Skip to content

Rapid City contains wastewater lift station cyber incident

Summary

City of Rapid City logo

Rapid City said it quickly detected and contained an attempted cyber intrusion involving a municipal wastewater lift station. Officials reported that water and wastewater infrastructure remained safe, drinking water was secure, and no operational disruption occurred while the city investigated with CISA and other federal partners.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Impacted locations

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. No credible public source clearly documents service disruption.

Attack mechanisms

Data impacts

  • No known data impact

    Available evidence indicates that the incident did not materially affect the confidentiality, integrity, or availability of data.

Operational impacts

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Rapid City, South Dakota, experienced an attempted cyber intrusion involving a municipal wastewater lift station. The city publicly characterized the event as a cyber incident and said officials quickly identified and contained the attempted breach. DysruptionHub’s published report said the city immediately took precautions and began working with the Cybersecurity and Infrastructure Security Agency and other federal partners.

The available evidence supports a contained intrusion attempt, not a confirmed ransomware or destructive event. The city did not disclose how access was attempted, whether an internet-facing controller was involved, or whether any system setting, account, data or device was actually accessed or altered. The public record also does not identify a responsible actor.

DysruptionHub assesses that this event belongs to a contemporaneous pattern involving remote, internet-exposed Rockwell Automation programmable logic controllers reachable with default credentials. That incident-specific mechanism is not independently confirmed in the public Rapid City record and is presented as analytic context rather than established fact. A federal joint cybersecurity advisory, updated July 22, documents malicious targeting of internet-facing, misconfigured Rockwell Automation/Allen-Bradley and other PLCs in municipal and water/wastewater environments, including project-file and HMI/SCADA manipulation and operational disruption at some victims. The advisory does not identify Rapid City.

Operational significance

The targeted asset was operationally sensitive because wastewater lift stations move sewage through a municipal collection system and can create public-health and environmental consequences if control or pumping is disrupted. Rapid City operates eight such stations, but officials did not identify which station was involved.

DysruptionHub respects Rapid City’s stated assessment that its water and wastewater infrastructure remained safe, drinking water remained secure and operations were never placed in jeopardy. The registry treats this as the city’s official position on the overall service and safety outcome. The statement does not provide, and DysruptionHub does not treat it as, a detailed on-the-ground account of lift-station device behavior, alarms, telemetry, control-state changes, communications or operator intervention before and during containment.

KOTA Territory News reported that the attempt was detected and contained without affecting drinking-water or wastewater services. DysruptionHub nevertheless assesses with low confidence that a brief, localized operational disturbance may have occurred at the targeted station without affecting the city’s overall service or safety outcome. No public evidence currently documents such a disturbance. The controlled classification therefore remains no known operational impact, and DD-CIT remains OC-ND: those labels reflect the absence of documented material disruption, not proof that every device-level or operator-level effect was ruled out.

Disclosure posture

Rapid City disclosed the incident on July 31 and directly addressed the most consequential public concern by stating that drinking water remained safe. The city also said that an active investigation limited the additional technical detail it could release. That caution leaves important analytic gaps and limits the scope of the no-disruption assessment available to the public, but it does not establish a conflict with the city’s reported overall outcome.

Current status

The city described the attempted intrusion as contained and reported no continuing operational effect. Federal coordination and investigation remained ongoing, but investigative activity alone does not indicate continuing service disruption. DysruptionHub therefore assesses the operational incident as resolved while recognizing that the technical and attribution investigations may remain open.

Confidence and uncertainty

Confidence is high that the event involved malicious or unauthorized cyber activity because Rapid City officially described an attempted cybersecurity breach and cyber incident. Confidence is also high that no material operational disruption was publicly documented because the city expressly said water and wastewater operations were not jeopardized and drinking water remained safe. This is a documentation assessment, not a definitive finding that no localized operational effect occurred.

Confidence is low that a brief localized operational disturbance occurred. That judgment rests on the operational role of the targeted lift station, the reporting analyst’s assessment of a Rockwell PLC/default-credential pattern across the contemporaneous incident set and the broader federal reporting on disruptive activity against internet-facing PLCs. It is constrained by the absence of a Rapid City device log, operator account, alarm history, controller configuration or final technical report.

The public record does not support confirmed ransomware, extortion or data theft. Rapid City did not report encryption, a ransom demand, a leak-site listing, altered data, loss of control or loss of monitoring. The city also did not link the incident to the contemporaneous Minnesota water-system activity, any specific threat actor, device, vendor or vulnerability.

Analytic gaps

The reviewed sources do not establish when the attempted intrusion occurred, the targeted station, the exposed device or service, the initial access vector, whether credentials were used, whether the attempt reached an operational-technology controller, whether any settings were changed, or what technical control stopped the activity. They also do not establish whether data was accessed, whether logs showed prior activity, whether a third party was involved, or whether investigators identified a common campaign.

The public record further does not resolve whether this incident was related to the separate Pennington County government cyber incident earlier in July. Rapid City reviewed municipal systems during the county response because the governments share some technology infrastructure, but officials reported no sign that city systems had been compromised at that time and did not publicly connect the two events.

Campaign

Status: ActiveCampaign confidence: MediumCampaign connection: Low

Beginning July 26-27, 2026, malicious actors targeted operational technology at U.S. water and wastewater utilities, causing loss of monitoring or control and other disruption. The registry links 15 named incidents across six states, while reporting supports unnamed July victims in Arkansas and Oregon and places the campaign in at least 12 states. Two similar late-August Colorado attacks remain unlinked. None of the 15 named victims responded to DysruptionHub requests for comment; that uniform silence and restricted federal disclosure strengthen, but do not prove, an assessment that federal coordination discouraged public discussion.

Why this incident is included

Rapid City confirmed an attempted intrusion involving a wastewater lift station during the late-July campaign window, worked with federal cybersecurity partners, and was identified by independent multistate reporting as an apparent campaign candidate. No public evidence confirms a PLC, device model, configuration change, shared infrastructure, or common actor.

Organizations involved

Impacted location

Sources

Rapid City reports cyber incident at wastewater lift station

DysruptionHub reported that Rapid City quickly detected an attempted cyber intrusion involving a wastewater lift station and took precautions. The city said its water and wastewater systems remained safe, drinking water was secure, and it was working with CISA and other federal agencies. Officials did not identify the targeted station, attack method, data impact or responsible party.

Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure

The joint advisory, updated July 22, 2026, warns of exploitation of internet-connected operational-technology devices, including Rockwell Automation/Allen-Bradley, Schneider Electric and Siemens PLCs, across local-government, water/wastewater and energy environments. It describes access to internet-facing, misconfigured PLCs, malicious project-file and HMI/SCADA manipulation, and operational disruption in some victims. It does not identify Rapid City or establish the device vendor, credential condition or impact in this incident.

City Reports Cyber Incident at Wastewater Lift Station, Water Supply Remains Safe

KOTA Radio reported that the city discovered an attempted cybersecurity breach targeting a wastewater lift station, immediately implemented protective measures and said water and wastewater operations were never placed in jeopardy. The incident remained under investigation with federal cybersecurity partners.

Rapid City says wastewater lift station targeted in cyber incident, water supply remains safe

KOTA reported that Rapid City officials said a cyberattack targeting a wastewater lift station was quickly detected and contained with no impact to drinking-water or wastewater services. Officials said neither system was compromised and that the city was working with CISA and other federal partners.

See something that needs correction?

Signed-in members can report an error, update, or missing source.