related breach at Davison County offices.

Mitchell, S.D., ‘Fully Operational’ After Cyber Attack

Government Technology republished The Daily Republic’s report quoting Mayor Jordan Hanson as saying Aug. 12 that Mitchell was fully operational and all online systems were operating as expected. The report said city computers had been shut down Aug. 6 and access to the meeting-agenda platform was limited until staff could post materials again Aug. 12.

City of Mitchell — claimed by Storm

Ransomware.live preserves a Storm listing naming the City of Mitchell and its cityofmitchellsd.gov domain. The captured actor page says it was posted Aug. 23, shows a pending status and Aug. 28 deadline, displays no uploaded file list, and presents 20 image thumbnails as proof. The record does not authenticate the images or establish Storm’s responsibility, ransomware, encryption, data theft or a ransom demand.

See something that needs correction?

Signed-in members can report an error, update, or missing source.