Pennington County, South Dakota

Pennington County identified a cybersecurity incident by July 5, 2026, closing most public-facing offices July 6 before staged reopening. Recovery remained incomplete August 31, when network service was still unavailable at some remote locations and the Wall Treasurer’s satellite office was expected to remain closed throughout September. Some employees told not to report July 6 had to use accrued leave or take unpaid time because the county did not formally declare an emergency closure, and commissioners voted September 1 against making an exception; data impact, ransomware and attribution remain unresolved.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
The organization could not process, receive, issue, reconcile, or record payments normally.
Business, financial, customer, administrative, or operational transactions could not be completed normally.
The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.
Public administrative, licensing, permitting, court, tax, records, benefits, or other government services were materially affected.
One or more offices, schools, clinics, stores, plants, branches, or other facilities closed because of the incident.
Services continued but with longer processing, response, delivery, or completion times.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.
Employees were sent home, placed on administrative leave, furloughed, or otherwise removed from normal duties because of the incident.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
The incident caused operational effects at customers, affiliates, subsidiaries, partners, tenants, or other dependent organizations.
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
DysruptionHub assesses with high confidence that a cybersecurity incident affected portions of Pennington County, South Dakota’s government network by July 5, 2026. The county closed most public-facing offices July 6 and reopened them July 7 with limited services while investigators and responders restored systems in a remediated environment.
July 5 is the earliest supported identification and public cyber-disclosure date, not a confirmed intrusion-start date. The public record does not establish when malicious activity began or identify the initial access vector, malware family or specific attack mechanism.
The incident caused a material county-government disruption. Most public-facing offices closed July 6, then reopened July 7 while core administrative functions remained constrained. Vehicle registrations, payments, lien processing, real-estate recording, permits and property-record access were among the affected functions. Residents were directed to state systems, kiosks, online vital-record services and neighboring counties, while staff used manual workarounds.
Critical continuity was preserved. The county repeatedly said 911 dispatch, the jail, Juvenile Services Center, Care Campus, emergency response, courts, the 24/7 Program and early voting remained operational. The evidence supports substantial administrative disruption, not a countywide public-safety shutdown.
The effects extended beyond county offices. KOTA reported that Rapid City temporarily disabled online utility payments and slowed building-permit processing while reviewing shared infrastructure, although city officials said there was no indication its systems were compromised.
County records also establish a direct workforce and financial consequence from the initial shutdown. A countywide notice told employees not to report July 6 and to contact their supervisors while the network remained offline. County leaders nevertheless did not formally invoke the Emergency Facility Closure policy, and the board chair later said he had not intended to declare one. That procedural distinction meant the policy did not automatically provide qualifying nonexempt employees with paid closure leave or qualifying employees who worked with time-and-a-half pay. Under the ordinary payroll treatment, affected employees instead had to use accrued leave or take the time unpaid.
A Sept. 1 memorandum estimated up to $32,500 in accrued leave used and up to $10,500 in unpaid time; those figures were directional because the county lacked a centralized scheduling record for the review. Staff presented four choices balancing existing policy, employee equity, administrative feasibility, cost and stewardship of public funds. The options ranged from retaining the $0 existing treatment to targeted restoration of leave and wages estimated at $43,000, emergency-closure compensation of up to $88,000 or a broader administrative-leave remedy illustrated at $133,000.
The Rapid City Journal reported that commissioners selected the no-change option 3-2 on Sept. 1. Supporters argued that paying employees who stayed home could be unfair to the estimated 75% who reported and that time-and-a-half for employees performing regular work was also inappropriate; the chair cited the county’s existing leave and vacation benefits. State’s Attorney Lara Roetzel supported relief, emphasizing that employees had been told not to report and that losing even one day of leave or wages mattered to workers living paycheck to paycheck. A narrower proposal to restore used leave and compensate unpaid hours without time-and-a-half failed 2-3. The decision therefore left the documented leave and wage losses with affected employees despite the countywide instruction not to report.
The county’s service document, originally published July 27 and marked updated Aug. 12, showed substantial but incomplete recovery. Its revised introduction said all county offices were open and operational, but a few services remained limited and processing could take longer as systems were safely restored. Because the page did not identify which individual bullets changed Aug. 12, DysruptionHub treats that date as general continuing-impact evidence without assuming every listed constraint was reconfirmed then.
Later reporting established that recovery remained incomplete. South Dakota Searchlight reported Aug. 24 that residents still could not access some services. On Aug. 31, KOTA reported that county network service had not been restored at some remote locations and the Wall Treasurer’s satellite office was expected to remain closed throughout September. The main Treasurer’s Office in Rapid City remained open, and some motor vehicle transactions were available through state online services and four Rapid City kiosks.
The operational incident remains active. A Sept. 14 NewsCenter1 report said PulsePoint remained unavailable and county information technology staff were coordinating restoration, while 911 response remained uncompromised. Sept. 14 is the latest supported operational-impact date. No countywide restoration notice or final all-clear was found through the Sept. 20 research cutoff.
Pennington County directly confirmed the incident and issued service updates, while withholding technical and investigative details. Its communications distinguished continuing critical services from disrupted administrative functions and said analysis of possible personal-information effects remained underway. This affected-organization-first sequence supports OC-OD classification.
Confidence is high that malicious or unauthorized cyber activity caused material disruption because the county confirmed the cybersecurity incident and tied closures, system restoration and service limitations to it. Confidence is high that operational impact continued Aug. 31 because two local reports attributed the remote network outage and Wall office closure to county officials, and one quoted Pennington County Treasurer Annette Brant.
Confidence is high that the July shutdown affected employee leave and wages because the county’s own memoranda document the notice not to report, the absence of a formal emergency closure and estimated accrued-leave and unpaid-time losses, while the Rapid City Journal documented the commission’s decision and competing rationales. The record does not establish how many employees were affected or the final aggregate losses.
Data impact, ransomware and threat-actor attribution remain unresolved. No reviewed source establishes encryption, a ransom note, an extortion demand, data exfiltration, data publication, payment or a named actor.
The public record does not establish the intrusion start, dwell time, initial access vector, compromised account or host, exploited vulnerability, malware family, persistence method, affected-system inventory or technical root cause. It does not disclose whether personal information was accessed, copied or removed, which data categories were reviewed or how many people might be affected.
The public record also does not identify every remote location still lacking network service, provide a reopening date for the Wall satellite office or establish when every county service will return to normal. It does not quantify the employees affected by the July 6 work directive or establish final leave and wage losses. No public source establishes ransomware or extortion, a threat actor, demand or payment, recovery cost or the restoration method for individual systems.

The Pennington County Treasurer's satellite office in Wall was expected to remain closed throughout September because county network service had not been restored at some remote locations.
Pennington County closed most public-facing offices during a cybersecurity response while critical public-safety, jail, court, election and selected registration services continued.
On August 18, Pennington County’s live homepage still stated that some services were unavailable because of the cybersecurity incident and directed residents to the current service notice.
KOTA reported that Rapid City reviewed systems because it shares some infrastructure with the county. The precaution temporarily disabled online utility payments, slowed permit processing and required manual receipts, although officials said there was no indication city systems were compromised.
Gov. Larry Rhoden said July 10 that the South Dakota National Guard and Bureau of Information and Technology were assisting Pennington County through the cybersecurity incident and that the investigation remained underway.
The county’s consolidated notice documents the July 6 closure, July 7 reopening with limited services, staged restoration through July 14, continuing security validation and monitoring, and an ongoing assessment of whether personal information was affected.
The county service page is dated July 27 and visibly marked ‘Updated on August 12, 2026.’ Its revised introduction says all county offices remain open and operational, but a few services remain limited and processing times may be longer as systems are safely restored. The page lists restored motor-vehicle and real-estate access alongside continuing limitations involving online real-estate payments, lien payments, real-estate recording, property-record access, processing times and a 4-H telephone line.
South Dakota Searchlight reported on August 24 that Pennington County residents still could not access some services after the July cyberattack. The report did not identify the unavailable services.
News Radio KOTA reported Aug. 31 that the Pennington County Treasurer’s satellite office in Wall would remain closed throughout September because network services had not been fully restored at some remote locations. The main Rapid City office, some state online services and four Rapid City kiosks remained available.
KOTA reported Aug. 31 that county network services had not been restored at some remote locations and that the Wall Treasurer’s satellite office would remain closed throughout September. County Treasurer Annette Brant apologized for the inconvenience; officials gave no reopening date.
A Sept. 1 county memorandum says the countywide direction not to report July 6 did not qualify automatically for Emergency Facility Closure benefits because no authorized formal closure had been declared. Staff estimated up to $32,500 in accrued leave used and $10,500 in unpaid time and presented four options: no changes at $0; targeted leave and wage restoration at about $43,000; emergency-closure compensation up to $88,000; or broader administrative leave illustrated at $133,000.
The Rapid City Journal reported that commissioners chose the no-change payroll option 3-2 on Sept. 1. Supporters cited fairness to the estimated 75% of employees who worked, objections to time-and-a-half for regular work and the county’s existing leave benefits. A proposal to restore leave and compensate unpaid hours without time-and-a-half failed 2-3; State’s Attorney Lara Roetzel supported relief because employees had been told not to report and a one-day loss mattered to workers living paycheck to paycheck.
NewsCenter1 reported Sept. 14 that PulsePoint remained unavailable in Pennington County and county IT staff were coordinating restoration; 911 service was not compromised.
Signed-in members can report an error, update, or missing source.